About The Position

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve. Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! The Senior Information Security Officer will be a key member of the GIS Exception Management team within the Business Information Security Office (BISO) organization. In this role, you will serve as a technical lead for the GIS Policy Exceptions and Secure Internet Browsing programs, providing oversight of operational execution, governance and reporting routines, risk management, and continuous improvement initiatives. You will continuously collaborate with IT, business technology groups, risk partners, GIS teams across their respective LOB and Third-party vendor.

Requirements

  • Information Security & Technology professional with 10+ years’ experience
  • 5+ years of risk management experience with proven ability to effectively apply risk principles to challenging business situations
  • Provides subject matter expertise in Web, Network, and Application security, vulnerability assessment and testing, and the establishment of risk appetite and risk management strategies
  • Strong experience with Insider Threat and Web Proxy Infrastructure as a focus area within Information Security
  • Experience and hands on knowledge with Data Loss Prevention and Malware security controls
  • Experience evaluating cyber security controls and providing guidance for computing & network platforms (Cloud, PaaS, SaaS)
  • Strong experience with information security for Network & DMZ Infrastructure and third-party connectivity including exposure to various security frameworks (ISO, NIST, PCI etc.)
  • Experience leading complex technical initiatives, driving projects to meet target timelines, facilitating stakeholder meetings, developing project documentation, resolving issues, and coordinating resource planning.
  • Exceptional executive presentation and communication skills
  • Strong interpersonal and leadership skills with the ability to build consensus, promote cooperation, and effectively influence, negotiate, and collaborate with senior leaders and stakeholders at all levels of the organization
  • Ability to independently lead projects and deliver desired outcomes with minimal supervision while meeting program goals
  • Strong knowledge of change and project management methodologies, with the ability to effectively incorporate these principles into project planning, design, and execution
  • Possess strong Network, Web and Application security background; with solid knowledge of SDLC from design, testing, deployment to post-production and the different risk elements associated with each step.
  • Has a deep understanding of Network and Web Security principles and emerging technologies

Nice To Haves

  • Bachelor's and/or Master’s degree in Computer Science, Information Technology or related field

Responsibilities

  • Serve as a technical lead for the GIS Policy Exceptions and Secure Internet Browsing programs.
  • Provide oversight of operational execution, governance and reporting routines, risk management, and continuous improvement initiatives.
  • Continuously collaborate with IT, business technology groups, risk partners, GIS teams across their respective LOB and Third-party vendor.
  • Serve as an Information Security subject matter expert, driving the implementation and support of secure web access solutions for enterprise users.
  • Partner with Information Security DLP and Malware Control teams, Proxy/Network Engineering and business stakeholders to balance security and usability.
  • Evaluate risk and provide expert guidance on web access, URL onboarding, and proxy change requests to ensure appropriate prioritization and alignment with Line of Business (LOB) objectives.
  • Monitor information security trends internal and external to the bank and keep LOB leadership informed about information security-related issues.
  • Manage quality control and reporting.
  • Ensure compliance with policies and laws.
  • Manage and oversee the documentation, assessment, and remediation of risk issues, governance decisions, policy exceptions, and audit-related action.
  • Collaborate with risk partners on info security critical priorities.
  • Participate in senior LOB specific Risk Management & Business Continuity Routines.
  • Identify and measure global information security (GIS) controls on most critical business processes or channels.
  • Identify and implement opportunities for automation, tooling enhancements and process optimization to improve efficiency and reduce operational risks.
  • Build strong Partner relationships with peer technology groups and supported LOB.
  • Identify and implement opportunities for automation, tooling enhancements and process optimization to improve efficiency and reduce operational risks.
  • Drive required risk culture and partnership with peer technology teams and supported LOB.
  • Participate in key CIO operating routines to drive information security risk strategy.

Benefits

  • Access to paid time off
  • Resources and support to our employees
  • Discretionary incentive eligible
  • Annual discretionary award based on individual performance, line of business performance, and company success.
  • Industry-leading benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service