Back to search results

Proactive Insider Threat Specialist (Global Information Security)

Addison, Texas;

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.

One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We’re devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.

The Cyber Security Operations (CSO) function within Global Information Security enables the various businesses of Bank of America to conduct operations in a secure, trusted, and safe manner by defending the organization and our customers from cyberattacks. Additionally, the team oversees all aspects of threat intelligence and monitoring, application and network security, access management operations and insider threats. The Proactive Insider Threat team within CSO monitors high risk populations and high-risk database activity for indicators of insider threat behaviors. 

In this role, the Proactive Insider Threat Specialist, is responsible for conducting the daily proactive insider threat strategy activities to include alert triage, user activity analysis, and alerting development / tuning. The analyst will be accountable for making the assessment of the alert activity and determine if it is suspicious, malicious, or a violation of policy and escalate as appropriate and may require collaboration with managers and other teams. 
Candidates must be willing to be enrolled in AIM (Associate Investment Monitoring) program and operate under a Non-Disclosure Agreement. Role will require non-traditional work hours and on-call duties.

Responsibilities include, but are not limited to:
•    Review and triage alerts, determine risk, and take appropriate response actions
•    Coordinate with existing GIS teams and leadership while effectively working across a complex organization that is geographically dispersed
•    Utilizing technical knowledge with behavior analytics focused methodologies to conduct insider threat activity monitoring, alerting, and strategic operations
•    Conduct trend analysis and research using data resources to and collaborate with partners to identify insider risk and or areas for improvement
•    Maintain an awareness of industry challenges and advancements in order to add value to existing technologies and processes used within the team
•    Complete written reports in compliance with current reporting procedures and policies; Must have the ability to write and present detailed, concise, and accurate reports
•    Complete assigned projects / tasks / areas of responsibility

Required Skills:
•    Expertise / experience in insider threat associated risk detection and mitigation practices, database management / anomaly detection, or technical background and experience that would apply to these focus areas
•    Ideal candidate will have experience with database management and understanding of database query language, be proficient coding using Python, or have advanced skills using Splunk (creating searches, dashboards, and alerting) 
•    Exceptional oral and written communication skills and ability to interact effectively with technical and non-technical audiences including stakeholders
•    Demonstrate ability to self-direct project outcomes with minimal supervision to achieve program goals
•    Curiosity, diversity of thought, critical thinking, willingness to learn, and persistence to identify risk
•    Ability to navigate and work effectively across a complex, geographically dispersed organization 

Desired Skills: 
•    Experience with Endpoint Detection & Response (EDR), Security Information and Event Management (SIEM), and/or manual log analysis techniques 
•    Understanding of basic Data Science concepts and processes 
•    Experience working with industry-wide frameworks and standards like MITRE ATT&CK, STIX, TAXII, and NIST SCAP and offensive strategies and assessment methodology 
•    An understanding of human behavior / human psychology 
This job will be open and accepting applications for a minimum of seven days from the date it was posted.


1st shift (United States of America)

Hours Per Week: 


Learn more about this role

Full time


Manages People: No

Travel: No

Colorado pay and benefits information

Colorado pay range:

$93,700 - $141,700 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.


This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.