Compliance and Operational Risk Manager – Application Security and Technology Risk Oversight
Bank of America
- Location
- Charlotte
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 278 approvals (FY2023)
- Posted
- Sep 17, 2026
Skills
About this role
Job Description
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve. Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description
This job is responsible for executing second line of defense compliance and operational risk oversight for a Front Line Unit, Control Function, and/or Third Parties. Key responsibilities include ensuring requirements of the Global Compliance Enterprise Policy, the Operational Risk Management Enterprise Policy (collectively “the Policies”), the Compliance and Operational Risk Management Program and Standard Operating Procedures are implemented and identifying, challenging, escalating, and mitigating risks in a timely manner. This role is responsible for providing independent second line of defense compliance and operational risk oversight across Front Line Units, Control Functions, and Third Parties. The position ensures adherence to the Global Compliance and Operational Risk Management framework, delivers effective challenge, and supports the timely identification, assessment, escalation, and mitigation of compliance and operational risks. We are seeking an experienced Compliance & Operational Risk Manager to provide independent second line oversight of the Bank's most highest risk technology environments, including Application and Technology Security Assessments, Technology Third Party Risk Management, and emerging technology risks. This role serves as a trusted advisor and effective challenger to senior technology leaders, providing risk oversight, governance, and strategic advisory to support the Bank’s cybersecurity, operational resilience, and regulatory objectives.
Responsibilities
Assesses risks and effectiveness of Front-Line Unit (FLU) processes and controls to ensure compliance with applicable laws, rules, and regulations, while responding to regulatory inquiries, other audits, and examinations Engages in activities to provide independent compliance and operational risk oversight of FLU or Control Function (CF) performance and any related third party/vendor relationships in alignment with the Global Compliance - Enterprise Policy, the Operational Risk Management - Enterprise Policy (collectively the Policies) and the Compliance and Operational Risk Management Program and Standard Operating Procedures Identifies and escalates problems or issues that arise and drives actions to address the root causes that lead to compliance risk issues and/or operational risk losses Monitors inventory of processes, risks, controls, and associated metrics for risk appetite and limits, reporting violations of compliance