Info Security Consultant II A
Bank of America · Mumbai Metropolitan Region
- Experience8–10 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted24 Sept 2026
About Bank of America
Bank of America is hiring in Mumbai Metropolitan Region in financial services. This role looks for around 8+ years of experience.
Skills
- Information Security Management
- Governance, Risk & Compliance
- Internal Auditing
- ISO 27001
- PCI DSS
- Sarbanes-Oxley Act
- Risk Assessment
- Remediation
- Process Improvement
- Stakeholder Management
The role
An information security consultant at a financial services company oversees third-party risk remediation, evaluates Governance, Risk & Compliance and ISO 27001 controls, and drives security findings to closure. The role also applies risk assessment and remediation and cloud security to validate controls, coordinate stakeholders, and report security outcomes.
Full job description
Job Description:
About Us
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Global Business Services
Global Business Services delivers Technology and Operations capabilities to Lines of Business and Staff Support Functions of Bank of America through a centrally managed, globally integrated delivery model and globally resilient operations.
Global Business Services is recognized for flawless execution, sound risk management, operational resiliency, operational excellence and innovation.
In India, we are present in five locations and operate as BA Continuum India Private Limited (BACI), a non-banking subsidiary of Bank of America Corporation and the operating company for India operations of Global Business Services.
Process Overview
The Global Information Security (GIS) is responsible for protecting Bank information systems, confidential and proprietary data, and customer information. The team develops the Bank’s Information Security strategy and policy, manages the Information Security program, identifies, and addresses vulnerabilities, Develops, deploys and manages a risk-based controls, portfolio, Manages and operates global security operations center that monitor, detect and respond to cybersecurity incidents.
Job Description
This role is responsible for overseeing the remediation of information security findings identified during third party assessments. The individual leads and provides guidance to the remediation assessors, ensuring consistent execution and timely resolution of identified risks throughout the remediation lifecycle.
Key responsibilities include supporting the remediation activities through reviewing evidence, validating the effectiveness of security controls, determining whether identified risks have been appropriately addressed, and driving findings to closure. The role also serves as a central point of coordination among third parties, business stakeholders, and internal partners, providing transparent reporting on remediation progress, managing escalations, and ensuring leadership is informed of significant risks, issues, and remediation outcomes.
Responsibilities
Manage relationships with third parties, vendor managers, and internal stakeholdersPlan, execute, and document remediation activities in accordance with established processes and proceduresPartner with third parties to address questions and support successful remediation of information security findingsEvaluate third-party information security risk through remediation reviews and activitiesIdentify and communicate gaps in third-party information security programsEscalate remediation risks, issues, and security concerns to leadershipSupport resource workload and planning to ensure effective execution of remediation activitiesWork independently with minimal oversight and a strong willingness to learnDemonstrate strong analytical, problem-solving, and critical-thinking skillsCollaborate effectively with global and virtual teamsLead teams toward defined objectives and hold resources accountable for results
Requirements
Education: B.E. / B Tech / M.E. / M Tech / MCA / M.Sc.,
Certifications If Any: ISO 27001 LA, CISA, CISM, CISSP
Experience Range: 8 to 10 years
Foundational Skills
Experience in Information Security ManagementExperience in Governance, Risk & ComplianceExperience in internal or external auditsExperience in implementing or reviewing ISO 27001, PCI, SOX, etc., controlsStrong analytical and problem-solving skillsExcellent written/verbal communication skillsRisk Assessment & RemediationProcess Improvement & ExecutionGlobal CollaborationIndependent LeadershipLeadership & Stakeholder Management
Desired Skills
Knowledge in Vulnerability Assessments and Application ArchitectureCloud SecurityKnowledge of business continuityExperience supporting regulatory & complianceUnderstanding of Networking, Systems Admin, Cryptography, Access ManagementFamiliarity with threat-informed security assessments
Work Timings: 13:30 – 22:30 Hours
Job Location: Chennai, Mumbai