Exposure Analysis Operations & Exposure Analysis and Identification Strategy Manager

Posted 10 Days Ago
Be an Early Applicant
3 Locations
In-Office
155K-220K Annually
Expert/Leader
Big Data • Fintech • Mobile • Payments • Financial Services • Data Privacy
The Role
Leads cybersecurity exposure analysis operations and strategic initiatives to improve vulnerability identification, prioritization, exploitability assessment, and risk-based remediation. Manages security professionals, defines tooling and data-platform requirements, evaluates emerging security capabilities, and partners with threat intelligence, application, cloud, endpoint, infrastructure, and technology teams. Advises senior leaders on cybersecurity risks and investments while aligning exposure management with broader cyber defense programs.
Summary Generated by Built In

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

The Exposure Analysis Operations & Exposure Analysis and Identification Strategy Manager will be part of the Global Information Security (GIS) Cyber Security Assurance (CSA) Exposure Analysis and Identification Leadership team. In this role, you will lead exposure analysis operations, and the planning and execution of strategic initiatives to enhance exposure analysis and identification capabilities. You will collaborate closely with cross functional teams and stakeholders across GIS and the broader Global Technology organization. 

Responsibilities
•    Lead a team of information security professionals that perform operational exposure analysis, and define and execute analysis and identification strategy, including process and technology advancements.
•    Continually enhance prioritization methodologies, incorporating exploitability, asset criticality, internet exposure, threat intelligence and business context.
•    Partner with threat intelligence, red team, application security, cloud security, endpoint security, infrastructure, and technology owners to improve the accuracy, relevance, and actionability of vulnerabilities.
•    Define requirements for exposure analysis tooling and data platforms.
•    Provide strategic guidance on the use of exposure analysis capabilities such as exploit prediction, reachability analysis, runtime context, attack path modeling, SBOM analysis, and exploitability. 
•    Evaluate emerging security products and capabilities that enhance exposure identification, exploitability validation, software component visibility, attack surface discovery, and risk-based prioritization.
•    Serve as a subject matter expert, advising senior leaders on process and technology risks and strategic investment priorities.
•    Drive alignment between exposure analysis and identification strategy and broader cyber defense programs.

Required Qualifications
•    CISSP or comparable certification.
•    10+ years of progressive experience in cybersecurity, vulnerability management, incident response, threat intelligence, application security, or related security disciplines. 
•    2+ years of leadership experience managing security programs, teams, or enterprise-scale exposure management functions. 
•    Deep knowledge of exposure management methodologies, lifecycles, and industry frameworks including NIST, CIS, MITRE ATT&CK, CVSS, CWE, and CISA Known Exploited Vulnerabilities (KEV). 
•    Experience working with enterprise platforms such as Tanium, Qualys, Tenable, Rapid7, CrowdStrike Exposure Management, Microsoft Defender, or similar technologies. 
•    Strong understanding of operating systems, networking, databases, cloud technologies, web applications, APIs, containers, and enterprise infrastructure architectures. 
•    Proven ability to communicate complex technical risks to executive leadership, technology stakeholders, and business partners. 
•    Strong analytical, problem-solving, and decision-making skills with the ability to influence outcomes across large organizations

Desired Qualifications
•    Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related discipline.

Required Skills
1. Critical Thinking
2. Customer and Client Focus
3. Information Systems Management
4. Problem Solving
5. Threat Analysis
6. Cyber Security
7. Policies
8. Procedures
9. and Guidelines Management
10. Quality Assurance
 

Shift:

1st shift (United States of America)

Hours Per Week: 

40

Pay Transparency details

US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)

Pay and benefits information

Pay range$155,000.00 - $220,000.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Skills Required

  • CISSP or comparable certification
  • 10+ years of progressive experience in cybersecurity, vulnerability management, incident response, threat intelligence, application security, or related security disciplines
  • 2+ years of leadership experience managing security programs, teams, or enterprise-scale exposure management functions
  • Deep knowledge of exposure management methodologies, lifecycles, and frameworks including NIST, CIS, MITRE ATT&CK, CVSS, CWE, and CISA Known Exploited Vulnerabilities
  • Experience with enterprise platforms such as Tanium, Qualys, Tenable, Rapid7, CrowdStrike Exposure Management, Microsoft Defender, or similar technologies
  • Strong understanding of operating systems, networking, databases, cloud technologies, web applications, APIs, containers, and enterprise infrastructure architectures
  • Ability to communicate complex technical risks to executive leadership, technology stakeholders, and business partners
  • Strong analytical, problem-solving, and decision-making skills with the ability to influence outcomes across large organizations
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related discipline

Bank of America Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Bank of America and has not been reviewed or approved by Bank of America.

  • Healthcare Strength Health coverage is described as comprehensive, with medical, dental, vision, virtual care via Teladoc, wellness programs, and specialized support for cancer and menopause. Wellness credits and an always‑on EAP with in‑person sessions add to the depth of care.
  • Parental & Family Support New parents can access up to 26 weeks of leave, including 16 weeks fully paid for eligible teammates, alongside back‑up child and adult care. Family‑building resources and reimbursements (e.g., fertility, adoption, surrogacy) and a dedicated Life Event Services team extend support across life stages.
  • Equity Value & Accessibility Broad‑based equity through the Sharing Success program, including $1B in stock to nearly all non‑executive employees in January 2026, is intended to foster an ownership mindset. Stock awards (including RSUs) are a recurring component that aligns employees’ interests with shareholders.

Bank of America Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Charlotte, NC
208,000 Employees
Year Founded: 1784

What We Do

We make financial lives better for our clients and our communities through the power of every connection. Our employees are at the heart of this purpose, and are key to driving responsible growth. Every day, across the globe, our employees bring a commitment to our purpose and to driving responsible growth by living our values: deliver together, act responsibly, realize the power of our people and trust the team. A key aspect of driving responsible growth is doing so in a sustainable manner, a critical pillar of which is being a great place to work for our teammates.

Gallery

Gallery

Similar Jobs

Comcast Logo Comcast

Critical Facilities Engineer

Digital Media • Information Technology • News + Entertainment
Hybrid
Centennial, CO, USA
115000 Employees
78K-117K Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Castle Rock, CO, USA
16000 Employees
15-24 Hourly

Cox Enterprises Logo Cox Enterprises

Sales Strategy & Enablement Director

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
United States
30000 Employees
135K-225K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Engineer Senior Principal - EO Payload Performance Analyst

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Broomfield, CO, USA
40000 Employees
133K-226K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account