Overview of Chief Information Security Office (CISO):
The Chief Information Security Office (CISO) is home to deeply talented colleagues that work to ensure the safety of Citi's clients', our revenue, our employees and our proprietary data. We manage information security as one end-to end program – one with a clear mandate and accountability. Our mission is a program that is fully anchored to modern control and architectural frameworks, is fully aligned with the enterprise architecture of the firm and is deeply integrated into the sectors and functions.
Overview of the Role:
This role will report to the Cybersecurity Continuity of Business (CoB), Third Party Management Governance (TPMG), and Records Management Manager, and will be responsible for supporting CISO’s compliance with the Digital Operational Resilience Act (DORA) and regulatory requirements related to Recovery and Resolution Planning. As such, this role will lead interactions with Citi’s DORA team and with CISO stakeholders for Register of Information maintenance. This role will also provide risk management support and governance of several programs, including Model Risk, End User Computing (EUC), and Export Licensing. Additionally, the scope of this role includes responsibilities for senior management reporting to ensure visibility of CISO’s compliance and potential risks for programs supported by the Cybersecurity CoB, TPMG, and Records Management team.
What you will do:
- Responsible for managing and supporting multiple risk and control programs for the organization including defining the strategy, approach, processes, quality, tools and reporting that provide global risk management consistency and excellence.
- Leads interactions with Citi’s DORA team and CISO stakeholders for maintenance of CISO’s inventory in the Register of Information (ROI).
- Partner with TPMG team to ensure the master inventory of CISO suppliers and supporting details in scope for DORA is comprehensive.
- Create and maintain the master inventory of CISO-owned applications in scope for DORA.
- Support execution of CISO’s Resolution Planning deliverables, interacting with key stakeholders to ensure inputs are provided on a timely basis and submitted to Enterprise Resilience Recovery and Resolution Planning.
- Execute coordination of ongoing Model Risk Management (MRM) objectives and activities within CISO. This includes leading the coordination of semi-annual MRM Attestations, ensuring completion of consent order deliverables, working with SME’s and product development teams to monitor and identify new and enhancements to existing products for MRM applicability prior to production implementation.
- Oversee EUC Governance for CISO, aiding the Accountable Business Owner (ABO) in reviewing EUC registrations and risk assessments, managing High Risk retirements, and CISO EUC Champions ensuring the overall program compliance by providing Senior CISO Leadership with oversight into the inventory and compliance metrics.
- Act as the Export License Coordinator (ELC) for CISO by providing oversight and monitoring of the Business performing export activities ensuring compliance with export, import, and reexport regulations. Monitor software planned development, deployment, enhancements, and changes via controls placed in the Businesses SDLC process which will timely identify when export reviews are necessary based upon various triggers.
- Provide senior management with appropriate visibility into CISO’s Export Licensing, EUC, Model Risk, and Resolution and Recovery Planning programs.
Your profile:
- 6 -8 years direct, relevant experience in any of the following: Risk and Controls, Governance, Compliance, Audit or Regulatory functions
- Information security/cyber/technology, project management and governance experience with the proven ability to communicate program requirements to help ensure compliance with policies.
- Experienced at interacting, influencing, and collaborating across all levels and functional areas of the organization.
- Superior organizational skills, with proven ability to successfully manage multiple, concurrent priorities in a pressured environment.
- Demonstrated relationship management skills with ability to deepen relationships and build partnerships with key stakeholders.
- Demonstrated ability to influence a group of diverse stakeholders and drive accountability and ownership with key business partners and process owners.
- Detail oriented, with proven ability to question and identify opportunities within existing processes and business practices by leveraging previous experiences and knowledge.
- Excellent written and oral communication skills, with demonstrated experience/skill in communicating with various levels of business leadership.
- Strong analytical, evaluative, and problem-solving abilities.
- Demonstrated track record of being proactive and taking initiative on projects.
- Familiarity with risk and management reporting concepts, as well as metrics and reporting.
- Bachelor’s / Master’s degree or equivalent experience in technology, business, or related discipline
- High level of proficiency in English
What we can offer you:
By joining Citi Hungary, you will not only be part of a business casual workplace with a hybrid working model (up to 2 days working at home per week), but also receive a competitive compensation package and enjoy a whole host of additional benefits that support you (and your family) to be well, live well and save well:
- Cafeteria Program
- Home Office Allowance (for colleagues working in hybrid work models)
- Paid Parental Leave Program (maternity and paternity leave)
- Private Medical Care Program and onsite medical rooms at our offices
- Pension Plan Contribution to voluntary pension fund
- Group Life Insurance
- Employee Assistance Program
- Access to a wide variety of learning and development programs, online course libraries and upskilling platforms, such as Udemy and Degreed
- Flexible work arrangements to support you in managing work - life balance
- Career progression opportunities across geographies and business lines
- Socially active employee communities with diverse networking opportunities
Alongside these benefits Citi is committed to ensuring our workplace is where everyone feels comfortable coming to work as their whole self every day. We want the best talent around the world to be energized to join us, motivated to stay, and empowered to thrive.
Sounds like Citi has everything you need?
Then apply to discover the true extent of your capabilities.
------------------------------------------------------
Job Family Group:
Risk Management
------------------------------------------------------
Job Family:
Business Risk & Control
------------------------------------------------------
Time Type:
Full time
------------------------------------------------------
Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.
If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.
View Citi’s EEO Policy Statement and the Know Your Rights poster.