Back to search results

Senior Engineer - GBS IND

Hyderabad, , India;

Job Description:

About Us

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection.  Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.

One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We’re devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.

 Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.

Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!

Global Business Services

Global Business Services delivers Technology and Operations capabilities to Lines of Business and Staff Support Functions of Bank of America through a centrally managed, globally integrated delivery model and globally resilient operations. Global Business Services is recognized for flawless execution, sound risk management, operational resiliency, operational excellence and innovation. In India, we are present in five locations and operate as BA Continuum India Private Limited (BACI), a non-banking subsidiary of Bank of America Corporation and the operating company for India operations of Global Business Services.

Process Overview

The Global Information Security (GIS) is responsible for protecting Bank information systems, confidential and proprietary data, and customer information. The team develops the Bank’s Information Security strategy and policy, manages the Information Security program, identifies, and addresses vulnerabilities, Develops, deploys and manages a risk-based controls, portfolio, Manages and operates global security operations center that monitor, detect and respond to cybersecurity incidents.

Job Description

This position will be a member of the Business Information Security Office (BISO) Governance and Execution team. The role requires executing against the quality assurance strategy to validate cyber security risk is being mitigated appropriately across lines of business as well as Third Parties. This role will support the new ERP Review Framework Strategy to ensure a consistent risk management process is being leveraged when assessing vulnerability risks by ensuring that appropriate mitigations and/or compensating controls are applied if remediation cannot be completed within SLA. For each Observation there must be relevant Mitigating or Compensating Control(s) in place before an exception can be considered and Level of residual risk is determined based on the completeness of the aligned Controls. In conjunction of this role, the key team members will perform QAs on additional processes ensuring adherence to audit process guidelines. The QA output will be utilized to identify and incorporate future process enhancements to maintain consistency and quality across BISO functions.


  • Strong background in information security and risk management
  • Experience with vulnerabilities and remediation
  • Skilled in requirement analysis, test plan/scenario preparations, design and execution, defect logging and management
  • Self-starting, organized, and requiring minimal management oversight
  • Strong analytical skills/problem solving/conceptual thinking/attention to detail
  • Ability to work effectively with peers and various levels of management
  • Well organized and thorough, with the ability to balance and prioritize
  • Ability to take ownership of an initiative/issue through completion.
  • Ability to work in a collaborative environment.
  • Process reporting and strategic thinking of process improvisation.
  • Ability to work with minimal supervision.
  • Ability to own and deliver on complex initiatives in a high paced, evolving environment.
  • Knowledge in Application security, Risk assessments, Cloud technologies, GRC (Governance, Risk, and Compliance) with emphasis on security processes and controls is desirable


Education: Bachelor’s Degree or technology and cybersecurity background

Certification: CISA, CRISC, CISM

Experience Range: 10+ years

Foundational skills:

  • Minimum 4 years of experience in cyber security or a technology-related field
  • Strong project management experience
  • Strong analytical skills/problem solving/critical thinking.
  • Able to work with technical and non-technical business owners.
  • Able to take ownership of an initiative/issue through completion.
  • Able to work in a collaborative environment.
  • Able to own and deliver on complex initiatives in a high paced, evolving environment.
  • Excellent verbal and written communication skills; Ability to communicate with business leaders, users and tech-savvy stakeholders.
  • Proficient in MS Office (Word, Excel, PowerPoint)
  • Ability to work with minimal supervision.

Desired skills:

  • Knowledge/Experience in Application security, Risk assessments, Cloud technologies, GRC (Governance, Risk, and Compliance) and/or third-party management with emphasis on security processes and controls
  • Experience evaluating threats/risks posed by new technologies spanning networks, hardware, software, etc.
  • Ability to evaluate technology to ensure cyber-secure development that adheres to internal application policy, standards, and baselines.
  • Bachelor’s degree in information technology, information security or related field

Work Timings:  13:30 – 22:30 Hours

Job Location: Hyderabad/ Mumbai

Learn more about this role

Full time


Manages People: