The Information Security Operations (ISO) Sr Manager is a senior management level position responsible for accomplishing results through the management of a team or department in an effort to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with Citi's data security policy.Responsibilities:
- Support the implementation of Information Security (IS) Training Plan, by verifying training participants completed the training and understand IS requirements
- Coordinate with cross-functional Operations and Technology (O&T) counterparts and teams to improve O&T risk oversight
- Attend and participate in internal/external IS forums and risk committees when necessary and provide IS updates to the business
- Ensure stakeholders are held accountable for IS controls, and understand responsibilities in risk mitigation and remediation
- Improve processes, remove IS deficiencies and enhance current tools that reduce an overall risk profile
- Ensure security practices and standards compliance to reduce the likelihood of audit, regulatory and legal liabilities and reduce security risks by enhancing controls and minimizing weaknesses in Citi’s applications portfolio
- Ensure non-compliant items are addressed through coordination with Business Manager and business staff
- Support the Global Information Security (GIS) policies, standards, and initiatives development and implementation
- Provide guidance on IS aspects of projects in support of business initiatives
- Establish communication channels with cross-sector ISOs to efficiently tackle security issues that span multiple businesses
- Manage project deadlines, deliverables, planning, budgeting and policy formulation for the team, including short-term resource planning
- Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency, as well as effectively supervise the activity of others and create accountability with those who fail to maintain these standards.
Qualifications:
- 6-10 years of relevant experience
- Knowledge of Scripting and Programming Languages preferred
- Demonstrated ability to interpret and apply information security policies, standards and procedures
- Consistently demonstrates clear and concise written and verbal communication
- Proven influencing and relationship management skills
- Proven analytical skills
Education:
- Bachelor’s degree/University degree or equivalent experience
- Master’s degree preferred
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
Main requirements
- English Advance Domain, fluently speaking and writing.
- Communication skills to explain security controls required for the solutions in a clear and concise manner to non-technology stakeholders.
- Project coordination, give track end to end to all the approval and presentation process.
- Correct comprehension technical and business requirements of the solutions to be explained in IS Global Committees.
- Proven Experience in Issue & Risk Management.
- On time results focused
- Information Security or Cybersecurity certifications preferred.
Deep Knowledge andproven experiencein:
- Cloud Security
- Network Security
- Software Development
- Security Operations
- Identity and Access Management
- Command sequence Language (code writing in Python and Powershell)
- Operation Systems (Windows, Linux, Mac, IOS, Android, etc.)
- Risk identification
- Issue and Risk Management
- Security Assessments
- Cybersecurity industry policies
Skills
- Collaboration
- Mentoring and Training
- Excellent written and verbal communication
- Project management
- High Integrity
- High pressure resistance
- Problem solving
Ability to:
- Design organization security architecture
- Identify potential vulnerabilities and risks
- Define security policies
- Select appropriate security technologies
- Assess security risks and determine how to minimize them.
- Supervise the correct implementation of cybersecurity solutions.
- Train employees on security best practices and how to identify potential threats.
Information Security
Time Type:
Full timeView the " " poster. View the .
View the .
View the