Cyber Security Application Remediation Governance Analyst
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Position Summary:
The Application Remediation Governance candidate will contribute to reduction of technology risk in the bank by driving down the time taken to remediate identified application vulnerabilities, working with application managers and risk partners to resolve vulnerabilities in a time frame aligned to the Bank’s risk appetite.The candidate will be at the forefront of the Bank’s response to the new AI- identified application vulnerabilities, working with application teams and driving remediation in a timely manner.
The candidate will attend report out calls following a security assessment of a particular application aligned with an assigned 4 dot hierarchy. Candidate will track the identified vulnerabilities in the system of record and work with the application or vendor manager until resolution. Candidate will update status of vulnerabilities as required in the system of record and will aid the application and/or vendor manager with any technical or process related queries during resolution of the identified vulnerabilities. Additionally the candidate will be expected to aid with creation of periodic risk metrics relating to the role.
Responsibilities:
- Creates and maintains the team's application vulnerability portfolio.
- Responsible for being at the forefront of the Bank’s response to the novel threat of AI identified vulnerabilities, possession of a good understand of LLM based vulnerabilities and the most effective and timely actions the team can take to minimize cyber risk to the Bank.
- Oversight and leadership responsibilities for ARG daily BAU activities.
- Leadership of the ARG team, including being proxy manager when required.
- Responsible for maintaining a balanced distribution of vulnerabilities between ARG team members to ensure workload balance.
- Work includes configuration of the SOR for all team members to view their portfolio, specifically alerting them to any items that require timely action (e.g. self assignment of new vulnerabilities).
- Responsible for escalation and representation of the ARG on Incident calls related application vulnerabilities, specifically P1s.
- The candidate will be expected to take responsibility for any ARG actions or collaboration, “owning” the issue for ARG.
- Works with CST tech teams to ensure that the SOR remains up to date and functioning correctly.
- Works with CST on enhancements to the SOR.
- Represents ARG on tech calls relating to SOR, providing end user input and validation of break/fix activities.
- Responsible for management of the ARG BAU process for unmasked corporate account details.
- Responsible for creation and maintenance of ARG team official process and procedure documentation, and training documentation.
- Responsible for configuration of the application access package for all new ARG team members in ARM.
- Responsible for creation and QA for monthly risk metrics at manager and board level.
- Responsible for training and onboarding any new members of the ARG team.
Required Qualifications:
- 3+ years cyber security experience.
- Vulnerability and remediation experience.
- Ability to improve team processes to increase efficiency and coverage. This would include maintenance of team documentation and optimising alignment of vulnerabilities among the team.
- Understanding of novel vulnerability vectors, primarily those aligned to AI capabilities.
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)Hours Per Week:
40