Full-Time

Head of Cyber Risk for Functions and Technology

Posted on 5/5/2025

Citigroup

Citigroup

10,001+ employees

Global financial services and banking provider

Compensation Overview

$156.2k - $234.2k/yr

+ Incentive Awards + Retention Awards

Expert

Tampa, FL, USA + 1 more

More locations: Irving, TX, USA

Primary location is Irving, Texas; secondary location is Tampa, Florida.

Category
Cybersecurity
IT & Security
Required Skills
Data Analysis
Requirements
  • Minimum of 10 years of progressive experience in cyber risk management, information security within the financial services industry.
  • Proven experience leading and managing a team of cyber risk professionals.
  • Demonstrated experience in developing and implementing cyber risk strategies and frameworks in a large, global organization.
  • Significant experience interacting with senior management and presenting risk findings.
  • Experience in 1st Line of Defense risk management and interfacing with regulators, auditors, and risk committees.
  • Ability to assess emerging threats, cyber risk trends, and define control strategies.
  • Deep understanding of cyber risk management principles, frameworks (e.g., NIST CSF, ISO 27001, Cyber Risk Institute Profile), and methodologies.
  • Familiarity with regulatory requirements and compliance frameworks relevant to the financial industry (e.g., GDPR, CCPA, GLBA).
  • Strong knowledge of various cyber threats, vulnerabilities, and attack techniques.
  • Experience with risk assessment methodologies (e.g., qualitative and quantitative risk analysis).
  • Excellent data analysis and reporting skills, with the ability to translate technical findings into business-relevant insights.
  • Experience in developing and implementing risk metrics and key risk indicators (KRIs).
  • Understanding of technology infrastructure, cloud computing, and application development.
  • Exceptional communication and presentation skills, with the ability to effectively communicate complex technical information to both technical and non-technical audiences, including senior management.
  • Strong leadership and team management skills, with the ability to motivate, develop, and inspire a team.
  • Excellent interpersonal and relationship-building skills, with the ability to collaborate effectively with diverse stakeholders.
  • Strategic thinking and problem-solving skills, with the ability to anticipate future risks and develop proactive solutions.
  • Strong influencing and negotiation skills, with the ability to drive consensus and achieve desired outcomes.
  • Ability to work independently and manage multiple priorities in a fast-paced environment.
  • Strong analytical and critical thinking skills, with a keen attention to detail.
  • High level of integrity and ethical standards.
Responsibilities
  • Develop and implement a comprehensive cyber risk strategy aligned with the company's overall risk appetite and regulatory requirements for global functions and technology business units.
  • Establish and maintain a robust cyber risk management operations and ensure cyber risk exposures are managed within the defined company risk appetite, proactively identifying and addressing potential breaches.
  • Prepare and present clear, concise, and insightful cyber risk reports to senior management and relevant risk committees, effectively communicating risk exposures and mitigation strategies.
  • Build and maintain strong relationships with senior and mid-level managers across business, technology, and risk functions, acting as a trusted advisor on all cyber risk matters.
  • Represent the First Line of Defense cyber risk perspective in various risk forums and committees, contributing to informed decision-making.
  • Lead, mentor, and develop a team of cyber risk analysts, fostering a high-performance culture focused on collaboration and excellence.
  • Identify emerging thematic cyber risk issues, analyze potential impacts, and develop proactive preventative and detective controls to mitigate these risks.
  • Oversee the design, implementation, and ongoing assessment of cyber risk controls to ensure their effectiveness in reducing risk.
  • Partner with the internal regulatory team to address cyber risk-related inquiries and ensure compliance with relevant regulations.
  • Collaborate effectively with the CISO organization, Technology and Business Risk & Controls, Second Line of Cyber Risk, Internal Audit, and other relevant stakeholders.
Desired Qualifications
  • Master’s degree preferred
  • Relevant professional certifications such as CISSP, CISM, CRISC, or equivalent are highly preferred.

Citigroup provides a wide range of financial products and services to various clients, including consumers, businesses, and governments, across more than 160 countries. Their offerings include consumer banking, credit, corporate and investment banking, securities brokerage, and wealth management. Citigroup's services work by leveraging a global network and advanced technology to facilitate transactions, manage assets, and provide liquidity in the financial system. Unlike many competitors, Citigroup stands out due to its extensive international presence and commitment to sustainability through environmental, social, and governance initiatives. The company's goal is to support global trade and investment while ensuring responsible financial practices.

Company Size

10,001+

Company Stage

IPO

Headquarters

Tel Aviv-Yafo, Israel

Founded

1812

Simplify Jobs

Simplify's Take

What believers are saying

  • Citi's partnership with Mastercard enhances its position in the digital banking sector.
  • 'Green Deposits' align with the growing demand for sustainable banking products.
  • Citi's involvement with Jumia taps into the expanding African e-commerce market.

What critics are saying

  • Increased competition from digital platforms like Versana may challenge Citi's market share.
  • Citi's partnership with Jumia exposes it to risks in the volatile African e-commerce market.
  • Regulatory challenges may arise from Citi's collaboration with Mastercard for Google Pay Plex accounts.

What makes Citigroup unique

  • Citi's global reach spans over 160 countries, offering unmatched international banking services.
  • The company integrates ESG initiatives, appealing to environmentally-conscious investors and customers.
  • Citi's technological infrastructure supports innovative solutions in consumer and corporate banking.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

401(k) Company Match

Wellness Program

Paid Vacation

Paid Sick Leave

Paid Holidays

Company News

Tech.eu
May 7th, 2025
Wagestream secures £300M debt financing to expand its alternative to high-interest loans

Wagestream’s solutions are offered to over three million people through 2,000+ brands, helping employees make better financial wellbeing decisions.

Startups Latam
Apr 30th, 2025
Supra secures strategic investment from Citi

Supra, a Colombian fintech, has secured a second strategic investment from Citi to boost its expansion in Colombia. The company, founded in 2023, focuses on profitability and efficiency rather than large funding rounds. With a 300% growth and a projected $1 billion in transaction volume by 2025, Supra processes payments for over 1,500 businesses. The investment underscores Citi's confidence in Supra's tech infrastructure and potential to transform SME foreign trade in the region.

Finsmes
Apr 28th, 2025
Lightrun Raises $70M in Series B Funding

Lightrun, a NYC-based developer observability company, raised $70M in Series B funding.

FinancialContent
Apr 23rd, 2025
Omnidian Secures $87M for Clean Energy

Omnidian has raised over $87 million in a funding round led by B Capital, with participation from investors like Marunouchi Innovation Partners and Citi Impact Fund. The investment will support Omnidian's growth initiatives, including scaling operations, geographic expansion, and exploring new product lines like EV charging infrastructure. The company aims to enhance clean energy investment security and performance assurance for solar and energy storage systems globally.

Finance Director Europe
Mar 18th, 2025
Nammu21 announces strategic investments from Nasdaq Ventures, State Street, and UBS

With fully automated technology, Nammu21 streamlines loan operations, improves productivity by eliminating the inefficiencies of manual inputs across legacy operating systems

INACTIVE