About Citi:
Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.
As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients’ best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first-class customer experience. We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services.
Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We’ll enable growth and progress together.
The Cyber Risk Analyst is responsible for supporting the identification, assessment, and remediation of cyber risks globally for the organization they support within the Business, Functions, and Technology Information Security Organization (BFT-ISO) in Citi. This position requires experience in cyber risk and the ability to lead initiatives, create executive and action-oriented presentations, and drive stakeholder remediation using a risk-based approach.
Cyber Risk Analysts are responsible for creating awareness and action regarding Citi’s cyber risk appetite and addressing risks across the environment with their stakeholders in the business and technology. Cyber Risk Analysts partner with Citi’s second line of defense, such as risk management organizations, to highlight key risks, drive compliance, and review gaps identified. These individuals also work with internal audit, external auditors, client requests and regulators to evidence cyber security controls in place and support audit request.
Key Responsibilities
Build Relationships
Act as a Trusted Security Advisor to business and technology teams, guiding them on understanding and addressing cyber risk.
Develop relationships with the business, technology, second line, third line, and other CISO teams.
Articulate risk and impact to stakeholders in a clear and succinct manner.
Guide the organization:
Evaluate CISO programs escalations, security incidents, key metrics, and other sources to prepare guidance for stakeholders on risk remediation and reduction prioritization.
Review results of cyber security risk appetite non-compliance, understand the gaps identified, their root causes, impacts and provide guidance to responsible stakeholders, as well as insights on key themes and remediation plans to CISO and related governance organizations.
Partner with BFT-ISO leadership to identify and dimension cyber risk, presenting status and actions.
Partner with BFT-ISO leaders, as well as second line of defense to drive security compliance and awareness.
Identify Cyber Risk and impacts
Build a working knowledge of Citi’s cyber security standards and partner with business/technology teams to help them understand the “so what” and prioritize risk reduction efforts.
Understand the alignment between program-level reporting and cybersecurity risk appetite non-compliance.
Issue Management
Ability to review issues identified and understand the “so what” of how the issue impacts the business.
Articulate how risk scoring is determined and be able to articulate why a risk is high, medium, or low
Determine if compensating/mitigating controls are sufficient to reduce risk score
Determine if severity should be increased when risks are aggregated
Challenge issue owners and the organization on predicted to achieve appropriate risk reduction
Reporting
Present risk-based reporting to senior leaders, stakeholders, including business, technology, second line of defense, and other BFT-ISO teams.
Client / Vendor Support
Partner with Enterprise CISO Programs to ensure third party risks are holistically addressed across the organization in alignment with Citi requirements
Audit / Regulatory Support
Understand regulatory and country-specific requirements for cyber security impacting the business and support audit requests working in partnership with CISO Governance, Controls and Policy.
Qualifications:
6+ years of relevant experience.
Understanding of security frameworks, specifically the Cyber Risk Institute (CRI) Profile.
Proficient in interpreting and applying policies, standards, and procedures.
Extensive knowledge of information security specifically in application SDLC as well as risk assessment methodologies, tools, and industry standards.
Strong leadership, analytical, and problem-solving skills
Excellent communication and interpersonal skills
CRISC, CISA, CISM, CISSP preferred.
At least intermediate-level proficiency in Microsoft Office tool
Excellent skills and experience in Tableau, and Microsoft Excel highly desirable.
Critical Competencies:
Ability to work at both a strategic and tactical level, focusing on the broader picture while driving execution.
Ability to manage multiple initiatives simultaneously, determine prioritization, and work under minimal supervision.
Awareness of latest Information Security risks.
Comfort working in a highly global, diverse, and hybrid (office and virtual) work environment.
Project management skills, ability to organize and prioritize activities, and report on those activities at an executive level.
Strong risk analysis and problem-solving skills.
Knowledge of business, regulatory, and compliance requirements in the financial services industry
Education:
Bachelor’s degree/University degree or equivalent experience
Master’s degree preferred
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
------------------------------------------------------
Job Family Group:
Technology
------------------------------------------------------
Job Family:
Information Security
------------------------------------------------------
Time Type:
Full time
------------------------------------------------------
Primary Location:
Irving Texas United States
------------------------------------------------------
Primary Location Full Time Salary Range:
$125,760.00 - $188,640.00
In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.
------------------------------------------------------
Anticipated Posting Close Date:
Jan 31, 2025
------------------------------------------------------
Citi is an equal opportunity and affirmative action employer.
Qualified applicants will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Citigroup Inc. and its subsidiaries ("Citi”) invite all qualified interested applicants to apply for career opportunities. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.
View the "EEO is the Law" poster. View the EEO is the Law Supplement.
View the EEO Policy Statement.
View the Pay Transparency Posting