Cloud Security Assurance Process Manager

Bank of America Bank of America · Banking · Denver, CO +2

The Cloud Assurance Process Manager role supports the Cloud Security Assurance organization within Global Information Security (GIS) and plays a critical role in enabling a scalable, repeatable, and defensible cloud assurance operating model across all Cloud Service Providers (CSPs). This role is responsible for the publication, governance, and continuous improvement of high quality cloud assurance process documentation that enables consistent execution across CSP teams. The Process Manager ensures that assurance processes, playbooks, and runbooks are clearly documented, audit defensible, accurately represented in the Single Process Inventory (SPI), and supported by well defined control, technology, and process health metrics. The individual coordinates assurance related engagements, supports audit and exam readiness, produces executive level reporting on process health, and integrates with upstream governance routines to anticipate new cloud business roadmaps and capabilities that will create future assurance demand.

What you'd actually do

  1. Lead the design, documentation, publication, and continuous improvement of Cloud Security Assurance processes across all CSP teams, including AWS, Azure, GCP, and SSPM.
  2. Own the development and maintenance of high quality, defensible assurance documentation, including playbooks, runbooks, procedures, and control narratives.
  3. Ensure all cloud assurance processes are accurately represented, governed, and maintained within the Single Process Inventory (SPI), including ongoing validation and quality reviews.
  4. Manage intake and coordination of internal and external engagements that impact Cloud Assurance, including audits, exams, assessments, and cloud risk reviews.
  5. Coordinate Cloud Assurance team participation in engagements driven by new business initiatives, cloud capabilities, and evolving platform roadmaps.

Skills

Required

  • 5+ years experience designing, documenting, and governing repeatable, well controlled assurance or operational processes.
  • Demonstrated ability to produce high quality, defensible documentation suitable for leadership, audit, and regulatory review.
  • Proven ability to establish operating routines, metrics, and reporting frameworks.
  • Strong influencing and collaboration skills across technical and non-technical stakeholders.
  • Ability to anticipate process, control, and operational risks and proactively implement solutions.
  • Excellent written and verbal communication skills with the ability to distill complex information into executive ready insights.
  • Strong relationship building skills across cloud, security, governance, and risk teams.
  • Proficiency in Microsoft Office tools (Excel, PowerPoint, Word, SharePoint).

Nice to have

  • Prior experience in assurance, governance, risk, compliance, or process management roles.
  • Familiarity with cloud platforms (AWS, Azure, GCP) and cloud security or assurance concepts.
  • Experience supporting audit, exam, or regulatory engagements.
  • Understanding of enterprise process inventories, control frameworks, and operating models.
  • Program or project management experience.
  • Experience operating in large, complex, or highly regulated environments.

What the JD emphasized

  • high quality cloud assurance process documentation
  • audit defensible
  • well defined control
  • process health metrics
  • executive level reporting
  • structured, defensible, and leadership ready artifacts
  • high quality, defensible assurance documentation
  • audit, exam, or regulatory engagements
  • highly regulated environments