Analyst I - System Administration and Support

Chennai Tamil Nadu, India

Bank of America

What would you like the power to do? At Bank of America, our purpose is to help make financial lives better through the power of every connection.

View all jobs at Bank of America

Apply now Apply later

Job Description:

About Us

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection.  Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities, and shareholders every day.

One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We are devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.

Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.

Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!

Global Business Services

Global Business Services delivers Technology and Operations capabilities to Lines of Business and Staff Support Functions of Bank of America through a centrally managed, globally integrated delivery model and globally resilient operations.

Global Business Services is recognized for flawless execution, sound risk management, operational resiliency, operational excellence, and innovation.

In India, we are present in five locations and operate as BA Continuum India Private Limited (BACI), a non-banking subsidiary of Bank of America Corporation and the operating company for India operations of Global Business Services.

Process Overview

The Global Information Security (GIS) team is responsible for protecting bank information systems, confidential and proprietary data, and customer information. The team develops the bank’s Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities, develops, deploys and manages a risk-based controls portfolio, and manages and operates global security operations centers that monitor, detect and responds to cybersecurity incidents.

The GIS team goal is to ensure that the control processes and effectiveness are within the identified risk tolerance.  The team manages the performance and effectiveness of the working control through the establishment of metrics with thresholds. They also validate the reasonability of Laws, Rules and Regulations mapping alignment to the controls, as aligned by the GIS Policy team.

Job Description

This position will be a member of the Business Information Security Office (BISO) Governance and Execution team. The role requires executing against the quality assurance strategy to validate cyber security risk is being mitigated appropriately across lines of business as well as Third Parties. This role will support the ERP Review Framework Strategy to ensure a consistent risk management process is being leveraged when assessing vulnerability risks by ensuring that appropriate mitigations and/or compensating controls are applied if remediation cannot be completed within SLA. For each Observation there must be relevant Mitigating or Compensating Control(s) in place before an exception can be considered and Level of residual risk is determined based on the completeness of the aligned Controls. In conjunction of this role, the key team members will perform QAs on additional processes ensuring adherence to audit process guidelines. The QA output will be utilized to identify and incorporate future process enhancements to maintain consistency and quality across BISO functions.

Responsibilities

  • Perform monthly risk review on business justification and exception expiration date for GIS Policy exception requests for GIS employees
  • Ability to evaluate business justification to ensure it sufficiently describes a valid business purpose and expiration date is for acceptable timeframe per indicated use
  • Ability to apply quality standards consistently during risk review and document results defensibility and clearly
  • Strong background in information security and risk management
  • Analyze vulnerabilities and validation of remediation plans
  • Skilled in requirement analysis, test plan/scenario preparations, design and execution, defect logging and management
  • Self-starter with minimal management oversight
  • Strong analytical skills/problem solving/conceptual thinking/attention to detail.
  • Ability to work effectively with peers and various levels of management.
  • Well organized and thorough, with the ability to balance and prioritize assigned tasks
  • Ability to take ownership of an initiative/issue through completion.
  • Ability to work in a collaborative environment.
  • Process reporting and strategic thinking of process improvisation.
  • Ability to work with minimal supervision.
  • Ability to own and deliver on complex initiatives in a high paced, evolving environment.
  • Knowledge in Application security, Risk assessments, Cloud technologies, GRC (Governance, Risk, and Compliance) with emphasis on security processes and controls is desirable.

Requirements

Education: Bachelor’s Degree or technology and cybersecurity background

Certification: CEH, CompTIA Security+, CISA, CRISC, CISM, CISSP (Good to have)

Experience Range: 4+ years

    Foundational skills:

    • Extensive knowledge of analyzing vulnerabilities and remediation
    • Good experience in performing Quality reviews, identifying gaps and following up with stakeholders on closing the observations
    • Knowledge/Experience in Application security, Risk assessments, Cloud technologies, GRC (Governance, Risk, and Compliance) and/or third-party management with emphasis on security processes and controls
    • Experience evaluating threats/risks posed by new technologies spanning networks, hardware, software,
    • Ability to evaluate technology to ensure cyber-secure development that adheres to internal application policy, standards, and baselines.
    • Bachelor’s degree in information technology, information security or related field
    • Must be flexible to work during hours that needs collaboration with US partners.

    Desired skills:

    • Minimum 4 years of experience in cyber security or a technology-related field
    • Strong project management experience
    • Strong analytical skills/problem solving/critical thinking.
    • Able to work with technical and non-technical business owners.
    • Able to take ownership of an initiative/issue through completion.
    • Able to work in a collaborative environment.
    • Able to own and deliver on complex initiatives in a high paced, evolving environment.
    • Excellent verbal and written communication skills; Ability to communicate with business leaders, users and tech-savvy stakeholders.
    • Proficient in MS Office (Word, Excel, PowerPoint)
    • Ability to work with minimal supervision.

    Work Timings:  13:30 – 22:30 IST

    Job Location: Chennai / Mumbai

    Apply now Apply later

    * Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

    Job stats:  5  0  0
    Categories: Admin Jobs Analyst Jobs

    Tags: Application security Banking BISO CEH CISA CISM CISSP Cloud Compliance CompTIA CRISC ERP Governance Risk assessment Risk management Security strategy Strategy Vulnerabilities

    Perks/benefits: Career development Flex hours Startup environment

    Region: Asia/Pacific
    Country: India

    More jobs like this

    Explore more career opportunities

    Find even more open roles below ordered by popularity of job title or skills/products/technologies used.