Cyber Security Third Party Governance and Planning Analyst

Bank of America Bank of America · Banking · Denver, CO +2

This position will be a member of the Third Party Cyber Security Assurance (TPCA) organization in Global Information Security (GIS), responsible for developing, maintaining, and communicating third party information security requirements. The position will be a key player in driving strategic initiatives focused on the design of Third Party Cyber Assurance (TPCA) program requirements. Additionally, position requires interaction with technical subject matter experts, GIS Policy team, the third party cyber assessment team, and the internal and external third party management community. In addition to tactical activities, the position will be a key player in driving strategic initiatives to transform the processes by which our third party information security requirements are created and aligned to third parties, including reviewing and adopting industry best practices.

What you'd actually do

  1. Develop, maintain, and communicate third party information security requirements.
  2. Drive strategic initiatives focused on the design of Third Party Cyber Assurance (TPCA) program requirements.
  3. Interact with technical subject matter experts, GIS Policy team, the third party cyber assessment team, and the internal and external third party management community.
  4. Drive strategic initiatives to transform the processes by which our third party information security requirements are created and aligned to third parties.
  5. Review and adopt industry best practices.

Skills

Required

  • 5 years of relevant experience
  • Previous information technology/security audit/assessment experience
  • Excellent verbal and written communication skills
  • Self-starting, organized, and requiring minimal management oversight
  • Ability to operate across organizational boundaries
  • Strong analytical skills/problem solving/conceptual thinking/attention to detail
  • Ability to work effectively with peers and various levels of management
  • Well organized and thorough, with the ability to balance and prioritize

Nice to have

  • Background in information security, data protection and risk management
  • Familiarity or experience with information security industry frameworks (e.g., NIST, CMMC, ISO 27001, PCI, etc.)
  • Deep understanding of risk management concepts
  • Cross functional project management and process development experience

What the JD emphasized

  • information security
  • risk management
  • NIST
  • CMMC
  • ISO 27001
  • PCI