Job Highlights
Title: Senior Analyst (Cyber Risk)
Type: Full Time
Experience: 5-8 Years
Function: Risk Management
Location: Tampa, FL, United States
Company: Citi
Company Profile
Citi is a global bank that provides financial services including safeguarding assets, lending money, making payments, and accessing the capital markets.
Job Profile
The bank is searching for a Cyber Risk Senior Analyst who will be responsible for the oversight of the Finance and Data Technology organization portfolio of projects, applications, systems, and processes.
Leverage technology or cyber subject matter expertise, business experience, data analysis techniques, current events, and industry trends and best practices to inform the prioritization of risks and the second-line’s approach for associated challenge and influence activities.
Works with our ORM, Compliance partners, and other stakeholders to provide support to our oversight and challenge activities with the components of our operational and compliance risk management frameworks.
Education Level
- Bachelor’s/University Degree or equivalent experience
Work Experience
Duties/Responsibilities
- Assesses technology or cyber risks and evaluates actions to address the root causes that persistently lead to operational risk losses by challenging both historical and proposed practices.
- Assesses technology or cyber risks associated with new initiatives and programs being proposed for implementation.
- Helps to appropriately assess risk when business decisions are made, demonstrating knowledge for the firm’s reputation and safeguarding Citigroup, its clients, and assets, by driving compliance with applicable laws, rules, and regulations, adhering to Policy, and applying sound ethical judgment.
- Participates in various second line of defense technology or cyber assessments including risk assessments, control assessments, maturity assessments, etc.
- Review potential risks associated with program/project delivery on a technical level.
- Supports ad-hoc activities for the TCCORO organization, including but not limited to researching and drafting materials for presentations of deep dives into selected topics, coordinating deliverables related to audits and examinations, and maintaining associated data for executive reporting.
- Supports independent assurance activities to assess areas of concern including substantive and controls testing.
- Supports the challenge of the design, adequacy, and strength of the control environment associated with technology and cyber and recommends actions to ensure the operational risk profile is in line with the technology or cyber risk appetite.
- Supports the monitoring, evaluation, and challenge of Key Risks and associated Key Risk Indicators triggers, and thresholds.
- Supports the review of compliance and technology or cyber policies and procedures, technology and tools, and governance processes to provide credible challenges for minimizing losses from technology or cyber risks.
Skills/Knowledge/Abilities
- Ability to work collaboratively with regional and global partners in other functional units; and to navigate a complex organization.
- Excellent project management and organizational skills and capability to handle multiple projects at one time.
- Excellent written and verbal communication skills.
- Experience in technology or cyber risk assessments, metrics, enterprise technology services, risks, and controls within globally complex, dispersed, and diverse organizations.
- Knowledge and understanding of industry-standard risk management frameworks (including ISO27001, COBIT, TOGAF, and CRI for example), and an in-depth understanding of technology or cyber risk mitigation strategies.
- Must be a self-starter, flexible, innovative, and adaptive.
- Preferred expertise in data architecture/management, application development, and finance and accounting functions.
- Proficient in MS Office applications (Excel, Word, PowerPoint).
- Strong interpersonal skills with the ability to work collaboratively and with people at all levels of the organization.
- Understanding of technology or cyber risks and controls across various information system architecture and engineering domains including data protection, identity and access management, vulnerability management, network security, endpoint security, logging and monitoring, incident management, and third-party management.
Required Certificate
- Relevant certifications (in CISM, CRISC, CISSP, CISA, or PMP) a plus.
Benefits/Perks
- The bank offers competitive employee benefits, including medical, dental, and vision coverage; 401(k); life, accident, and disability insurance; and wellness programs.
- Offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays.
Employer’s Statement
Citi is an Equal Opportunity Employer. All qualified applicants will be considered regardless of their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
#J-18808-Ljbffr