Cyber Security Authentication Risk Assessor - Open Web Application Security Project (OWASP) Application Security Verification Standard (ASVS)
Denver, Colorado;Washington, District of Columbia; Jacksonville, Florida; Jersey City, New Jersey; Chicago, Illinois
**Job Description:**
**Are you passionate about working with the best information security team in the world?** **Bank of America is hiring top talent to join our innovative and forward thinking team.**
**What We Do:**
At Bank of America, we handle the finances of over 67 million client relationships every day, including helping them save, borrow, and invest for today and for their future. We stand by our clients each and every day giving them the power to realize their personal financial goals and help make their financial lives better.
The Global Information Security organization is responsible for protecting bank information systems, confidential and proprietary data, and customer information. The team:
+ Develops the banks Information security strategy and policy
+ Manages the Information security program and identifies and addresses vulnerabilities
+ Develops, deploys and manages a risk-based controls portfolio
+ Manages and operates a global security operations center that monitors, detects and responds to cybersecurity incidents
**What Were Looking For:**
Were looking for the next generation of Cyber security experts those with a passion for growing a long-term career, building relationships and working with a team ofinnovative and forward thinkinginformation security professionals. Our cyber team is meant for those looking to make a real impact and build a career in information security. The role is ideal for those who have a passion to work with industry leaders to protect our brand and the customer/client experience by proactively detecting, disrupting, and mitigating cyber security across the organization.
**What Youll Get:**
From day one, youll receive training including hands-on practice, personalized coaching and dedicated support throughout your on-boarding experience. With demonstrated success, youll have the opportunity to advance into many different roles with Global Information Security with unlimited opportunity to grow throughout your career. You will be supported with dedicated programs, tools, and resources throughout your career journey.
**Well help you:**
Build a successful career at Bank of America through world-class training and on-boarding programs that set you up for success
Grow in your current role through one-on-one coaching from managers who are invested in your success and training programs that help you excel, build new skills or take on additional responsibility
Continuously learn and advance your career goals through intentional career paths to the next best role
Use resources and innovative technologies to optimize the client experience
Expand your business knowledge and network by partnering with experts in Global Information Security, Global Technology and other lines of business
Become an expert in what you do
**What you can look forward to:**
Ongoing professional development to deepen your skills and optimize your expertise as the industry evolves and changes
Resources and dedicated support to help you reach your full potential throughout your career
A benefits program designed to meet the diverse needs of our employees at every stage of their life and help them plan for tomorrow
Progressive workplace practices and initiatives that promote inclusion
**Were a culture that:**
Believes in responsible growth and has a proven dedication to supporting the communities we serve.
Provides continuous training and developmental opportunities to help people achieve their goals, whatever their background or experience.
Believes diversity makes us stronger, so we can reflect, connect to and meet the diverse needs of our clients and customers around the world.
Is committed to advancing our tools, technology, and ways of working. We always put our clients first to meet their evolving needs.
**Role Description:**
The Authentication Risk Assessor performs research, analysis, and testing of authentication applications leveraging industry standard baselines to identify potential vulnerabilities that could be exploited by a threat actor. The assessor clearly documents their findings and sometimes assist the Line of Businesses with questions regarding these findings and associated remediation efforts.
The successful candidate will have a strong application security assessment background and be familiar with the Open Web Application Security Project (OWASP) Application Security Verification Standard (ASVS). Experience with access management is not required but is a plus. The candidate will typically have 5+ years of information security and/or secure application development experience. Previous experience working in the financial services is preferred but not required.
Responsibilities include:
Documenting how control objectives are met
Identifying, explaining, and documenting gaps in control objectives
Raising gaps to the Platform Assessor Lead/Execution Coordination Manager
Compiling the status of all identified gaps at the assessment's conclusion
Remediation tracking/review of identified gaps
Communicating with CSA leaders on progress updates
**Required Skills:**
**** Open Web Application Security Project (OWASP) Application Security Verification Standard (ASVS)**
Significant experience and detailed technical knowledge in at least 3 of the following areas: general information security; security engineering; application architecture; authentication and security protocols; application session management; applied cryptography; common communication protocols; mobile frameworks, single sign-on technologies; exploit automation platforms; RESTful web services
Must be able to critically examine an organization and system through the perspective of a threat actor and articulate risk in clear, precise terms
Knowledge of Structured Query Language
Must be able to both work independently as well as effectively work in teams with individuals with a variety of skills and backgrounds
BS/MS in Computer Science (or relevant work experience in a large scale IT environment)
Knowledge of network and Web related protocols/technologies
Experience as a developer
Knowledge of a Structured Query Language
Enterprise Job Description: Analyzes, improves, implements, and executes security controls proactively to prevent external threat actors from infiltrating company information or systems. Researches more advanced and complex attempts/efforts to compromise security protocols. Maintains or reviews security systems, assesses security policies that control access to systems, and provides regular status updates to the management team. Typically has 5-10 years of relevant experience and will act as an individual contributor.
**Job Band:**
H5
**Shift:**
1st shift (United States of America)
**Hours Per Week:**
40
**Weekly Schedule:**
**Referral Bonus Amount:**
0
**Job Description:**
**Are you passionate about working with the best information security team in the world?** **Bank of America is hiring top talent to join our innovative and forward thinking team.**
**What We Do:**
At Bank of America, we handle the finances of over 67 million client relationships every day, including helping them save, borrow, and invest for today and for their future. We stand by our clients each and every day giving them the power to realize their personal financial goals and help make their financial lives better.
