Information Security Officer – Global Banking & Markets (GBAM)
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
The Information Security Officer (ISO) will serve as a key member of the Business Information Security Officer (BISO) organization, partnering closely with Global Banking & Markets (GBAM) Chief Information Officers (CIOs), Chief Technology Officers (CTOs), and business stakeholders to develop a deep understanding of business objectives, technology strategy, and associated cybersecurity risks.
Through strong partnerships and risk-based engagement, the ISO will provide strategic security guidance, challenge and oversight, helping ensure information security risks are effectively identified, assessed, and managed in alignment with enterprise policies, standards, and regulatory expectations. The successful candidate will become a trusted advisor to senior stakeholders, enabling informed risk decisions while supporting business innovation and growth.
Responsibilities
• Serve as the primary information security advisor and point of contact for assigned GBAM, providing guidance on cybersecurity risks, policies, standards, and controls.
• Act as a subject matter expert in the development, implementation, and ongoing oversight of information security practices within the line of business.
• Provide independent risk-based challenge and advisory support for technology initiatives, strategic programs, and implementation changes across the GBAM environment.
• Influence and advocate for the prioritization of investments that strengthen the organization's security posture and reduce risk.
• Advise business and technology leadership on cybersecurity risk issues and recommend actions that support the bank’s broader risk management, regulatory, and compliance objectives.
• Collaborate with Risk, Technology, and Control partners to enhance security processes, governance frameworks, and risk management capabilities.
• Partner with the Global BISO organization to ensure GIS policies, standards, requirements, and strategic initiatives are communicated, understood, and effectively implemented.
• Establish and maintain strong relationships across business, technology, risk, and control functions to facilitate effective security risk management.
• Conduct routine coordination with risk partners and technology teams to address vulnerabilities, control gaps, and remediation activities, with a focus on issues identified as elevated risk.
• Drive remediation efforts for cybersecurity issues and support stakeholders in achieving sustainable solutions aligned with GIS standards, baselines, and control requirements.
• Support ad hoc security consultations, risk assessments, governance activities, and executive reporting as required.
Required Qualifications
• Experience within information security, cybersecurity engineering, technology risk management, security operations, or security consulting functions.
• Strong understanding of security controls, risk management practices, and cybersecurity frameworks applicable to enterprise systems, applications, cloud platforms, and network environments.
• Demonstrated ability to communicate, influence, and negotiate effectively with senior business and technology leaders.
• Strong analytical and problem-solving skills with the ability to assess risk and provide practical, business-aligned recommendations.
• Understanding of vulnerability management concepts, associated tooling, and remediation governance processes.
• Ability to independently manage competing priorities and oversee a diverse portfolio of work.
• Strong communication and stakeholder management skills, including the ability to deliver challenging messages and drive issue resolution.
• Proven ability to build relationships, establish credibility, and operate effectively across complex organizational environments.
Desired Qualifications
• Experience with Artificial Intelligence (AI) governance, AI risk management, and responsible AI practices, including familiarity with emerging regulatory requirements, AI security controls, model risk considerations, and governance frameworks supporting the secure adoption of AI technologies.
• Experience within large-scale technology and financial services organizations, with strong knowledge of application security risks, controls, and secure development practices.
• Experience conducting formal security risk assessments and facilitating risk-based decision-making.
• Deep technical understanding of technology infrastructure, cloud platforms, application architectures, and operational security practices.
• Previous experience working within a highly regulated financial institution.
• Demonstrated ability to work collaboratively within a matrixed Global Information Security organization.
• Excellent verbal, written, and executive briefing skills, with experience producing management-level reporting and presentations.
Preferred Leadership Attributes
• Trusted advisor mindset with strong business acumen.
• Ability to balance risk management objectives with business enablement.
• Proven capability to influence without direct authority across multiple organizations.
• Strategic thinker with the ability to translate complex security risks into clear business outcomes and actionable recommendations.
Required Skills
1. Controls Management
2. Cyber Security
3. Data Governance
4. Information Systems Management
5. Risk Management
6. Architecture
7. Customer and Client Focus
8. Executive Presence
9. Threat Analysis1
0. Vendor Management
Shift:
1st shift (United States of America)Hours Per Week:
40Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)Pay and benefits informationPay range$99,200.00 - $145,000.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.