Compliance and Operational Risk Manager – Application Security and Technology Risk Oversight

Posted 6 Hours Ago
Be an Early Applicant
4 Locations
In-Office
97K-195K Annually
Senior level
Big Data • Fintech • Mobile • Payments • Financial Services • Data Privacy
The Role
Provides independent second-line compliance and operational risk oversight for application security, technology risk, third-party technology risk, and emerging AI-related risks. The role assesses controls, challenges risk acceptance and remediation decisions, monitors regulatory and policy adherence, supports audits and examinations, manages issues, and advises senior technology leaders. It also contributes to governance reporting, operational resilience, cybersecurity oversight, and enterprise risk management across critical applications and technology environments.
Summary Generated by Built In

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Job Description:
This job is responsible for executing second line of defense compliance and operational risk oversight for a Front Line Unit, Control Function, and/or Third Parties. Key responsibilities include ensuring requirements of the Global Compliance Enterprise Policy, the Operational Risk Management Enterprise Policy (collectively “the Policies”), the Compliance and Operational Risk Management Program and Standard Operating Procedures are implemented and identifying, challenging, escalating, and mitigating risks in a timely manner.

This role is responsible for providing  independent second line of defense compliance and operational risk oversight across Front Line Units, Control Functions, and Third Parties. The position ensures adherence to  the Global Compliance and Operational Risk Management framework, delivers effective challenge, and supports the timely identification, assessment, escalation, and mitigation of compliance and operational risks. 

We are seeking an experienced Compliance & Operational Risk Manager to provide independent second line oversight of the Bank's most highest risk technology environments, including Application and Technology Security Assessments, Technology Third Party Risk Management, and emerging technology risks. This role serves as a trusted advisor and effective challenger to senior technology leaders, providing risk oversight, governance, and strategic advisory to support the Bank’s cybersecurity, operational resilience, and regulatory objectives. 
 

Responsibilities:

  • Assesses risks and effectiveness of Front-Line Unit (FLU) processes and controls to ensure compliance with applicable laws, rules, and regulations, while responding to regulatory inquiries, other audits, and examinations
  • Engages in activities to provide independent compliance and operational risk oversight of FLU or Control Function (CF) performance and any related third party/vendor relationships in alignment with the Global Compliance - Enterprise Policy, the Operational Risk Management - Enterprise Policy (collectively the Policies) and the Compliance and Operational Risk Management Program and Standard Operating Procedures
  • Identifies and escalates problems or issues that arise and drives actions to address the root causes that lead to compliance risk issues and/or operational risk losses
  • Monitors inventory of processes, risks, controls, and associated metrics for risk appetite and limits, reporting violations of compliance or regulatory activities
  • Assists in the development of independent risk management reporting for respective area(s) of coverage as input into country/regional governance and management routines
  • Analyzes and interprets applicable laws, rules, and regulations to provide clear and practical advice to stakeholders, and identify and manage risks
  • Reviews and challenges FLU/CF process, risk, Single Process Inventory, and FLU/CF Risk and Control Self-Assessment related to themes or trends, while monitoring the regulatory environment to identify regulatory changes applicable to area(s) of coverage
  • Monitor and assess adherence to Global Technology policies and standards
  • Perform inline review of ITGPST issue management activities, including remediation of regulatory issues
  • Providing independent second line oversight of the Bank's Application and Technology Security Assessment program, including assessment of control effectiveness, risk  identification, issue management, and regulatory compliance. 
  • Assessing technology and cyber risks across critical applications, business processes, and technology environments.
  • Reviewing and challenging risk acceptance decisions, remediation strategies, and control design associated with application security risks.
  • Monitoring emerging technology and AI-related risks, evaluating evolving cyber threats, governance frameworks, and control environments to ensure appropriate risk management practices.
  • Supporting executive reporting, governance routines, and strategic communications for senior leadership audiences.
  • Evaluating adherence to enterprise risk management standards, technology policies, and regulatory expectations.
  • Partnering across technology, cybersecurity, risk, audit, and business teams to strengthen operational resilience and risk management practices.
     

Required Qualifications:

  • 7+ years of experience in operational risk, technology risk, information security, cybersecurity, , compliance, audit, or related risk management disciplines preferably within a large financial institution
  • Demonstrated expertise in cybersecurity, application security, technology governance, third-party technology risk management, or operational resilience.
  • Proven ability to influence and challenge senior leaders and executive stakeholders while maintaining effective partnerships.
  • Experience supporting regulatory examinations, audit engagements, issue remediation programs, and risk governance activities.
  • Proven background in risk-related disciplines; strong experience with the Global Compliance & Operational Risk program from a 1st or 2nd line perspective.
  • Communicates with clarity and impact; comfortable engaging at the executive level and shaping outcomes.
  • Understanding of AI-related risks, governance considerations, cybersecurity implications, and the application of technology-enabled solutions to support risk management activities.
  • Familiarity with GCOR programs, Global Technology policies, and ITGPST processes and risks
  • Skilled in identifying, assessing, and remediating operational risks and issues.
  • Proficient in generating actionable insights through data analysis and reporting tools.
  • Builds trust, challenges constructively, and partners effectively across the enterprise.
  • Proficient in industry security frameworks (e.g., NIST CSF) and applicable Laws, Rules and Regulations. 

