The Info Sec Prof Senior Analyst is an intermediate level position responsible for leading efforts to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with Citi's data security policy.
Responsibilities:
- Identify potential information security (IS) risks and make recommendations for enhancement
- Collect and analyze security risk evidence and coordinate with internal and external compliance and auditing agencies / officials
- Execute meetings and communicate complex security topics and safe IS practices with all levels of the organization
- Ensure that controls are utilized daily and that non-compliance remediation is addressed
- Provide IS consulting services, including interpreting and/or clarifying information security policy, procedures, standards or concepts
- Assist with defining and implementing IS standards to align procedures and practices in compliance with Citi standards
- Educate and advise on safe information security practices and current, changing, and/or recommended information security requirements
- Validate compliance with IS policies, practices, and procedures, and resolve a variety of IS related issues in coordination with the business
- Assume informal/formal mentorship role within teams and assist with the coaching and training of new team members
- Has the ability to operate with a limited level of direct supervision.
- Can exercise independence of judgement and autonomy.
- Acts as SME to senior stakeholders and /or other team members.
- Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency.
Qualifications:
- 9+ year of total experience out of which 5-8 years of relevant experience
- Applicable Certifications or willingness to earn within 12 months of joining
- Consistently demonstrates clear and concise written and verbal communication
- Proven influencing and relationship management skills
- Proven analytical skills
- Certifications such as CISSP / CCSP / CISM will be an added advantage but not mandatory
Education:
- Bachelor’s degree/University degree or equivalent experience
Essential
- Minimum 4-7 years’ experience in project management and business analysis with experience using a structured methodology
- Experience in developing and presenting metrics and performance for a large program
- Proven ability to work independently and in a multi-tasking environment
Desirable
- Knowledge of data engineering principles and predictive analytics
Essential
- Strong understanding of software development lifecycle.
- Proficient in using Microsoft Office products (Word, Excel, PowerPoint, Project, Visio)
- In-depth knowledge of technology, security, risk, and compliance best practices, preferably in the Identity and Access Management discipline
Desirable
- Experience with CyberArk or other privileged access management solutions
- Prior experience with automation and orchestration projects is a plus.
- Knowledge of authentication and authorization techniques, processes, and protocols.
Competencies (Soft skills )
- Strong communications skills & facilitation experience across all levels of leadership
- Advanced analytical problem-solving skills, including the ability to analyze datasets and present in a format that facilitates senior management decision making
- Experience managing both process improvement and software development projects
- Experience with analyzing and documenting business requirements and interfacing with application developers
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
Key Responsibilities:
Manage projects through their complete lifecycle
Gather and analyze data from multiple sources; develop reports and key risk indicators
Document and maintain program related training and awareness materials and communications
Facilitate discussions, conduct meetings and drive initiatives and issues to conclusion
Consult with stakeholders to gather and document requirements and specifications for solutions and enhancements
Time Type:
Full timeView the " " poster. View the .
View the .
View the