Jobs · Finance · Texas

Cyber Risk Senior Officer - Senior Vice President

Citi · Irving, TX · 1 wk ago
HybridFinance$156k–$234k/yrFull-time

Citi’s Technology and Cyber Compliance and Operational Risk Office (TCCORO) serves as the firm’s reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report, and manage operational and compliance risks while promoting actions to address root causes that may lead to unintended operational losses or regulatory breaches. TCCORO provides specialist subject matter experts to challenge Enterprise, Infrastructure, Operations, and Technology entities across the firm. We act as the technology and cyber conscience of the bank, ensuring internal controls mitigate technology and cyber risks in alignment with our risk appetite under the Operational Risk Management (ORM) and Independent Compliance Risk Management (ICRM) frameworks.

About the role

The Cyber Risk Sr Officer – SVP role is part of the Cyber Risk & Compliance function within TCCORO, responsible for overseeing, challenging, and advising the first line of defense in managing cyber risk. This position leverages cyber subject matter expertise, business experience, data analysis, current events, and industry trends to inform risk prioritization and second-line challenge activities. The role collaborates with ORM, Compliance partners, and other stakeholders to provide expertise aligned with operational and compliance risk management frameworks.

Responsibilities

  • Manages internal projects on threat issues supporting various participants and stakeholders, measuring the effectiveness and comprehensiveness of Citi’s first-line defenses.
  • Establishes and oversees compliance and cyber policies, procedures, technology, tools, and governance processes to provide credible challenge for minimizing cyber risk losses.
  • Independently assesses cyber risks and drives actions to address root causes that persistently lead to operational risk losses by challenging historical and proposed practices.
  • Leads independent assurance activities, including substantive and controls testing, to assess areas of concern.
  • Monitors, evaluates, and challenges Key Risks and associated Key Risk Indicators, including discussions with owners on breaches and corrective actions.
  • Identifies potential risks associated with program/project delivery at a technical and detailed level.
  • Leads second-line cyber assessments, including risk, control, and maturity assessments.
  • Assesses cyber risks tied to new initiatives and programs proposed for implementation.
  • Challenges the design, adequacy, and strength of the control environment related to technology and cyber, recommending actions to align with cyber risk appetite.
  • Executes ad-hoc activities for TCCORO, such as researching and producing materials for presentations, coordinating audit/examination deliverables, and maintaining data for executive reporting.
  • Assesses risk in business decisions, demonstrating knowledge of Citi’s reputation and safeguarding assets by adhering to laws, rules, regulations, and ethical standards.

Requirements

  • 10+ years of relevant experience.
  • Practical experience working in, assessing, or challenging security architecture, infrastructure security, network security, cloud security, cyber resilience, or data protection.
  • Deep knowledge of products within the coverage area, including technical understanding of current and emerging trends and their business impacts.
  • Experience in cyber risk assessments, metrics, enterprise technology services, risks, and controls within globally complex, dispersed, and diverse organizations.
  • In-depth knowledge of cyber risks and controls across information system domains, including data protection, identity and access management, vulnerability management, network security, endpoint security, logging and monitoring, incident management, cyber resilience, and third-party management. Preferred expertise in security architecture, cloud security, and emerging technologies (e.g., Artificial Intelligence, Digital Assets).
  • Subject matter expertise in industry-standard risk management frameworks (e.g., ISO27001, COBIT, TOGAF, CRI) and cyber risk mitigation strategies.
  • Outstanding communication and influencing skills across all organizational levels and with external partners/vendors.
  • Exceptional relationship management skills, including conflict resolution while maintaining relationships.
  • Ability to communicate complex topics to broad audiences.
  • Strong analytical skills, including filtering, prioritizing, and validating complex material from multiple sources.

Qualifications

  • Bachelor’s degree required; Master’s degree preferred.
  • Relevant certifications (e.g., CISM, CRISC, CISSP, CISA, PMP) are a plus.

Pay

Full-time salary range: $156,160.00 - $234,240.00. In addition to salary, eligible employees may receive discretionary and formulaic incentive and retention awards.

Benefits

  • Medical, dental, and vision coverage.
  • 401(k) retirement plan.
  • Life, accident, and disability insurance.
  • Wellness programs.
  • Paid time off, including vacation, sick leave, and holidays.

Schedule

Full time.

Primary location: Irving, Texas, United States.

Similar jobs