Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
The Standards, Strategy, and Enablement leader will manage the execution of ongoing governance and oversight of strategic and technology initiatives, cybersecurity standards, and operational enablement and excellence across Cyber Security Operations (CSO). This role is responsible for leading a team to drive collaboration across CSO functions, deliver consistent management of initiatives, strategy, and risk operations. The role will own the Monitoring, Response and Forensics (MRF) and Data Protection (DAP) Information Security Standards and manage related activities such as, ongoing Law, Rule and Regulation (LRR) evaluations, control and stakeholder engagement, mitigating aligned risk concerns and partnering across Global Technology to drive adherence to specific standard requirements. This leader will partner across Cyber Security Operations, Global Information Security, Global Technology, and Risk partners.
Responsibilities:
- Strategy Development & Alignment:
- Collaborate with CSO leadership to define and evolve the strategic direction of Cyber Security Operations, ensuring alignment with Global Information Security strategy and regulatory expectations.
- Standards Ownership & Governance:
- Own and maintain the Data Protection Standard, partnering with the Data Loss Prevention Executive to ensure effective controls and coverage and adherence monitoring.
- Own and maintain the Monitoring, Response, and Forensics Standard, partnering with Cyber Threat Defense and CSO leaders to ensure controls and coverage and adherence monitoring.
- Oversee and drive related governance activities such as: ongoing Law, Rule and Regulation (LRR) evaluations, control and stakeholder engagement, mitigating aligned risk concerns and partnering across Global Technology to drive adherence to specific standard requirements.
- Technology Enablement:
- Drive execution of CSO technology initiatives by establishing routines, tracking progress, and ensuring alignment with strategic priorities and risk posture and holding CSO accountable for the business ownership of the initiative lifecycle.
- Process & Operational Excellence:
- Oversee the Single Process Inventory of CSO processes and metrics. Lead efforts to streamline operations, reduce complexity, validate coverage of day-to-day operational execution and improve consistency across CSO functions.
- Risk & Regulatory Management:
- Oversee CSO’s risk and regulatory routines, ensuring timely and accurate responses to audits, regulatory inquiries, and internal risk assessments. Partner with GIS Risk Oversight, Audit, and Compliance teams to manage commitments and reporting.
- Quality Assurance & Oversight:
- Lead quality assurance efforts across CSO to validate control effectiveness, identify gaps, and drive continuous improvement.
- Executive Reporting, Engagement & Governance:
- Develop and deliver executive-level reporting on CSO strategy, operational reporting and metrics, and risk posture through meaningful CSO governance forums.
Managerial Responsibilities:
This position may also have responsibilities for managing associates. At Bank of America, all managers at this level demonstrate the following responsibilities, in addition to those specific to the role, listed above.
- Opportunity & Inclusion Champion: Models an inclusive environment for employees and clients, aligned to company Great Place to Work goals.
- Manager of Process & Data: Demonstrates deep process knowledge, operational excellence and innovation through a focus on simplicity, data based decision making and continuous improvement.
- Enterprise Advocate & Communicator: Communicates enterprise decisions, purpose, and results, and connects to team strategy, priorities and contributions.
- Risk Manager: Ensures proper risk discipline, controls and culture are in place to identify, escalate and debate issues.
- People Manager & Coach: Provides inspection, coaching and feedback to motivate, differentiate and improve performance.
- Financial Steward: Actively manages expenses and budgets in alignment with objectives, making sound financial decisions.
- Enterprise Talent Leader: Assesses talent and builds bench strength for roles across the organization.
- Driver of Business Outcomes: Delivers results by effectively prioritizing, inspecting and appropriately delegating team work.
Required Qualifications:
- 7+ years of experience in cybersecurity, risk management, or technology governance within financial services.
- Proven leadership in developing and managing standards and strategic programs.
- Understanding of data protection, threat detection, incident response, and regulatory frameworks (e.g., FFIEC, GLBA, SOX).
- Experience managing cross-functional initiatives and governance routines in a matrixed environment.
- Strong analytical, communication, and executive stakeholder engagement skills.
- Relevant certifications (e.g., CISSP, CISM, CRISC, CGEIT) preferred.
Desired Qualifications:
- Strategic thinker with a strong execution mindset.
- Skilled in navigating complex environments and driving cross-functional alignment.
- Passion for operational excellence and continuous improvement.
Skills:
- Customer and Client Focus
- Interpret Relevant Laws, Rules, and Regulations
- Policies, Procedures, and Guidelines
- Problem Solving
- Stakeholder Management
- Business Process Analysis
- Data Privacy and Protection
- Innovative Thinking
- Quality Assurance
- Risk Analytics
- Business Continuity Management
- Data Governance
- External Resource Management
- Information Systems Management
- Vendor Management
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40
Learn more about this role