Info Security Exposure Management Specialist I B
Bank of America- Posted 2 hours ago
- Be among the first 10 applicants
Job Description
Job Description:
About Us
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Global Business Services
Global Business Services delivers Technology and Operations capabilities to Lines of Business and Staff Support Functions of Bank of America through a centrally managed, globally integrated delivery model and globally resilient operations. Global Business Services is recognized for flawless execution, sound risk management, operational resiliency, operational excellence and innovation. In India, we are present in five locations and operate as BA Continuum India Private Limited (BACI), a non-banking subsidiary of Bank of America Corporation and the operating company for India operations of Global Business Services.
Process Overview
The Global Information Security (GIS) is responsible for protecting Bank information systems, confidential and proprietary data, and customer information. The team develops the Bank's Information Security strategy and policy, manages the Information Security program and identifies and addresses vulnerabilities, Develops, deploys and manages a risk-based controls portfolio, Manages and operates a global security operations center that monitors, detects and responds to cybersecurity incidents.
Job Description
This position will be a member of the GIS Vulnerability Identification team. The Vulnerability scanning deployment & engineering specialist will be primarily responsible for end-to-end technology enablement in support of the global Vulnerability Identification program. To continuously improve vulnerability detection capabilities, the role's remit will span across the Americas, EMEA and the Asia Pacific regions and will focus on the planning, design, testing, deployment of tactical and strategic solutions. This role requires partnership with solutions vendors and technology infrastructure partners to optimally tailor future solutions to vulnerability identification strategic objectives. The role will require cross-organization collaboration to solve key issues impactful to the enterprise.
Responsibilities
- Responsible for vulnerability scanning platforms, optimization and resiliency
- Responsible for the mapping of vulnerability identification gaps with remedial technology solutions
- Maintain relationships with Vulnerability Management Solutions Providers and Technology implementation partners
- Responsible for Technology-based thematic issue tracking, resolution, and reporting
- Key participants to Vulnerability Identification Incident Management & Response.
- Provide technical guidance and mentorship to team members
- Responsible for the development and execution of the vulnerability identification technology strategy
- Deliver proof-of-concept testing and validation of emerging vulnerability identification technologies to support strategic security initiatives.
- Deliver periodic project updates to Senior Leadership
Requirements
Education : Bachelor's and/or master's degree in computer science, Information Technology or related field
Certifications If Any : Qualys VMDR, CASM/EASM preferred, Relevant certifications such as CISSP, CISM, ISO 27001, NIST is a plus
Experience Range : 4-7 Years
Foundational skills
- Comfortable working in a fast-paced environment
- Minimum 4 years of experience in information Security
- Strong Proficiency in Vulnerability Management and Exposure Management programs (Qualys, Tanium).
- Strong proficiency in Qualys Query Language (QQL) & Qualys Agent Deployment (QAD).
- Hands-on experience with Tanium & prioritizing vulnerabilities based on business risk, exploitability, and threat intelligence.
- Proven experience performing root cause analysis on vulnerability findings, scan coverage gaps, agent deployment issues, false positives/negatives, and remediation failures.
- Superior sense of urgency and ability to accurately prioritize deliverables
- Excellent communication and presentation skills, capable of translating technical security findings into clear business risk and executive-level insights.
- Excellent team player with critical thinking skills
Desired skills
- BS or MS in Information technology/security or related areas of study
- Experience with establishing and maintaining integration between Vulnerability identification tools and Vulnerability Management Workflows (e.g. ServiceNow)
- Familiarity with mainstream attacker techniques, tactics, and procedures (i.e. MITRE ATT&CK Framework)
- Experience with deploying and managing Cloud-based Vulnerability scanning solutions
- Familiarity with compliance regulations, frameworks, and certifications (e.g., NIST, FFIEC.)
- Working knowledge of Network architecture and Engineering concepts
- Experience with Vulnerability ratings methodologies
- Background in Windows & UNIX platform Administration
- Experience with a scripting language(s)or Power BI
Work Timings : 12:30 pm to 9:30 pm
Job Location : Hyderabad, Chennai
More Info
Key Skills
Tanium
MITRE ATT&CK Framework
Qualys Query Language (QQL)
Cloud-based Vulnerability scanning solutions
Exposure Management
Qualys VMDR
Root Cause Analysis on vulnerability findings
Qualys Agent Deployment (QAD)
Network architecture and Engineering concepts
Vulnerability scanning platforms optimization
Vulnerability ratings methodologies
