Evaluation Analyst

Bank of AmericaWashington, DC
$100,000 - $141,300Onsite

About The Position

The Global Information Security (GIS) organization at Bank of America is responsible for protecting the bank's information systems, confidential and proprietary data, and customer information. The Cyber Threat Evaluation and Prevention Team (CTEP) within GIS assesses threats and emerging risks, evaluates cybersecurity controls, and defines observations for risk remediation. The CTEP program analyzes threats and incidents, identifies gaps for remediation, and evaluates improvements to the bank's risk and control environment for cyber security threats. The Evaluation team specifically analyzes threats and incidents to identify and triage process and control weaknesses, documents the defensive posture and overall risk, and reviews threats holistically to identify broad themes and strategic issues for proactive protection against cyber threats.

Requirements

  • Strong technical writing capabilities; writing technical content in a broadly consumable format.
  • Functional knowledge of information security, IT infrastructure, and risk management.
  • Ability to prioritize and manage time effectively and work independently with minimal direction.
  • Knowledge of Cyber Industry Frameworks like MITRE/NIST.
  • Strategic thinking AND attention to detail – ability to think “like a threat actor.”
  • Proficient computer/analytics skills – esp. Jira, Excel, Word, Power Point, Alteryx, etc.
  • General understanding of bank policies, specific to data and privacy, third parties, incident management, vulnerability management, etc.

Nice To Haves

  • Experience with cyber threat intelligence collection, analysis, and reporting.
  • Experience responding to and managing security incidents and events.
  • Experience creating, executing, and documenting assessments and exercises in JIRA.

Responsibilities

  • Conducts evaluations of threats and incidents to identify opportunities for process and control enhancements.
  • Supports the organization in making decisions and taking action to improve how the bank is defended using threat-led operations.
  • Engages with subject matter experts and control owners.
  • Conducts independent research using various applications and tools.
  • Comprehensively documents details on threats and the bank's defensive posture in the system of record.
  • Completes Quality Assurance (QA) reviews to ensure all threats are comprehensive, complete, and accurate.
  • Analyzes threats identified from internal and external intelligence sources.
  • Analyzes cyber incidents and events managed at the Bank (e.g., Third-party incidents).
  • Analyzes threat-based assessments conducted by GIS teams (e.g., Red Team).

Benefits

  • Industry-leading benefits
  • Access to paid time off
  • Resources and support
  • Discretionary incentive eligible
  • Eligible to participate in the annual discretionary plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service