Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Enterprise Infrastructure Remediation Governance Analyst - Cloud

AT Bank of America
Bank of America

Enterprise Infrastructure Remediation Governance Analyst - Cloud

Denver, CO

CO Salary Range: USD 98,200.00 - 146,600.00 per year

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.

One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.

Want more jobs like this?

Get jobs in Denver, CO delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.


Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.

Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!

Job Description:

This position will be a member of the Cybersecurity Assurance (CSA) Global Information Security (GIS) Enterprise Infrastructure Remediation Governance team. In this role, you will help drive infrastructure remediation efforts to protect the confidentiality, integrity, and availability of the line of businesses' (LOB) information assets with a specific focus on cloud computing. You will partner with LOB points of contact, technology points of contact, and application teams to track and/or develop remediation plans for identified vulnerabilities.

You will present key findings, progress, and all hurdles and issues to GIS and LOB leadership on a regular basis and be responsible for influencing the stakeholders to prioritize/execute risk management issues and drive remediation efforts. The Information Security Governance Analyst will carry out these responsibilities in collaboration with IT, business technology groups, risk partners and GIS teams across their respective LOBs.

Key responsibilities:

  • Analyze findings from security monitoring systems such as Aqua, Qualys Scanning, Network Configuration Compliance, and Security Compliance, to identify and direct a respond to all potential security incidents and data breaches.
  • Review all current and existing vulnerabilities for active and acceptable remediation plans. These plans may be reviewed with LOB point of contacts, Application Owners, Data Owners / Custodians or System Administrators. Verify that remediation plans are implemented per remediation plan and GIS guidelines. Review and identify any potential gaps that may result in possible audit issues.
  • Drive remediation of vulnerabilities and misconfiguration issues in public and private cloud
  • Design and enhance vulnerability management process for Public and Private cloud.
  • Assist in improving the governance of end-user remediation and act as the subject matter expert of end-user remediation governance.
  • Review all vulnerability scan results to identify all security risks and report on findings to appropriate partners.
  • Respond to relevant requests received from stakeholders, or representatives of stakeholders, for investigation of potential reporting issues.
  • Provide all necessary reports and presentations on the status of remediation efforts and all gaps and potential obstacles or issues to management and technical staff.
  • Performs other related duties incidental to the work described herein and all special assignments as needed or assigned.

Qualifications:

  • 4+ years of experience in information security and/or project management roles
  • Familiarity with cloud-native application development and application modernization
  • Familiarity with one or more of Cloud Service Provider (i.e. Red Hat, AWS, and Azure) products and services
  • Good communication skills, and the ability to understand and translate cyber security threats from a technical perspective to business-line understanding and execution; ability to communicate risks and propose counter measures to senior technology executives
  • Well-developed analytic, qualitative, and quantitative reasoning skills and demonstrated creative problem solving abilities with complementary skills for log analytics and diagnosis skills utilizing regular expression and/or scripting
  • Ability to work independently on initiatives with little oversight. Motivated and willing to learn
  • Broad technical background utilizing security technologies, such as Cloud, Server and workstation Operating Systems, Network Security, Vulnerability Scanning Engines, and Compliance Management solutions
  • Strong PC skills including Microsoft Office applications
  • Proven project management Skills

Desired:

  • Bachelors and/or Master's degree in Computer Science, Information Technology or related field
  • Strong analytical skills/problem solving/conceptual thinking
  • Ability to effectively communicate with Technical and Non-Technical business owners
  • Assist with internal efficiencies projects and development

Skills:

  • Controls Management
  • Cyber Security
  • Data Governance
  • Information Systems Management
  • Risk Management
  • Architecture
  • Customer and Client Focus
  • Executive Presence
  • Threat Analysis
  • Vendor Management
  • Advisory
  • Business Acumen
  • Business Intelligence
  • Cloud Solutions
  • Technology System Assessment

Enterprise Role Overview:
This job is responsible for supporting Line of Business leaders by balancing the needs of the business while ensuring information security risk is appropriately identified and managed to drive uncompromising cyber security protection. Key responsibilities include applying an understanding of the business and engaging with technology partners, business partners, and Global Information Security teams to provide blended security and business expertise to ensure appropriate management of information security risks.

Shift:
1st shift (United States of America)

Hours Per Week:
40

Pay Transparency details

US - CO - Denver - 1144 15th St (CO9926)

Pay and benefits information

Pay range

$98,200.00 - $146,600.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Client-provided location(s): Denver, CO, USA
Job ID: BankOfAmerica-JR-24037792
Employment Type: Full Time

Perks and Benefits

  • Health and Wellness

    • FSA
    • HSA
    • On-Site Gym
    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • Life Insurance
  • Parental Benefits

    • Non-Birth Parent or Paternity Leave
    • Birth Parent or Maternity Leave
  • Vacation and Time Off

    • Leave of Absence
    • Personal/Sick Days
    • Paid Holidays
    • Paid Vacation
    • Sabbatical
  • Financial and Retirement

    • Performance Bonus
    • Company Equity
    • 401(K) With Company Matching
  • Professional Development

    • Promote From Within
    • Mentor Program
    • Access to Online Courses
    • Lunch and Learns
    • Tuition Reimbursement
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program