Cloud Remediation Lead - Chicago, United States - Bank of America

Bank of America
Bank of America
Verified Company
Chicago, United States

4 weeks ago

Mark Lane

Posted by:

Mark Lane

beBee recruiter


Description

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection.

Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.


One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world.

We're devoted to being a diverse and inclusive workplace for everyone.

We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.

Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.


Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference.

Join us


This job is responsible for partnering with leaders to balance the needs of the business while ensuring information security and organizational risks are appropriately identified and managed to drive uncompromising cyber security protection.

Key responsibilities include leading in-depth information security risk-based discussions and acting as an integrated business partner with cross-functional leaders to provide blended security and business expertise to ensure appropriate management of information security risks.

Position Summary

An experience senior security professional with expertise in cloud security.

The Senior Information Security Consultant will be part of the Global Information Security (GIS) Cyber Security Assurance (CSA) Infrastructure Remediation Governance team.

In this role, you will play an integral part in ensuring security of the cloud infrastructure by governing and overseeing remediation activities.

As the Cloud Remediation Lead, you will collaborate closely with cross functional teams and stakeholders in IT, business technology groups, Risk Partners, and GIS teams across their respective LOBs.

You will present key findings, progress, and escalate issues to GIS and LOB leadership on a regular basis and be responsible for influencing the stakeholders to prioritize/execute risk management issues and lead remediation efforts.


Key responsibilities:

  • Lead and oversee remediation efforts for identified vulnerabilities and compliance/configuration violations in the cloud infrastructure environment.
  • Analyze findings from security monitoring systems such as Aqua, Qualys Scanning, Network Configuration Compliance, and Security Compliance, to identify and direct a respond to all potential security incidents and data breaches.
  • Review all current and existing vulnerabilities for active and acceptable remediation plans. These plans may be reviewed with LOB point of contacts, Application Owners, Data Owners / Custodians or System Administrators. Verify that remediation plans are implemented per remediation plan and GIS guidelines. Review and identify any potential gaps that may result in possible audit issues.
  • Drive remediation of vulnerabilities and misconfiguration issues in public and private cloud
  • Design and enhance vulnerability management process for Public and Private cloud.
  • Review all vulnerability scan results to identify all security risks and report on findings to appropriate partners.
  • Respond to relevant requests received from stakeholders, or representatives of stakeholders, for investigation of potential reporting issues.
  • Provide all necessary reports and presentations on the status of remediation efforts and all gaps and potential obstacles or issues to management and technical staff.
  • Performs other related duties incidental to the work described herein and all special assignments as needed or assigned.

Required Qualifications:

  • 6+ years of experience in information security and/or project management roles
  • Experience with one or more of Cloud Service Provider (i.e. Red Hat, AWS, and Azure) products and services
  • Excellent communication skills, and the ability to understand and translate cyber security threats from a technical perspective to businessline understanding and execution; ability to communicate risks and propose counter measures to senior technology executives
  • Welldeveloped analytic, qualitative, and quantitative reasoning skills and demonstrated creative problemsolving abilities with complementary skills for log analytics and diagnosis skills utilizing regular expression and/or scripting
  • Ability to work independently on initiatives with little oversight. Motivated and willing to learn
  • Broad technical background utilizing security technologies, such as Cloud, Server and workstation Operating Systems, Network Security, Vulnerability Scanning Engines, and Compliance Management solutions
  • Proven project management Sk

More jobs from Bank of America