Job Description:
About Us
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Global Business Services
Global Business Services delivers Technology and Operations capabilities to Lines of Business and Staff Support Functions of Bank of America through a centrally managed, globally integrated delivery model and globally resilient operations.
Global Business Services is recognized for flawless execution, sound risk management, operational resiliency, operational excellence and innovation.
In India, we are present in five locations and operate as BA Continuum India Private Limited (BACI), a non-banking subsidiary of Bank of America Corporation and the operating company for India operations of Global Business Services.
Process Overview*
Global Information Security (GIS) is responsible for protecting Bank information systems, confidential and proprietary data, and customer information. The team develops the Bank’s Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities, Develops, deploys and manages a risk-based controls, portfolio, Manages and operates global security operations center that monitor, detect and respond to cybersecurity incidents.
Job Description*
The associate will be responsible for assessing the compliance of internal and external applications, as well as enterprise and GIS policies, against applicable regulatory frameworks and the bank’s established information security policies and standards. The ideal candidate will have a strong information security background, along with excellent communication and interpersonal skills to effectively engage and collaborate with a broad range of stakeholders.
The GIS Policy Assessment team works closely with policy owner, application teams, risk partners, remediation teams, and subject‑matter experts across various technologies, including platforms, databases, operating systems, and at application layers. The role operates in a fast‑paced environment with time‑sensitive deliverables and requires a high level of flexibility and adaptability.
Candidates should possess strong technical writing skills to produce clear, actionable, and easy‑to‑understand assessment reports covering diverse technical and policy‑related topics.
Responsibilities*
As a GIS Policy Assessment Specialist, the associate will be responsible for the following:
- Assess the compliance of internal and external applications against established bank information security policies and standards, including areas such as confidential data protection, authentication services, user access and accounts, and log monitoring.
- Work closely with application owners, technical teams, risk partners, remediation teams, and subject‑matter experts across a wide range of applications and technologies.
- Support the development of compliance assessment reports for assigned areas, incorporating inputs from assessment activities and management reviews.
- Assist in the development, maintenance, and review of GIS‑owned policies and standards, as well as FLU/CF‑owned policies, standards, and procedures, to ensure alignment with regulatory requirements and identification of operational risks.
- Monitor the regulatory environment to identify changes relevant to assigned areas of coverage and maintain an up‑to‑date regulatory inventory. Support communication of regulatory changes and ensure that policies, standards, procedures, and processes are appropriately implemented or updated.
- Complete assigned assessments and deliverables in line with defined Service Level Agreements (SLAs).
- Apply independent judgment in selecting methods, techniques, and evaluation criteria to achieve assessment objectives.
- Perform assessments, including pre‑assessment reviews of systems of record and supporting documentation.
- Identify control gaps and failed controls, and submit observations to continuous monitoring, risk, and leadership dashboards.
- Facilitate evidence collection and coordination with Front Line Units (FLUs).
- Perform Level 1 quality assurance reviews and determine the level of compliance.
- Track and report assessment status, progress, and outcomes to the leadership tea
Requirements*
Education* B.E. / B. Tech/M.E. /M. Tech/B.Sc./M.Sc./BCA/MCA (prefer IT/CS specialization)
Certifications If Any: NA
Experience Range* 4-6+ years
Foundational skills*
- Strong experience in Information Security or IT Audit.
- Good understanding of global regulators and regulatory requirements relevant to information security and technology risk.
- Excellent technical writing, presentation‑building, and verbal communication skills.
- Ability to work effectively with stakeholders across different technical skill levels and organizational layers.
- Strong stakeholder management skills with a high level of attention to detail.
- Ability to communicate clearly with both technology/development teams and business partners, including translating technical concepts into business‑friendly language.
- Highly organized, self‑motivated, and capable of delivering results with minimal supervision.
- Proactive and creative problem solver with the ability to anticipate team needs and suggest improvements beyond stated requirements.
- Naturally curious, with the ability to quickly develop expertise in the data, systems, and tools used by the team.
- Strong relationship‑building, collaboration, and facilitation skills.
- Good working knowledge of operating systems, database management concepts, the OSI model, and Identity and Access Management (IAM) processes.
- Proficient in Microsoft Office tools (Word, PowerPoint, Excel), along with Tableau and SharePoint.
Desired skills
- Information Security certifications, including ISO27001 / CISSP / CEH / CISM / CISA.
- Experience in coordinating team projects
Work Timings* 01:30 PM to 11:30 PM IST
Job Location* Chennai and Mumbai

