Evaluation Analyst

Bank of America Bank of America · Banking · Chicago, IL +2

The Evaluation Analyst role within Bank of America's Global Information Security organization focuses on assessing cyber threats and risks, evaluating security controls, and identifying remediation opportunities. The role involves analyzing threats and incidents, documenting defensive postures, and conducting quality assurance reviews to ensure comprehensive and accurate threat assessments. It requires strong technical writing, information security knowledge, and familiarity with cyber industry frameworks.

What you'd actually do

  1. Analyzes threats and incidents to the bank.
  2. Identifies gaps to be remediated by process and control owners.
  3. Evaluates and influences the improvement of Bank of America’s risk and control environment for cyber security threats and emerging risks.
  4. Analyzes threats and incidents sourced from GIS partner teams to identify and triage process and control weaknesses in context of risks arising from the threat.
  5. Documents defensive posture, process and control weaknesses, and overall risk of each threat.

Skills

Required

  • Critical Thinking
  • Customer and Client Focus
  • Information Systems Management
  • Problem Solving
  • Threat Analysis
  • Cyber Security
  • Policies, Procedures, and Guidelines Management
  • Quality Assurance
  • Risk Analytics
  • Technology System Assessment
  • Business Acumen
  • Business Intelligence
  • Data Privacy and Protection
  • Data and Trend Analysis
  • Stakeholder Management

Nice to have

  • Experience with cyber threat intelligence collection, analysis, and reporting.
  • Experience responding to and managing security incidents and events.
  • Experience creating, executing, and documenting assessments and exercises in JIRA.

What the JD emphasized

  • Strong technical writing capabilities
  • Functional knowledge of information security, IT infrastructure, and risk management
  • Ability to prioritize and manage time effectively and work independently with minimal direction
  • Knowledge of Cyber Industry Frameworks like MITRE/NIST
  • Strategic thinking AND attention to detail – ability to think “like a threat actor.”
  • Proficient computer/analytics skills – esp. Jira, Excel, Word, Power Point, Alteryx, etc.
  • General understanding of bank policies, specific to data and privacy, third parties, incident management, vulnerability management, etc.