Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
GIS Policy Regulatory Management Specialist represents Global Information Security (GIS) while working with Compliance, Risk, Legal, FLU's and Enterprise functions, consulting on all regulations with Global Information Security applicability. Expected to read published laws rules regulations and guidance’s (LRRGs), understand how they apply to GIS and map them to GIS policy. Maintain the inventory of LRRGs and mappings in the system of record and update the mappings as needed when policy language changes. Must be able to assess regulatory requirements against GIS policy, controls and assessment proof points. Drive action plans to address any regulatory gaps and ensure accurate risk and compliance reporting. Will work closely with subject matter experts including GIS Policy, Risk, Audit, Lines of Business, Legal, Compliance and external regulators as needed.
Additional expectations of role:
• Ensure Laws, Rules, Regulations and Guides (LRRGs) in the GIS inventory are mapped to GIS policies and identified gaps are addressed to ensure policy coverage of regulatory requirements, industry standards and best practices.
• Breakdown and map assigned Laws, Rules, Regulations and Guides (LRRGs) to GIS policy requirements
• Raise any identified policy language gaps to be validated and remediated
• Perform Impact Assessments for any GIS policy changes (standards and baselines) to ensure coverage is maintained to aligned LRRGs
• Perform Impact Assessments for GIS Policy Exception Types to ensure a policy violation is not created based on aligned LRRGs
• Maintain accurate data for all LRRGs and GIS policy mappings in the system of records through BAU and QA routines
• Publish routine reports for Regulatory Landscape, metrics, newsletters, etc
• Maintain process documentation and playbooks
• Analytical mindset and teamwork to support and improve the GIS Policy Governance ecosystem.
• Technical and business knowledge to ensure policy language gaps are covered by policy and have aligned controls.
• Result-oriented, business focused, and successful individual to interface across multiple organizational units, at various levels.
• Knowledge/experience/exposure with information security topics, including the design, development, testing, implementation or governance of information security practices and solutions
• Knowledge of access management/risk identification and mitigation/project management skills.
Minimum Years of Experience
5
Required Qualifications:
• Previous experience in Information Technology / Information Security
• Ability to identify, analyze and address problems to resolve issues whenever possible in a way that minimizes negative impact and risk to the organization
• Strong critical thinking/analytical skills/problem solving/conceptual thinking
• Highly effective written and verbal communication skills.
• Microsoft Office Proficient (Excel, Word, Outlook, Visio, PowerPoint, etc.)
• Ability to communicate complex information in simple terms (oral and written)
• Strong organization skills with the ability to prioritize requests and workload accordingly
• Strong analysis and fact-based decision-making
• Strong leadership skills and qualities which enable you to work with peers and various levels of management
• Proven ability of risk oriented approach and Strong risk management acumen.
• Influence horizontally and vertically across the organization and diverse audiences with varying degrees of technical understanding
• Ability to work independently on initiatives with little oversight.
• Motivated and willing to learn.
• Quick learner and self-starter
Desired Qualifications
• 5 years of experience operating within an information security environment.
• Bachelor's degree in Information Technology or related field
• Prior Governance, Compliance, and or Audit experience desired.
• Broad awareness of information security operations and/or enterprise information technology (Enterprise data management, application development, network management).
• Familiarity with independent audit, assessment, QA/QC functions desired.
• Leadership competency in geographically diverse matrixed environment.
• Must be comfortable communicating technology impacts and risk to various levels of executive management understanding the need to tailor and deliver appropriate content for given audience.
• Ability to work with Technical and Non Technical business owners
• Experience with Project Management or working with Project Managers
Skills:
Customer and Client FocusInterpret Relevant Laws, Rules, and RegulationsPolicies, Procedures, and GuidelinesProblem SolvingQuality AssuranceBusiness AcumenControls ManagementInnovative ThinkingProcess ManagementStakeholder ManagementBusiness Process AnalysisData GovernanceData Privacy and ProtectionData and Trend AnalysisRisk AnalyticsThis job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)Hours Per Week:
40