This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Senior Information Security Officer is an intermediate level position within Citi’s CISO (Chief Information Security Office) organization. This role is responsible for driving efforts to prevent, monitor and respond to Information Security breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security directives and control programs in alignment with Citi’s Information & Cybersecurity policy.
Job Responsibility:
Act as a Trusted Security Advisor to business and technology teams, guiding them on IS/Cyber risks
Drive compliance with applicable Information & Cybersecurity laws, rules and regulations
Work with business & technology management to drive the information security program and govern risk management activities including CSRA (Cybersecurity Risk Appetite) reporting
Work with the internal Applications Development function to facilitate improvements in both architectural and application security posture
Provide strategic risk guidance for business and technology projects, including the evaluation and recommendation of security controls and corrective actions to mitigate/remediate risks
Manage security incidents and events to protect corporate IT assets
Facilitate compliance with all Information Security policies, standards and regulations/directives as mandated by Global CISO Organization and regulators
Perform Information Security Assessments across applications/business processes
Communicate and interact periodically with employees, business and technology management to update on IS related programs, risks & controls, policies/standards
Requirements:
10+ years of proven experience as Information & Cybersecurity Officer or Cybersecurity risk manager/Architect/Auditor/Consultant
Banking/Financial Services/Markets experience is an advantage
Strong understanding of Information security domains with hands-on experience of performing application security risk assessments covering controls such as Authentication techniques, Authorization frameworks, Privileged Access Management, API Security, Cloud/SaaS Security, Cryptography, Sensitive Data protection, Audit Logging & Monitoring
Sound knowledge of Application Vulnerability Assessments, Source code, component & container vulnerability management related controls
Deep understanding of application security controls ranging from Secure SDLC principles, Secure Coding Practices, OWASP Top 10 vulnerabilities & countermeasures and DevSecOps fundamentals
Understanding of policy compliance and how it relates to risk
Extensive knowledge of information security risk assessment frameworks/industry standards/threat modelling methodologies, such as STRIDE, OWASP, NIST SPs, CVSS etc
Demonstrated ability to take proactive ownership and follow up on issues
Demonstrated ability to work in a team and to work well under pressure
Advanced analytical and problem-solving skills
Consistently demonstrates clear and concise written and verbal communication
Proficient in interpreting and applying policies, standards and procedures
Demonstrated ability to remain unbiased in a diverse working environment
Ability to manage multiple tasks, changing priorities and meet tight deadlines
Self-starter with ability to take the initiative and master new tasks quickly
Methodical with attention to detail
Proven influencing and relationship management skills
Nice to have:
Additional IS/Cybersecurity certifications (CISA, CISSP, CISM, SANS GIAC, CEH etc.)
Welcome to CrawlJobs.com – Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.
We use cookies to enhance your experience, analyze traffic, and serve personalized content. By clicking “Accept”, you agree to the use of cookies.