Third Party Cyber Assurance Assessor

Bank of America Bank of America · Banking · Denver, CO +2

This role performs information security reviews of third parties, assessing their controls by reviewing independent audit reports (e.g., SOC 2 Type 2, ISO 27001, PCI DSS RoC) or Self Attestation / Self-Certification reports (e.g., SIG, PCI DSS AoC) to determine the third party's information security posture. The position also contributes to strategic initiatives for the Third Party Cyber Assurance Program, analyzing risk indicators to provide insights and enable prioritized assurance approaches.

What you'd actually do

  1. performing information security reviews of third parties, such as pre-assessment, assessment, and remediation activities that provide services to the bank.
  2. validating assessment scope, partnering with vendor managers and third parties to prepare them for the assessment, collecting, and reviewing documentation during the assessment, determining if appropriate information security controls are in place, and completing an assessment of workpapers.
  3. conducting information security assessments of third parties by reviewing independent audit reports (e.g., SOC 2 Type 2, ISO 27001, PCI DSS RoC) or Self Attestation / Self-Certification reports (e.g., SIG, PCI DSS AoC) to document a point of view on the information security posture of the third party.
  4. driving strategic initiatives focused on the design of Third Party Specialized Subcategory Cyber Assurance (TPSSCA) program requirements, governance routines, and third party risk metrics and reporting.
  5. analyzing and interpreting diverse information security risk indicators to deliver actionable insights into third party information security risk and enable prioritized cyber security assurance approaches.

Skills

Required

  • 3 years of relevant experience
  • Previous security audit/assessment or remediation experience
  • Experience with ISO 27001 and SOC 2 Type 2 control frameworks
  • Previous experience reviewing independent audit reports / certification (e.g., ISO 27001, SOC 2 Type 2, PCI DSS RoC)
  • Previous experience reviewing self attestation / assessment reports (e.g., SIG, PCI DSS AoC)
  • Self-starting, organized, and requiring minimal management oversight
  • Ability to operate across organizational boundaries and hierarchies to accomplish tasks
  • Strong analytical skills/problem solving/conceptual thinking/attention to detail
  • Ability to collaborate effectively with peers and various levels of management
  • Well organized and thorough, with the ability to balance and prioritize
  • Excellent verbal and written communication skills across multiple levels of the organization

Nice to have

  • Background in information security and third party risk management
  • Familiarity or experience with information security industry frameworks (e.g., NIST, ISO, PCI DSS)
  • Deep understanding of risk management and reporting concepts
  • Cross functional project management and process development experience
  • Critical Thinking
  • Data Privacy and Protection
  • Information Systems Management
  • Problem Solving
  • Technology System Assessment

What the JD emphasized

  • relevant experience
  • information security controls
  • third party risk management