> Markdown version of [/jobs/ext/2257177-controls-mapping-governance-lead-global-information-security](https://www.wearedevelopers.com/jobs/ext/2257177-controls-mapping-governance-lead-global-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Controls Mapping Governance Lead - Global Information Security - **Company:** Bank of America - **Location:** Addison, IL, United States - **Experience:** Expert - **Salary:** $78,200.0 - $136,300.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cloud Computing Security, Configuration Management, Control Objectives for Information and Related Technology (COBIT), Software Documentation, Cyber Security, Identity and Access Management, Information Security Management, Network Security, Microsoft SharePoint, Software Vulnerability Management, Software Security, CIS Benchmarks - **Published:** August 26, 2026 - **Apply:** https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Addison/Controls-Mapping-Governance-Lead---Global-Information-Security_26031194 ## About the Role * 3+ years of experience in information security, cybersecurity risk, technology risk, controls governance, policy governance, compliance, audit, or a related field within a regulated environment. * Working knowledge of cybersecurity concepts, technology infrastructure, and security domains such as identity and access management, network security, cloud security, application security, data protection, vulnerability management, monitoring, incident response, or configuration management. * Ability to understand how security processes and controls operate across systems, applications, infrastructure, data, users, and technologies, without needing to be an engineer or subject matter expert in every domain. * Experience reviewing technical procedures, process flows, control descriptions, system documentation, and evidence artifacts to identify incomplete responses, unsupported conclusions, exclusions, failure conditions, or gaps in coverage. * Strong analytical and communication skills, including the ability to question technical subject matter experts constructively, distinguish direct coverage from general alignment, and document clear, defensible mapping decisions for technical and senior audiences. * Ability to evaluate and independently validate data against authoritative requirements, approved inventories, owner responses, and supporting evidence rather than relying solely on owner conclusions. Desired Qualifications * Knowledge of cybersecurity frameworks and standards, such as NIST, ISO/IEC 27001, COBIT, CIS Controls, or comparable frameworks. * Experience mapping requirements to processes, controls, control objectives, assessments, or other governance mechanisms. * Familiarity with governance, risk, and compliance platforms, and SharePoint workflows. * Experience working with technology teams, policy or standard owners, control owners, risk partners, auditors, compliance functions, or regulators. * Relevant cybersecurity, risk, audit, cloud, or controls certification. ## Description This role supports the enterprise policy governance lifecycle by interpreting information security requirements, identifying the processes and controls that may address those requirements, and determining whether the proposed coverage is sufficiently supported. The successful candidate will evaluate requirements at the individual must-statement level, develop preliminary coverage recommendations, engage process and control owners, and assess supporting evidence. The candidate must be comfortable discussing technical concepts with subject matter experts and determining whether a documented process or control logically addresses the requirement's intent, scope, and expected outcome. Responsibilities * Interpret laws, rules, regulations, policies, and standards; break complex requirements into individual must statements; and define the required outcome, scope, accountable parties, and expected evidence. * Identify and assess candidate processes, controls; develop preliminary coverage recommendations; and determine whether coverage is direct, supporting, partial, or insufficient. * Review technical processes and challenge owner responses to determine whether the documented activity, scope, ownership, dependencies, limitations, and evidence support the proposed mapping. * Document clear, defensible mapping decisions and determine whether proposed coverage should be accepted, clarified, treated as partial or a gap, or escalated through established governance channels. * Use data and approved tools to support requirement interpretation, coverage identification, response review, reporting, and process improvement, while independently validating all outputs and maintaining decision accountability. ## Related Videos - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)