Skip to main content

Controls Mapping Governance Lead - Global Information Security

Controls Mapping Governance Lead - Global Information Security

Addison, Texas;Washington, District of Columbia; Chicago, Illinois; Denver, Colorado

**To proceed with your application, you must be at least 18 years of age.**

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Addison/Controls-Mappin...\_26031194)

**Bank of America employees are required to meet all** **posting eligibility requirements** **prior to applying for any new position.**

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Addison/Controls-Mappin...\_26031194)

Refer a friend

**To proceed with your application, you must be at least 18 years of age.**

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Addison/Controls-Mappin...\_26031194)

**Bank of America employees are required to meet all** **posting eligibility requirements** **prior to applying for any new position.**

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Addison/Controls-Mappin...\_26031194)

**Job Description:**

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.

We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.

Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

The Controls Mapping Governance team is seeking an **information security professional** with experience in cybersecurity, technology infrastructure, audit, or regulatory or policy requirements.

This role supports the enterprise policy governance lifecycle by interpreting information security requirements, identifying the processes and controls that may address those requirements, and determining whether the proposed coverage is sufficiently supported.

The successful candidate will evaluate requirements at the individual must-statement level, develop preliminary coverage recommendations, engage process and control owners, and assess supporting evidence. The candidate must be comfortable discussing technical concepts with subject matter experts and determining whether a documented process or control logically addresses the requirement’s intent, scope, and expected outcome.

Responsibilities

• Interpret laws, rules, regulations, policies, and standards; break complex requirements into individual must statements; and define the required outcome, scope, accountable parties, and expected evidence.

• Identify and assess candidate processes, controls; develop preliminary coverage recommendations; and determine whether coverage is direct, supporting, partial, or insufficient.

• Review technical processes and challenge owner responses to determine whether the documented activity, scope, ownership, dependencies, limitations, and evidence support the proposed mapping.

• Document clear, defensible mapping decisions and determine whether proposed coverage should be accepted, clarified, treated as partial or a gap, or escalated through established governance channels.

• Use data and approved tools to support requirement interpretation, coverage identification, response review, reporting, and process improvement, while independently validating all outputs and maintaining decision accountability.

Required Qualifications

• 3+ years of experience in **information security,** cybersecurity risk, technology risk, controls governance, policy governance, compliance, audit, or a related field within a regulated environment.

• Working knowledge of cybersecurity concepts, technology infrastructure, and security domains such as identity and access management, network security, cloud security, application security, data protection, vulnerability management, monitoring, incident response, or configuration management.

• Ability to understand how security processes and controls operate across systems, applications, infrastructure, data, users, and technologies, without needing to be an engineer or subject matter expert in every domain.

• Experience reviewing technical procedures, process flows, control descriptions, system documentation, and evidence artifacts to identify incomplete responses, unsupported conclusions, exclusions, failure conditions, or gaps in coverage.

• Strong analytical and communication skills, including the ability to question technical subject matter experts constructively, distinguish direct coverage from general alignment, and document clear, defensible mapping decisions for technical and senior audiences.

• Ability to evaluate and independently validate data against authoritative requirements, approved inventories, owner responses, and supporting evidence rather than relying solely on owner conclusions.

Desired Qualifications

• Knowledge of cybersecurity frameworks and standards, such as NIST, ISO/IEC 27001, COBIT, CIS Controls, or comparable frameworks.

• Experience mapping requirements to processes, controls, control objectives, assessments, or other governance mechanisms.

• Familiarity with governance, risk, and compliance platforms, and SharePoint workflows.

• Experience working with technology teams, policy or standard owners, control owners, risk partners, auditors, compliance functions, or regulators.

• Relevant cybersecurity, risk, audit, cloud, or controls certification.

Required Skills

1. Customer and Client Focus

2. Interpret Relevant Laws

3. Rules

4. and Regulations

5. Policies

6. Procedures

7. and Guidelines

8. Problem Solving

9. Quality Assurance

10. Business Acumen

**Shift:**

1st shift (United States of America)

**Hours Per Week:**

40

Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.

View your "Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088\_EEOC\_KnowYourRights6.12.pdf) " poster.

View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notic...) .

Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy (“Policy”) establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.

Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank’s required accommodation request process before your first day of work.

This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.

Investment products offered through MLPF&S and insurance and annuity products offered through MLLA:

**Are Not FDIC Insured** **Are Not Bank Guaranteed** **May Lose Value**

**Are Not Deposits** **Are Not Insured by Any Federal Government Agency** **Are not a condition to Any Banking Service or Activity**

Merrill Lynch, Pierce, Fenner & Smith Incorporated (also referred to as “MLPF&S” or “Merrill”) makes available certain investment products sponsored, managed, distributed or provided by companies that are affiliates of Bank of America Corporation (“BofA Corp.”). MLPF&S is a registered broker-dealer, registered investment adviser, **Member SIPC** and a wholly owned subsidiary of BofA Corp. Insurance and annuity products are offered through Merrill Lynch Life Agency Inc., a licensed insurance agency and wholly owned subsidiary of Bank of America Corporation.

Trust, fiduciary and investment management services are provided by Bank of America, N.A., Member FDIC and wholly owned subsidiary of Bank of America Corporation (“BofA Corp.”).

Bank of America Private Bank is a division of Bank of America, N.A.

Banking products are provided by Bank of America, N.A. and affiliated banks, Members FDIC and wholly owned subsidiaries of Bank of America Corporation.

© 2026 Bank of America Corporation. All rights reserved.

Controls Mapping Governance Lead - Global Information Security

Full time
Addison, TX

Published on 08/25/2026

Share this job now