
Third Party Cyber Assurance Assessor
Bank of America · Washington, DC
- On site
- Full-time
- $110,000 / year
- Washington, DC
Job highlights
- Assess third-party information security controls.
- Review audit reports like SOC 2 and ISO 27001.
- Identify and report on third-party cyber risks.
- Collaborate with vendors and internal teams.
- Contribute to strategic program development.
About the role
About Bank of America
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!Responsibilities
This job is responsible for performing information security reviews of third parties, such as pre-assessment, assessment, and remediation activities that provide services to the bank. Key responsibilities include validating assessment scope, partnering with vendor managers and third parties to prepare them for the assessment, collecting, and reviewing documentation during the assessment, determining if appropriate information security controls are in place, and completing an assessment of workpapers.Summary
Position will be a member of the Third Party Cyber Assurance Specialized Subcategory Cyber Assurance Program (TPSSCAp) organization in Global Information Security (GIS), responsible for conducting information security assessments of third parties by reviewing independent audit reports (e.g., SOC 2 Type 2, ISO 27001, PCI DSS RoC) or Self Attestation / Self-Certification reports (e.g., SIG, PCI DSS AoC) to document a point of view on the information security posture of the third party. The position will be a key player in driving strategic initiatives focused on the design of Third Party Specialized Subcategory Cyber Assurance (TPSSCA) program requirements, governance routines, and third party risk metrics and reporting. In addition to supporting strategic initiatives, the position will include analyzing and interpreting diverse information security risk indicators to deliver actionable insights into third party information security risk and enable prioritized cyber security assurance approaches. Position requires interaction with the third party cyber procurement team, technical subject matter experts, GIS Policy, and the internal and external third party management community.Required Qualifications
- At least 3 years of relevant experience.
- Previous information technology/security audit/assessment or remediation experience.
- Experience with ISO 27001 and SOC 2 Type 2 control frameworks.
- Previous experience reviewing independent audit reports/certification (e.g., ISO 27001, SOC 2 Type 2, PCI DSS RoC).
- Previous experience reviewing self-attestation/assessment reports (e.g., SIG, PCI DSS AoC).
- Self-starting, organized, and requiring minimal management oversight.
- Ability to operate across organizational boundaries and hierarchies to accomplish tasks.
- Strong analytical skills/problem-solving/conceptual thinking/attention to detail.
- Ability to collaborate effectively with peers and various levels of management.
- Well organized and thorough, with the ability to balance and prioritize.
- Excellent verbal and written communication skills across multiple levels of the organization.
Desired Qualifications
- Background in information security and third party risk management.
- Familiarity or experience with information security industry frameworks (e.g., NIST, ISO, PCI DSS).
- Deep understanding of risk management and reporting concepts.
- Cross-functional project management and process development experience.
- Critical Thinking.
- Data Privacy and Protection.
- Information Systems Management.
- Problem Solving.
- Technology System Assessment.
Key skills/competency
- Third Party Risk Management
- Cyber Assurance
- Information Security Audits
- SOC 2
- ISO 27001
- PCI DSS
- Risk Assessment
- Security Controls
- Vendor Management
- Compliance
Skills & topics
- Cyber Assurance Assessor
- Third Party Risk
- Information Security
- Risk Management
- Audit
- Compliance
- SOC 2
- ISO 27001
- PCI DSS
- Vendor Assessment
- Security Controls
- NIST
- Cyber Security
- Risk Assessment
- Assessor
- Bank of America
How to get hired
- Tailor your resume: Highlight your experience with information security audits, ISO 27001, SOC 2, and third-party risk management.
- Showcase your skills: Emphasize your analytical abilities, attention to detail, and communication skills.
- Understand the role: Familiarize yourself with third-party cyber assurance processes and relevant frameworks.
- Prepare for interviews: Be ready to discuss your experience with risk assessment and control validation.
- Network internally: If possible, connect with current Bank of America employees in similar roles.
Technical preparation
Master ISO 27001 and SOC 2 control frameworks.,Practice reviewing audit reports (SOC 2, PCI DSS).,Understand self-attestation report analysis (SIG, AoC).,Familiarize with NIST cybersecurity principles.
Behavioral questions
Describe a complex security assessment you conducted.,How do you handle disagreements with third parties?,Explain how you prioritize multiple assessment tasks.,How do you ensure attention to detail in reviews?
Frequently asked questions
- What is the primary focus of the Third Party Cyber Assurance Assessor role at Bank of America?
- The Third Party Cyber Assurance Assessor at Bank of America is primarily responsible for conducting information security reviews of third parties that provide services to the bank. This involves assessing their security controls, reviewing audit reports, and identifying potential risks to ensure the bank's security posture is maintained.
- What specific audit reports or frameworks are important for a Third Party Cyber Assurance Assessor at Bank of America?
- Experience with reviewing independent audit reports such as SOC 2 Type 2, ISO 27001, and PCI DSS RoC, as well as self-attestation reports like SIG and PCI DSS AoC, is crucial for this role at Bank of America. Familiarity with other frameworks like NIST is also beneficial.
- What level of experience is required for the Third Party Cyber Assurance Assessor position at Bank of America?
- Bank of America requires candidates for the Third Party Cyber Assurance Assessor role to have at least 3 years of relevant experience. Previous experience in information technology, security audit, assessment, or remediation is highly preferred.
- How does Bank of America approach work arrangements for this role?
- Bank of America is committed to an in-office culture, with specific requirements for office-based attendance. While there are requirements for office presence, there may be an appropriate level of flexibility for teammates and businesses based on role-specific considerations.
- What are the key soft skills needed for a Third Party Cyber Assurance Assessor at Bank of America?
- Key soft skills for this role include being a self-starter, highly organized, possessing strong analytical and problem-solving abilities, attention to detail, the capacity to operate across organizational boundaries, and excellent verbal and written communication skills to collaborate effectively.
- What does 'Responsible Growth' mean in the context of Bank of America's mission?
- Responsible Growth at Bank of America means pursuing business objectives in a way that benefits clients, teammates, communities, and shareholders. It encompasses an inclusive workplace, talent development, teammate well-being, performance recognition, and community impact.
- How can I best demonstrate my qualifications for the Third Party Cyber Assurance Assessor role during the application process?
- To best demonstrate your qualifications, tailor your resume to highlight specific experiences with the required frameworks (ISO 27001, SOC 2) and report types. Be prepared to articulate your problem-solving approach and how you've managed risks in previous roles during interviews.