Business Information Security Officer – Global Banking and Markets

Bank of America Bank of America · Banking · Denver, CO +2

The Business Information Security Officer (BISO) will be a key functional member of the Business Information Security Officer (BISO) organization, working closely with Global Banking and Markets (GBAM) Chief Information Officer (CIO) and Chief Technology Officer (CTO) teams. The role requires developing a deep understanding of GBAM’s business and technology landscape to enable informed, risk-based information security discussions. Through strong partnerships with technology and risk stakeholders, the ISO will help ensure focus on the most critical information security risk priorities. Acting as a day-to-day point of contact, the ISO will provide guidance on information security topics, policies, and controls, ultimately becoming a trusted governance and risk partner to the business.

What you'd actually do

  1. Serve as a subject matter expert for the development, implementation, and ongoing maintenance of information security controls within the line of business (LOB).
  2. Provide guidance and advocacy on the prioritization of LOB investments, with a focus on information security impact and risk reduction.
  3. Advise LOB management on information security risks and recommend actions aligned with the bank’s broader risk management and compliance programs.
  4. Act as the primary point of contact for ad hoc information security enquiries from the LOB.

Skills

Required

  • 3+ years experience in an information security technology, operations, engineering, or consulting role
  • strong knowledge of security controls and processes across systems and networks
  • Excellent interpersonal skills
  • ability to communicate, influence, and negotiate effectively with senior stakeholders

Nice to have

  • Experience within a technology or financial services organization at a mid to senior level
  • solid knowledge of application security controls and associated risks
  • Understanding of vulnerability management concepts, monitoring solutions, and remediation practices
  • Experience with formal security risk assessment methodologies
  • In-depth technical understanding of technology infrastructure operations and related subject matter areas
  • Previous experience working within a financial institution
  • Proven ability to proactively set work priorities and independently manage a portfolio of activities
  • Strong communication skills, including the ability to deliver difficult messages and drive issue resolution with stakeholders
  • Demonstrated ability to work collaboratively as part of an integrated EMEA GIS team
  • Excellent written and verbal communication skills, including the ability to produce and present clear management-level progress and status reports

What the JD emphasized

  • strong knowledge of security controls and processes across systems and networks
  • solid knowledge of application security controls and associated risks
  • Understanding of vulnerability management concepts, monitoring solutions, and remediation practices
  • In-depth technical understanding of technology infrastructure operations and related subject matter areas