Global Information Security Regulatory Management Specialist

Bank of America Bank of America · Banking · Addison, TX

This role focuses on managing regulatory requirements within Global Information Security (GIS) at Bank of America. The specialist will map laws, rules, regulations, and guidance (LRRGs) to GIS policies, identify and remediate gaps, and ensure accurate risk and compliance reporting. The role involves collaboration with various internal teams and external regulators, maintaining an inventory of LRRGs, and assessing regulatory impacts on GIS policies and controls.

What you'd actually do

  1. Ensure Laws, Rules, Regulations, and Guides (LRRGs) within the GIS inventory are effectively mapped to GIS policies, with any gaps identified, validated, and remediated to maintain full coverage of regulatory requirements, industry standards, and best practices.
  2. Conduct impact assessments for GIS policy changes (including standards and baselines) to ensure continued alignment with LRRGs, and evaluate Policy Exception Types to prevent unintended policy violations.
  3. Maintain accurate LRRG-to-policy mappings within the system of record through consistent BAU and QA routines, and deliver routine reporting on the regulatory landscape and key metrics.
  4. Sustain up-to-date process documentation and playbooks to enable operational consistency and efficiency.
  5. Apply strong analytical thinking and collaboration to continuously enhance the GIS Policy Governance ecosystem.

Skills

Required

  • 5 years of experience operating within an information security environment.
  • Ability to identify, analyze and address problems to resolve issues whenever possible in a way that minimizes negative impact and risk to the organization
  • Strong critical thinking/analytical skills/problem solving/conceptual thinking
  • Highly effective written and verbal communication skills.
  • Microsoft Office Proficient (Excel, Word, Outlook, Visio, PowerPoint, etc.)
  • Ability to communicate complex information in simple terms (oral and written)
  • Strong organization skills with the ability to prioritize requests and workload accordingly
  • Strong analysis and fact-based decision-making
  • Strong leadership skills and qualities which enable you to work with peers and various levels of management
  • Proven ability of risk oriented approach and Strong risk management acumen.
  • Influence horizontally and vertically across the organization and diverse audiences with varying degrees of technical understanding
  • Ability to work independently on initiatives with little oversight.
  • Motivated and willing to learn.
  • Quick learner and self-starter

Nice to have

  • Bachelor's degree in Information Technology or related field
  • Prior Governance, Compliance, and or Audit experience desired.
  • Broad awareness of information security operations and/or enterprise information technology (Enterprise data management, application development, network management).
  • Familiarity with independent audit, assessment, QA/QC functions desired.
  • Leadership competency in geographically diverse matrixed environment.
  • Must be comfortable communicating technology impacts and risk to various levels of executive management understanding the need to tailor and deliver appropriate content for given audience.
  • Ability to work with Technical and Non-Technical business owners
  • Experience with Project Management or working with Project Managers

What the JD emphasized

  • regulatory requirements
  • GIS policy
  • risk and compliance reporting
  • information security practices