Align Information Security Assessments Program with business needs and goals and Information Security (IS) program requirements
Establish and implement Information Security Assessments strategic plans, and oversee all Information Security Assessments Program prioritization, design and communications with leadership and key stakeholders
Oversee security practices and standards compliance, and address non-compliance in teams, applications, documents, and processes
Define the IS service engagement model and transform the IS team, by promoting partnerships with clients
Coordinate with cross-sector leaders to solve security issues, and educate leaders and staff on IS value through cost-benefit analysis
Determine Information Security Officer (ISO) training needs and requirements and resolve identified training gaps
Monitor Corrective Action Plans and remediation efforts, and conduct periodic quality assurance reviews to identify areas of improvement
Manage the budget, resource planning, and delivery of end results through executing the functional strategy
Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency, as well as effectively supervise the activity of others and create accountability with those who fail to maintain these standards.
Qualifications:
15+ years of experience in Cyber Security, 5+ Years in Cyber Security Management role, with Program Management experience
Demonstrated ability to collaborate with a variety of analytical groups and service delivery organizations
Experience leading Information Security Assessments Programs or Cyber Risk Management
Advanced analytical and problem-solving skills
Consistently demonstrates clear and concise written and verbal communication
Proficient in interpreting and applying policies, standards and procedures
Demonstrated ability to remain unbiased in a diverse working environment
Education:
Bachelor’s degree/University degree or equivalent experience
Master’s degree preferred
CISSP, CISA, CCSP or other relevant Cyber Security Certifications