Cloud Security Vulnerability Management Program Specialist Job at Bank of America Corporation, Denver, CO

K1NQSlZJMXBicysrOFI0OVZsU2FFQXlkVEE9PQ==
  • Bank of America Corporation
  • Denver, CO

Job Description

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.

Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

The Role:

We are seeking a skilled and motivated Cloud Security Vulnerability Management Program Specialist to support the Cloud Security Assurance (CSA) organization by ensuring enterprise cloud workloads are securely configured, continuously monitored, and protected throughout their runtime lifecycle. This role is focused on identifying workload-level vulnerabilities, insecure configurations, and runtime behaviors that could expose systems to compromise, service disruption, or unauthorized access across hybrid and multi-cloud environments.

The Cloud Security Vulnerability Management Program Specialist is responsible for maintaining visibility into workload security posture across virtual machines, containers, and supporting compute services. This includes vulnerability assessment, configuration validation, and runtime monitoring to detect drift from defined security baselines and identify suspicious or policy-violating activity. The role requires strong understanding of cloud workload architectures, operating system security fundamentals, and shared responsibility models to accurately assess risk and prioritize remediation.

This role partners closely with infrastructure, platform, engineering, and operations teams to ensure vulnerability findings are actionable, risk-assessed, and remediated appropriately. The Cloud Security Vulnerability Management Program Specialist plays a critical role in strengthening workload security maturity by operationalizing Cloud Security tooling, supporting audit and regulatory requirements, and providing leadership with transparent, risk-based reporting on workload security posture.

The Cloud Security Vulnerability Management Program Specialist operates in fast-paced, enterprise-scale environments and contributes to the development and maintenance of workload security standards, baselines, and documentation that support consistent governance and assurance across all in-scope compute platforms.

Job Responsibilities:

  • Ensure cloud workloads are protected and monitored in alignment with CSA security standards and defined baselines.

  • Maintain continuous visibility into workload security posture across virtual machines, containers, and compute platforms.

  • Identify workload vulnerabilities, misconfigurations, and insecure operating system or platform settings.

  • Monitor runtime activity to detect suspicious behavior, privilege escalation, policy violations, and drift from security baselines.

  • Build, maintain, and tune vulnerability detections aligned to vulnerability management and runtime protection requirements.

  • Support onboarding and operationalization of cloud security tooling across environments and workload types.

  • Partner with infrastructure, DevOps, and platform teams to drive remediation of workload security risks.

  • Triage vulnerability findings, assess risk and impact, and support prioritization of remediation efforts.

  • Provide workload security posture reporting, metrics, and risk transparency to CSA leadership.

  • Contribute to workload security standards, baseline documentation, and audit readiness activities.

Required Qualifications:

  • Understanding of Cloud Native security concepts and runtime security principles.

  • Experience identifying and managing workload vulnerabilities and insecure configurations.

  • Knowledge of cloud compute services, operating systems, and containerized workloads.

  • Familiarity with vulnerability management and runtime detection techniques.

  • Strong analytical, documentation, and collaboration skills.

Desired Qualifications

  • Experience supporting cloud or workload security assurance programs.

  • Hands-on experience with Cloud Security Vulnerability Management tools (e.g., Aqua, Prisma Cloud, Wiz, Defender).

  • Familiarity with Linux security fundamentals.

  • Experience supporting audit or compliance-driven security reviews.

  • Bachelor’s degree in a technical or security-related field.

  • Relevant cloud or security certifications preferred.

This job will be open and accepting applications for a minimum of seven days from the date it was posted

Shift:

1st shift (United States of America)

Hours Per Week: 

40

Job Tags

Work at office, Shift work, Day shift

Similar Jobs

Lane Enterprises Inc

Laborer Job at Lane Enterprises Inc

 ...removing snow. May be trained to act as forklift operator when normal operator is out....  ...Physical Requirements: Prolonged periods standing and walking. Must be able to lift up...  ...to climb, bend, squat, kneel, crawl, and reach above shoulder level. Ability to withstand... 

Southeast Technical College

Collision Technology Instructor Job at Southeast Technical College

 ...resolve conflicts, hold yourself and other accountable, and work under pressure. CERTIFICATIONS AND LICENSES: Current ASE and I-CAR certifications preferred or ability to attain certifications required. Work is performed primarily in a classroom, a lab, and an... 

Bluedrop LLC

Journeyman Plumber Job at Bluedrop LLC

Description: Bluedrop solves water quality issues for Residential and Commercial clients with the design and installation of water purification equipment. We are seeking a Journeyman Plumber to join our growing installation team! Our ideal candidate is personable... 

RoadSafe Traffic Systems

Traffic Control Supervisor II Job at RoadSafe Traffic Systems

 ...designing, setting up, and maintaining temporary traffic control in work zones. Their duties include using traffic control devices to...  ...with occasional overnight stays, and ability to work nights and weekends as required by projects. ~ Must be available for a rotating on... 

NavitasPartners

Help Desk Analyst (Tier 1) 26-04632 Job at NavitasPartners

 ...Job Title: Help Desk Analyst (Tier 1) Location: Harrisburg PA (Onsite) Job Type: Contract Schedule: Monday Friday (Onsite) Telework on Fridays Interview Process: In-person interview (approx. 1 hour) Position Overview Navitas Partners LLC is seeking...