• Find preferred job with Jobstinger
  • ID
  • Job type
  • Salary
  • Source
    Bank Of America
  • Date
  • Deadline

Job Description:

Are you passionate about working with the best information security team in the world? Bank of America is hiring top talent to join our innovative and forward thinking team.

What We Do:

At Bank of America, we handle the finances of over 67 million client relationships every day, including helping them save, borrow, and invest for today and for their future. We stand by our clients each and every day giving them the power to realize their personal financial goals and help make their financial lives better.

The Global Information Security organization is responsible for protecting bank information systems, confidential and proprietary data, and customer information. The team:
  • Develops the bank's Information security strategy and policy
  • Manages the Information security program and identifies and addresses vulnerabilities
  • Develops, deploys and manages a risk-based controls portfolio
  • Manages and operates a global security operations center that monitors, detects and responds to cybersecurity incidents

What We're Looking For:

We're looking for the next generation of Cyber security experts - those with a passion for growing a long-term career, building relationships and working with a team of innovative and forward thinking information security professionals. Our cyber team is meant for those looking to make a real impact and build a career in information security. The role is ideal for those who have a passion to work with industry leaders to protect our brand and the customer/client experience by proactively detecting, disrupting, and mitigating cyber security across the organization.

What You'll Get:

From day one, you'll receive training including hands-on practice, personalized coaching and dedicated support throughout your on-boarding experience. With demonstrated success, you'll have the opportunity to advance into many different roles with Global Information Security - with unlimited opportunity to grow throughout your career. You will be supported with dedicated programs, tools, and resources throughout your career journey.

We'll help you:

•Build a successful career at Bank of America through world-class training and on-boarding programs that set you up for success

•Grow in your current role through one-on-one coaching from managers who are invested in your success and training programs that help you excel, build new skills or take on additional responsibility

•Continuously learn and advance your career goals through intentional career paths to the next best role

•Use resources and innovative technologies to optimize the client experience

•Expand your business knowledge and network by partnering with experts in Global Information Security, Global Technology and other lines of business

•Become an expert in what you do

What you can look forward to:

•Ongoing professional development to deepen your skills and optimize your expertise as the industry evolves and changes

•Resources and dedicated support to help you reach your full potential throughout your career

•A benefits program designed to meet the diverse needs of our employees at every stage of their life and help them plan for tomorrow

•Progressive workplace practices and initiatives that promote inclusion

We're a culture that:

•Believes in responsible growth and has a proven dedication to supporting the communities we serve.

•Provides continuous training and developmental opportunities to help people achieve their goals, whatever their background or experience.

•Believes diversity makes us stronger, so we can reflect, connect to and meet the diverse needs of our clients and customers around the world.

•Is committed to advancing our tools, technology, and ways of working. We always put our clients first to meet their evolving needs.

The Cyber Security Defense (CSD) function within Global Information Security is responsible for all aspects of threat intelligence and monitoring, application and network security, and insider threat. In addition, the CSD team drives out the enterprise-wide cyber exercise program.

Manual Ethical Hacking is part of the Global Controls Assurance and Validation Program within Cyber Security Assurance. The program performs assessments to validate the efficacy of Global Information Security controls.

The role will be responsible for conducting application security assessments and penetration tests of the Bank's internal and external web, mobile and web service applications using manual and automated tools in order to uncover and report security vulnerabilities that exist.

Responsibilities include, but are not limited to: • Understanding the requirements of the applications and how to use it • Testing applications using a variety of tools to identify vulnerabilities that could expose the Bank to risk • Monitoring existing and proposed security standard setting groups • Conducting meetings to communicate the findings and implications and set realistic timescales for remediation • Providing technical support to clients, management and staff throughout risk assessments and the implementation of appropriate data security procedures and products • Acting as a SME, providing guidance and knowledge to reduce the vulnerabilities and risk when apps are being created • Sharing knowledge with technical and non-technical colleagues through training sessions • Risk management

Required Skills: • Expert level experience and very detailed technical knowledge in at least 3 of the following areas: general information security; security engineering; application architecture; authentication and security protocols; applications session management; applied cryptography; common communication protocols; mobile frameworks; single sign-on technologies; exploit automation platforms; RESTful web services • One or more of the following certifications (desirable): CISSP, CJEH, OSCP or qualified work experience • Technical expertise in conducting web application ethical hacking assessments. • Ability to demonstrate manual web application testing experience i.e. must be able to simulate a SQL inject/Cross-site script attack without the use of tools • Knowledge of network and Web related protocols/technologies (e.g. UNIX/LINUX, TCP/IP, Cookies) • Experience with vulnerability assessment tools and penetration testing techniques • Solid programming/debugging skills • Experience of using a variety of tools, included, but not limited to, IBM AppScan, Burp and SQL Map • Strong scripting skills desirable • Ability to learn and apply critical thinking in a variety of situations • Effective written and oral communication skills • Ability to multi task and handle multiple projects

Enterprise Job Description: Analyzes, improves, implements, and executes security controls proactively to prevent external threat actors from infiltrating company information or systems. Researches more advanced and complex attempts/efforts to compromise security protocols. Maintains or reviews security systems, assesses security policies that control access to systems, and provides regular status updates to the management team. Typically has 5-10 years of relevant experience and will act as an individual contributor.

Shift:1st shift (United States of America)

Hours Per Week:40

Learn more about this role

Report job

Related Jobs