Third Party Cyber Assurance Assessor

Bank of AmericaWashington, DC
Onsite

About The Position

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Requirements

  • At least 3 years of relevant experience.
  • Previous security audit/assessment or remediation experience.
  • Experience with ISO 27001 and SOC 2 Type 2 control frameworks.
  • Previous experience reviewing independent audit reports / certification (e.g., ISO 27001, SOC 2 Type 2, PCI DSS RoC).
  • Previous experience reviewing self attestation / assessment reports (e.g., SIG, PCI DSS AoC).
  • Self-starting, organized, and requiring minimal management oversight.
  • Ability to operate across organizational boundaries and hierarchies to accomplish tasks.
  • Strong analytical skills/problem solving/conceptual thinking/attention to detail.
  • Ability to collaborate effectively with peers and various levels of management.
  • Well organized and thorough, with the ability to balance and prioritize.
  • Excellent verbal and written communication skills across multiple levels of the organization.

Nice To Haves

  • Previous information technology/security audit/assessment experience is a plus.
  • Background in information security and third party risk management.
  • Familiarity or experience with information security industry frameworks (e.g., NIST, ISO, PCI DSS).
  • Deep understanding of risk management and reporting concepts.
  • Cross functional project management and process development experience.
  • Critical Thinking.
  • Data Privacy and Protection.
  • Information Systems Management.
  • Problem Solving.
  • Technology System Assessment.

Responsibilities

  • Performing information security reviews of third parties, such as pre-assessment, assessment, and remediation activities that provide services to the bank.
  • Validating assessment scope.
  • Partnering with vendor managers and third parties to prepare them for the assessment.
  • Collecting and reviewing documentation during the assessment.
  • Determining if appropriate information security controls are in place.
  • Completing an assessment of workpapers.
  • Conducting information security assessments of third parties by reviewing independent audit reports (e.g., SOC 2 Type 2, ISO 27001, PCI DSS RoC) or Self Attestation / Self-Certification reports (e.g., SIG, PCI DSS AoC) to document a point of view on the information security posture of the third party.
  • Driving strategic initiatives focused on the design of Third Party Specialized Subcategory Cyber Assurance (TPSSCA) program requirements, governance routines, and third party risk metrics and reporting.
  • Analyzing and interpreting diverse information security risk indicators to deliver actionable insights into third party information security risk and enable prioritized cyber security assurance approaches.
  • Interacting with the third party cyber procurement team, technical subject matter experts, GIS Policy, and the internal and external third party management community.

Benefits

  • Access to paid time off
  • Resources and support to our employees

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

5,001-10,000 employees

© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service