Desired Qualifications:

  • Familiarity with Application Technology Security Assessments, vulnerability management, software development lifecycle controls, or application security testing programs.
  • Understanding of emerging technology risks, including AI governance, model risk considerations, and cybersecurity implications of AI-enabled technologies.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, or equivalent risk and technology certifications.
  • Second or third line of defense experience or experience in a business risk and controls role
  • Strong familiarity with the Global Compliance & Operational Risk (GCOR) program and related tools / applications
  • Familiarity with the Issues Management program and tools
  • Demonstrated success leading targeted assessments, audits, or regulatory exam engagements, including authoring responses, report outs and observations
  • Constructively challenges; supports opinion and recommendations with facts and data 
  • Demonstrates productive partnering with various stakeholders across the enterprise at all levels 

Skills:

  • Advisory
  • Monitoring, Surveillance, and Testing
  • Regulatory Compliance
  • Reporting
  • Risk Management
  • Critical Thinking
  • Influence
  • Interpret Relevant Laws, Rules, and Regulations
  • Issue Management
  • Policies, Procedures, and Guidelines Management
  • Business Process Analysis
  • Decision Making
  • Negotiation
  • Process Management
  • Written Communications

Shift:

1st shift (United States of America)

Hours Per Week: 

40

Pay Transparency details

US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540), US - NJ - Pennington - 1600 American Blvd - Hopewell Bldg 6 (NJ2600)

Pay and benefits information

Pay range$97,200.00 - $195,000.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Skills Required

  • 7 or more years of experience in operational risk, technology risk, information security, cybersecurity, compliance, audit, or related risk management disciplines
  • Experience preferably within a large financial institution
  • Expertise in cybersecurity, application security, technology governance, third-party technology risk management, or operational resilience
  • Ability to influence and challenge senior leaders and executive stakeholders while maintaining effective partnerships
  • Experience supporting regulatory examinations, audit engagements, issue remediation programs, and risk governance activities
  • Strong experience with the Global Compliance and Operational Risk program from a first- or second-line perspective
  • Clear and impactful communication skills with comfort engaging at the executive level
  • Understanding of AI-related risks, governance considerations, cybersecurity implications, and technology-enabled risk management solutions
  • Familiarity with GCOR programs, Global Technology policies, and ITGPST processes and risks
  • Ability to identify, assess, and remediate operational risks and issues
  • Proficiency generating actionable insights through data analysis and reporting tools
  • Knowledge of industry security frameworks such as NIST CSF and applicable laws, rules, and regulations
  • Familiarity with Application Technology Security Assessments, vulnerability management, software development lifecycle controls, or application security testing programs
  • Understanding of emerging technology risks, AI governance, model risk considerations, and cybersecurity implications of AI-enabled technologies
  • Professional certification such as CISSP, CISM, CRISC, CISA, or equivalent risk and technology certification
  • Second- or third-line of defense experience or business risk and controls experience
  • Familiarity with the Global Compliance and Operational Risk program and related tools or applications
  • Familiarity with Issues Management programs and tools
  • Experience leading targeted assessments, audits, or regulatory examination engagements, including authoring responses, report-outs, and observations
  • Ability to support opinions and recommendations with facts and data
  • Demonstrated productive partnering with stakeholders across the enterprise at all levels

Bank of America Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Bank of America and has not been reviewed or approved by Bank of America.

  • Healthcare Strength Health coverage is described as comprehensive, with medical, dental, vision, virtual care via Teladoc, wellness programs, and specialized support for cancer and menopause. Wellness credits and an always‑on EAP with in‑person sessions add to the depth of care.
  • Parental & Family Support New parents can access up to 26 weeks of leave, including 16 weeks fully paid for eligible teammates, alongside back‑up child and adult care. Family‑building resources and reimbursements (e.g., fertility, adoption, surrogacy) and a dedicated Life Event Services team extend support across life stages.
  • Equity Value & Accessibility Broad‑based equity through the Sharing Success program, including $1B in stock to nearly all non‑executive employees in January 2026, is intended to foster an ownership mindset. Stock awards (including RSUs) are a recurring component that aligns employees’ interests with shareholders.

Bank of America Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Charlotte, NC
208,000 Employees
Year Founded: 1784

What We Do

We make financial lives better for our clients and our communities through the power of every connection. Our employees are at the heart of this purpose, and are key to driving responsible growth. Every day, across the globe, our employees bring a commitment to our purpose and to driving responsible growth by living our values: deliver together, act responsibly, realize the power of our people and trust the team. A key aspect of driving responsible growth is doing so in a sustainable manner, a critical pillar of which is being a great place to work for our teammates.

Gallery

Gallery

Similar Jobs

Zscaler Logo Zscaler

Director, Threat Research Engagement

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
USA
8697 Employees
200K-285K Annually

Shield AI Logo Shield AI

Mission Assurance Lead (R5896)

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
In-Office
Dallas, TX, USA
112K-168K Annually

ServiceNow Logo ServiceNow

Product Manager

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Addison, TX, USA
29000 Employees

Wise Logo Wise

Technical Account Manager

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
Austin, TX, USA
9000 Employees
180K-230K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account