Info Security Exposure Management Specialist I B
Job Description
:
About Us
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities, and shareholders every day.
One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. Were devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.
Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!
Global Business Services
Global Business Services delivers Technology and Operations capabilities to Lines of Business and Staff Support Functions of Bank of America through a centrally managed, globally integrated delivery model and globally resilient operations.
Global Business Services is recognized for flawless execution, sound risk management, operational resiliency, operational excellence, and innovation.
In India, we are present in five locations and operate as BA Continuum India Private Limited (BACI), a non-banking subsidiary of Bank of America Corporation and the operating company for India operations of Global Business Services.
Process Overview.
Global Information Security (GIS) is responsible for protecting Bank information systems, confidential and proprietary data and customer information. The team develops the Banks information security strategy and policy, manages the information security Program and identifies address vulnerabilities, develops, deploys and manages a risk based controls portfolio, manages and operates at global security operations center that monitors, detects and responds to Cyber security incidents. GIS, Cyber Security Assurance (CSA) team identifiesthe Potential Vulnerabilities and is designed to validate and report potential vulnerabilities identified through Qualys tool and OSINT process addresses external, internet-accessible security concerns or poor internet hygiene impacting Bank of Americas internet reputation. Team works with outside-in approachwhich leverages external open-source intelligence (OSINT) and internal data to analyze internet-accessible hosts associated with Bank of America that pose a potential security risk to the Bank and negatively impact the Banks internet reputation or brand.
.
The Information Security Exposure Management Specialist role will involve identifying risks and promoting Internet hygiene improvement opportunities to enhance the Banks overall public security posture. The role also requires working as part of a team developing methods to quickly reference systems of record (SORs), systems of origin (SOOs) and other available data stores for a comprehensive reliable and timely view of the Banks attack surface and vulnerability exploitability potential, with the goal of enabling answers to the following three questions as quickly as possible.
. Do we have it
. Are we vulnerable
. Is it exploitable
Responsibilities.
- Identify and remove older, no longer maintained Bank branded sites.
- Ability to communicate effectively across all levels of a global finance institution
- Ensure all external assets align to LOB ownership.
- Identify and eradicate end of life software or software in use exposing the Bank to risk.
- Address issues impacting CRR (Cyber Risk Rating) scores that impact the reputational risk of Bank of America
- Submits false positives to Cyber Risk Rating vendors.
- Evaluates true positives for inclusion escalation.
- Proactively perform Risk Analysis (DNS Records Cleanup, Expired/Malformed Digital Certificates)
- Assist CSA/CSD in Identifying P1/CAPD level risks leveraging an outside in view along with Bank data intelligence.
- Escalate issues to management in a timely manner with appropriate severity, exposure and action items this role requires critical thinking, and investigative mindset coupled with effective written and verbal communication skills
- Identifies gaps with external perimeter findings to internal bank policies and raises them up with the team.
- Excellent research skills - able to identify relevant data sources for information about bank technologies, gain an understanding of how things work and be willing to dig in and help identify usage throughout the firm.
- Strong analytical skills/problem solving/conceptual thinking.
- Excellent communication and presentation skills.
- Collaborate with peers and business units in a team-focused environment.
Requirements:
Education: Bachelors degree in IT Discipline
Looking to get Placed? Try our Placement Guarantee Plan
Experience Range: 4 to 6+ Years
Foundational skills.
- Excellent research skills - able to identify relevant data sources for information about bank technologies, gain an understanding of how things work and be willing to dig in and help identify usage throughout the firm
- A broad knowledge of Information security principles
- Knowledge of externally facing network DNS architecture and associated vulnerabilities
- Understanding of Vulnerability Management principles
- Understanding of Risk Assessment Methodologies & Data Analytics background
- Basic network fundamentals, like OSI model, TCP/IP model, DNS Records
- Prior experience in leveraging MS Access or other data repositories.
- Background in Network Security /Application Security preferred.
Desired skills
- Understanding Network devices such as servers, switches, load balancers, etc.
- Qualys and Tanium Tools experience
- Knowledge of information security concepts, research tools, and products
- Ability to work with Technical and Non-Technical business owners
- SQL/Python Basic Knowledge, Power BI
Work Timings. 7.30am to 4.30PM IST / 12:30PM to 09:30PM IST
Job location: Chennai/Hyderabad/Mumbai
Skills
Data AnalyticsPythonAnalyticsSqlIf an employer asks you to pay any kind of fee, please notify us immediately. Jobaaj does not charge any fee from the applicants and we do not allow other companies also to do so.
About Company
Bank of America is one of the world’s largest financial institutions, serving individual consumers, small and middle‑market businesses, and large corporations with a full range of banking, investing, asset management, and risk management products. Headquartered in Charlotte, North Carolina, the bank operates in more than 35 countries and provides access to over 140 currencies.
In 2008, Bank of America acquired Merrill Lynch, one of the most respected names in investment banking and wealth management. Following the acquisition, the investment banking and markets division operated as Bank of America Merrill Lynch (BAML) until 2019, when it was rebranded as BofA Securities, while the wealth management business continues under the Merrill brand. This integration strengthened the bank’s global presence in capital markets, advisory, and private wealth.
In India, Bank of America has been present since 1964, with branches in Mumbai, New Delhi, Chennai, Bengaluru, and Kolkata, and large Global Capability Centers in Gurugram, Hyderabad, Chennai, and Mumbai. The India teams deliver corporate & investment banking, markets, treasury, and technology solutions to clients worldwide, while also supporting the bank’s global operations.
Bank of America offers career opportunities in finance, technology, operations, risk, and analytics, attracting professionals who value innovation, client focus, and global collaboration. The firm is recognised for its sustainability initiatives, diversity & inclusion programs, and community engagement in India.
Important dates & deadlines?
Application Deadline
13 Jul 26, 05:42 PM IST
Similar Jobs
View All

