Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We’re devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
Role Overview:
As the Security Control Design Lead, you will leverage your expertise in data loss prevention and cloud security to foster collaborative efforts across teams. This role combines expertise in DLP technologies and cloud security to drive innovative solutions that enhances the organizations ability to protect sensitive data. Join us in driving forward-thinking initiatives that integrate DLP strategies into our cloud environment.
Key Responsibilities:
- Design and drive the implementation of cloud security solutions, ensuring DLP controls are effectively integrated into cloud environments.
- Document technical capabilities and solution configurations; this may include conceptual, logical, and physical diagrams; new environment design documents etc.
- Collaborate with internal teams to ensure solutions are built, deployed, and modified as applicable.
- Apply technical skills to recommend, support, improve, and operate information protection technologies with limited supervision.
- Assess and make recommendations regarding current and proposed cloud architectures, strategies and systems.
- Establish reporting routines that provide visibility to effective execution of long-term maturity/strategic plans.
- Consult with control owners and others on developing complete and repeatable control processes including control documentation such as procedures, control evidence, narratives, control matrices, metrics etc.
- Develop high-level presentations tailored for executives and stakeholders.
Required Skills
- Strategic mindset with proven experience deploying Data Loss Prevention (DLP) Technologies in a cloud environment
- Experience with developing performance baselines for DLP tools
- Experience in administration of a DLP tool which includes configuring policies, upgrading and disaster recovery of DLP operations planning
- Security and systems administration certifications preferred (CISSP, CISM, GSEC, MCSE, etc.)
- Understanding of technical and organizational security vulnerabilities, threats, and risks
- Strong analytical, data analysis and problem solving skills, including strong attention to detail (e.g. you should be comfortable working on problems that have a fair amount of ambiguity at the onset).
- Exceptional communication skills and the ability to explain yourself concisely and accurately.
- Ability to troubleshoot and solve complex problems rapidly
Desired Skills
- Experience operating and tuning DLP technologies
- Experience with CASB solutions, Microsoft Purview,, Proofpoint, M365
- Cloud platform familiarity as it relates to DLP solutions (AWS, Azure)
- Operating Systems (Windows/Mac/Linux)
- Basic Networking - VPN, TCP/UDP protocols
- Basic Encryption - SSL, AES, IPsec, Key Management, Certificates
- Ancillary Services - DNS, Web Server, LDAP/AD, Database technologies
- Intermediate Level Scripting - e.g., Python, PowerShell
Enterprise Job Description: This job is responsible for developing and managing enterprise-wide information security policies, procedures, and standards. Key responsibilities include applying cyber security knowledge and an understanding of laws, rules and regulations to maintain and manage policies, execute and streamline processes, identify gaps in coverage, and manage risk reduction in a policy governance lifecycle. Job expectations include aligning processes and controls to requirements and reporting on adherence to the enterprise policy.
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40