The Global Information Security organization is responsible for protecting bank information systems, confidential and proprietary data, and customer information. The team:
+ Develops the banks Information security strategy and policy
+ Manages the Information security program and identifies and addresses vulnerabilities
+ Develops, deploys and manages a risk-based controls portfolio
+ Manages and operates a global security operations center that monitors, detects and responds to cybersecurity incidents
**What Were Looking For:**
Were looking for the next generation of Cyber security experts those with a passion for growing a long-term career, building relationships and working with a team ofinnovative and forward thinkinginformation security professionals. Our cyber team is meant for those looking to make a real impact and build a career in information security. The role is ideal for those who have a passion to work with industry leaders to protect our brand and the customer/client experience by proactively detecting, disrupting, and mitigating cyber security across the organization.
**What Youll Get:**
From day one, youll receive training including hands-on practice, personalized coaching and dedicated support throughout your on-boarding experience. With demonstrated success, youll have the opportunity to advance into many different roles with Global Information Security with unlimited opportunity to grow throughout your career. You will be supported with dedicated programs, tools, and resources throughout your career journey.
**Well help you:**
Build a successful career at Bank of America through world-class training and on-boarding programs that set you up for success
Grow in your current role through one-on-one coaching from managers who are invested in your success and training programs that help you excel, build new skills or take on additional responsibility
Continuously learn and advance your career goals through intentional career paths to the next best role
Use resources and innovative technologies to optimize the client experience
Expand your business knowledge and network by partnering with experts in Global Information Security, Global Technology and other lines of business
Become an expert in what you do
**What you can look forward to:**
Ongoing professional development to deepen your skills and optimize your expertise as the industry evolves and changes
Resources and dedicated support to help you reach your full potential throughout your career
A benefits program designed to meet the diverse needs of our employees at every stage of their life and help them plan for tomorrow
Progressive workplace practices and initiatives that promote inclusion
**Were a culture that:**
Believes in responsible growth and has a proven dedication to supporting the communities we serve.
Provides continuous training and developmental opportunities to help people achieve their goals, whatever their background or experience.
Believes diversity makes us stronger, so we can reflect, connect to and meet the diverse needs of our clients and customers around the world.
Is committed to advancing our tools, technology, and ways of working. We always put our clients first to meet their evolving needs.
**Role Description:**
The Authentication Risk Assessor performs research, analysis, and testing of authentication applications leveraging industry standard baselines to identify potential vulnerabilities that could be exploited by a threat actor. The assessor clearly documents their findings and sometimes assist the Line of Businesses with questions regarding these findings and associated remediation efforts.
The successful candidate will have a strong application security assessment background and be familiar with the Open Web Application Security Project (OWASP) Application Security Verification Standard (ASVS). Experience with access management is not required but is a plus. The candidate will typically have 5+ years of information security and/or secure application development experience. Previous experience working in the financial services is preferred but not required.
Responsibilities include:
Documenting how control objectives are met
Identifying, explaining, and documenting gaps in control objectives
Raising gaps to the Platform Assessor Lead/Execution Coordination Manager
Compiling the status of all identified gaps at the assessment's conclusion
Remediation tracking/review of identified gaps
Communicating with CSA leaders on progress updates
**Required Skills:**
**** Open Web Application Security Project (OWASP) Application Security Verification Standard (ASVS)**
Significant experience and detailed technical knowledge in at least 3 of the following areas: general information security; security engineering; application architecture; authentication and security protocols; application session management; applied cryptography; common communication protocols; mobile frameworks, single sign-on technologies; exploit automation platforms; RESTful web services
Must be able to critically examine an organization and system through the perspective of a threat actor and articulate risk in clear, precise terms
Knowledge of Structured Query Language
Must be able to both work independently as well as effectively work in teams with individuals with a variety of skills and backgrounds
BS/MS in Computer Science (or relevant work experience in a large scale IT environment)
Knowledge of network and Web related protocols/technologies
Experience as a developer
Knowledge of a Structured Query Language
Enterprise Job Description: Analyzes, improves, implements, and executes security controls proactively to prevent external threat actors from infiltrating company information or systems. Researches more advanced and complex attempts/efforts to compromise security protocols. Maintains or reviews security systems, assesses security policies that control access to systems, and provides regular status updates to the management team. Typically has 5-10 years of relevant experience and will act as an individual contributor.
**Shift:**
1st shift (United States of America)
**Hours Per Week:**
40
Learn more about this role
Full time
JR-22076357
Band: H5
Manages People: No
Travel: No
Manager:
Talent Acquisition Contact:
Stuart Collier
Referral Bonus:
0
Colorado pay and benefits information
**Colorado pay range:**
$86,500 - $135,000
annualized salary, offers to be determined based on experience, education and skill set.
**Discretionary incentive eligible**
This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
**Benefits**
This role is currently benefits eligible . We provide industry-leading benefits, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
Jersey City pay and benefits information
**Jersey City pay range:**
$86,500 - $135,000
annualized salary, offers to be determined based on experience, education and skill set.
**Discretionary incentive eligible**
This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
**Benefits**
This role is currently benefits eligible . We provide industry-leading benefits, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity and affirmative action, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
To view the "EEO is the Law" poster, CLICK HERE (https://www.dol.gov/ofccp/regs/compliance/posters/pdf/eeopost.pdf) .
To view the "EEO is the Law" Supplement, CLICK HERE (https://www.dol.gov/ofccp/regs/compliance/posters/pdf/OFCCP\_EEO\_Supplement\_Final\_JRF\_QA\_508c.pdf) .
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy (Policy) establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
To view Bank of Americas Drug-free workplace and alcohol policy, CLICK HERE .