Bank of America Logo

Bank of America

Controls Mapping Governance Lead - Global Information Security

Posted Yesterday
Be an Early Applicant
In-Office
2 Locations
78K-136K Annually
Mid level
In-Office
2 Locations
78K-136K Annually
Mid level
Supports enterprise information security policy governance by interpreting regulatory and policy requirements, breaking them into must-statements, mapping them to processes and controls, and evaluating evidence. The role reviews technical documentation, challenges control-owner responses, identifies gaps or partial coverage, validates data, documents defensible decisions, and escalates issues through governance channels. It requires cybersecurity, technology risk, audit, compliance, or controls-governance experience in a regulated environment, along with strong analytical and communication skills.
The summary above was generated by AI

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

The Controls Mapping Governance team is seeking an information security professional with experience in cybersecurity, technology infrastructure, audit, or regulatory or policy requirements.

This role supports the enterprise policy governance lifecycle by interpreting information security requirements, identifying the processes and controls that may address those requirements, and determining whether the proposed coverage is sufficiently supported.

The successful candidate will evaluate requirements at the individual must-statement level, develop preliminary coverage recommendations, engage process and control owners, and assess supporting evidence. The candidate must be comfortable discussing technical concepts with subject matter experts and determining whether a documented process or control logically addresses the requirement’s intent, scope, and expected outcome.

Responsibilities
•    Interpret laws, rules, regulations, policies, and standards; break complex requirements into individual must statements; and define the required outcome, scope, accountable parties, and expected evidence.
•    Identify and assess candidate processes, controls; develop preliminary coverage recommendations; and determine whether coverage is direct, supporting, partial, or insufficient.
•    Review technical processes and challenge owner responses to determine whether the documented activity, scope, ownership, dependencies, limitations, and evidence support the proposed mapping.
•    Document clear, defensible mapping decisions and determine whether proposed coverage should be accepted, clarified, treated as partial or a gap, or escalated through established governance channels.
•    Use data and approved tools to support requirement interpretation, coverage identification, response review, reporting, and process improvement, while independently validating all outputs and maintaining decision accountability.

Required Qualifications
•    3+ years of experience in information security, cybersecurity risk, technology risk, controls governance, policy governance, compliance, audit, or a related field within a regulated environment.
•    Working knowledge of cybersecurity concepts, technology infrastructure, and security domains such as identity and access management, network security, cloud security, application security, data protection, vulnerability management, monitoring, incident response, or configuration management.
•    Ability to understand how security processes and controls operate across systems, applications, infrastructure, data, users, and technologies, without needing to be an engineer or subject matter expert in every domain.
•    Experience reviewing technical procedures, process flows, control descriptions, system documentation, and evidence artifacts to identify incomplete responses, unsupported conclusions, exclusions, failure conditions, or gaps in coverage.
•    Strong analytical and communication skills, including the ability to question technical subject matter experts constructively, distinguish direct coverage from general alignment, and document clear, defensible mapping decisions for technical and senior audiences.
•    Ability to evaluate and independently validate data against authoritative requirements, approved inventories, owner responses, and supporting evidence rather than relying solely on owner conclusions.

Desired Qualifications
•    Knowledge of cybersecurity frameworks and standards, such as NIST, ISO/IEC 27001, COBIT, CIS Controls, or comparable frameworks.
•    Experience mapping requirements to processes, controls, control objectives, assessments, or other governance mechanisms.
•    Familiarity with governance, risk, and compliance platforms, and SharePoint workflows.
•    Experience working with technology teams, policy or standard owners, control owners, risk partners, auditors, compliance functions, or regulators.
•    Relevant cybersecurity, risk, audit, cloud, or controls certification.

Required Skills
1. Customer and Client Focus
2. Interpret Relevant Laws
3. Rules
4. and Regulations
5. Policies
6. Procedures
7. and Guidelines
8. Problem Solving
9. Quality Assurance
10. Business Acumen

Shift:

1st shift (United States of America)

Hours Per Week: 

40

Pay Transparency details

US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)

Pay and benefits information

Pay range$78,200.00 - $136,300.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Similar Jobs

11 Minutes Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
220K-260K Annually
Senior level
220K-260K Annually
Senior level
Food • Software
Leads accounting operations for a remote, multi-entity organization, including monthly close, consolidation, financial reporting, billing, revenue recognition, banking, AP, payroll, audits, tax compliance, and internal controls. Manages a team of 10, partners with finance and business leaders, oversees external audit and tax relationships, and drives process automation and scalable accounting systems.
Top Skills: CartaFinancial ReportingInternal ControlsMulti-Entity ConsolidationNetSuiteRampRevenue RecognitionSales And Use Tax ComplianceStock-Based CompensationUs Gaap
Yesterday
Remote or Hybrid
United States
111K-162K Annually
Senior level
111K-162K Annually
Senior level
Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Own revenue forecasting, business planning, performance reporting, financial modeling, and business analytics for the consumer business. Partner with leaders to define and analyze key metrics, deliver recurring performance updates and deep dives, and generate decision-support insights. Build models covering regional forecasts, LTV/CAC, content benchmarking, and marketing ROI. Improve FP&A processes, systems, reporting automation, data accuracy, and scalability.
Top Skills: ExcelGoogle SuiteIbm Tm1NetSuiteOracle Essbase
Yesterday
Remote or Hybrid
United States
Senior level
Senior level
eCommerce • Fintech • Payments • Software
Build and productionize applied AI/ML systems (predictive ordering and agentic copilots) end-to-end, drive measurable business KPI impact, collaborate with product/engineering, implement model-ops, observability, HITL workflows, and mentor peers.
Top Skills: Agent TechnologiesAWSGCPHuman-In-The-Loop (Hitl)LlmsObservability/MonitoringRanking/RecommendationRetrieval SystemsSelf-Hosted Agent InfrastructureVector Search

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account