Global Head of Cyber Risk and Compliance
CitiAbout the role
The Technology & Cyber Compliance and Operational Risk Office (TCCORO) at Citi is the firms reliable second set of eyes overseeing Technology and Cyber risk. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report and manage operational risks while promoting the implementation of actions to address root causes which may lead to unintended operational losses. TCCORO provides the specialist subject matter experts to challenge Enterprise, Infrastructure, Operations and Technology entities across the firm. We are the technology and cyber conscious of the bank. In line with the ORM and ICRM frameworks, we aim to ensure that the internal controls that are designed to mitigate technology and cyber risks are managed, mitigated and aligned with our risk appetite.
Responsibilities
Reporting into the Global Head of TCCORO, the Head of Cyber Risk will have oversight responsibility for the Chief Information Security Office and evaluation of cyber risk holistically across the firm. The following highlight the coverage area responsibilities for this Managing Director position:
- Oversight and challenge of the cybersecurity incident response programs.
- Oversight of the security operations center (SOC) and cybersecurity fusion center (CSFC).
- Oversight of cybersecurity penetration testing and red-team operations.
- Oversight of the Chief Information Security Office (CISO), including the review of the effectiveness of the controls, standards and programs across the enterprise.
- Implementation of guidance for overseeing Emerging Technology and Operational Risks, in compliance with OCC Heightened Standards.
- Able to present and lead discussions with key Regulators, internal and external auditors, as well the Board of Directors and the Risk and Audit sub-committees.
- Governance and Oversight of security risks impacting the business and technology
- Support in the development of Cyber Policy and Standards
- Oversight of Key Operational Risks and related indicators and thresholds
- Challenge of Cyber Risk Self Assessments
- Challenge of Business and Technology Scenario Analysis
- Issue management, oversight and escalation
- Advise on best practices leveraging expertise and industry insights
Qualifications:
Knowledge /Experience
The Head of Cyber Risk will be an acknowledged thought leader in technology and security risk management with over 20 years of hands-on technical experience in complex IT management, Information Security, and Emerging Technologies with globally complex, dispersed and diverse organizations. The ideal Managing Director will have in-depth, detailed knowledge of good infrastructure, cloud, and emerging Technology Management inclusive of Artificial Intelligence, Operations and Information Security practices in the financial industry. This individual should have the following experience and skills:
- 20+ years' experience in technology risk and/or cyber risk management in the banking/financial services industry, or related field, with at least 5+ years in 2nd or 3rd line senior leadership positions.
- Subject matter expert in technology risk and/or cyber risk management principles and practices across various information system architecture and engineering domains.
- Proven experience in managing complex risk portfolios and developing strategic risk management frameworks for large organizations.
- Robust understanding of operational risk management frameworks, industry standards, regulatory requirements, and risk mitigation practices.
- Experience managing and overseeing large remediation and transformation programs to achieve intended results.
- Extensive experience in effective written and verbal communication with executive audiences including Boards.
- Experienced risk challenger who balances risks vs. rewards aligned with corporate risk culture.
- Understanding of Citi products and services and downstream impacts of technology risk and/or cyber risk strategy.
- Professional certifications in either technology risk and/or cyber risk preferred, including: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), ERM, CET, ISO27001, COBIT, TOGAF, or CRI
The ideal candidate will have in-depth, working knowledge of banking technologies, fraud, cybercrime detection and countermeasures, encryption, data retention, as well as information security support for segregation of duties, application development, network and systems operation, testing and vendor management. Prior experience in previous roles should include companies with global technology infrastructure in global financial ser
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s