The information security operations (iso) sr.
analyst is an intermediate level position responsible for leading efforts to prevent, monitor and respond to information/data breaches and cyber-attacks.
the overall objective of this role is to ensure the execution of information security directives and activities in alignment with citi's data security policy.
responsibilities
address security issues identified in the various information security programs
review and address issues identified within various information security (is) programs and ensure all is issues related to internal audit, and external auditors are closed by their original target date
improve the efficacy of governance processes by identifying risks, monitoring controls, and remediating issues
establish cross-sector working relationships and complete weekly awareness discussions with local team to efficiently tackle security issues
ensure risk exceptions are raised, registered and closed on a timely basis and communicate updates and changes to the global standards
complete risk assessment process, including completing accurate inventory reporting, data classification, threat analysis, and action plans
test and validate that the business complies with applicable is requirements; develop and implement is policies and procedures
determine and validate appropriate level of controls are being implemented to safeguard sensitive data
develop corrective action plans for all information security-related gaps and approve all closures through reviewing evidence to ensure each closure meets citi requirements
assume informal/formal mentorship role within teams and assist with the coaching and training of new team members
has the ability to operate with a limited level of direct supervision.
can exercise independence of judgement and autonomy.
acts as sme to senior stakeholders and/or other team members.
appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency.
qualifications
5-8 years of relevant experience
proficient in interpreting and applying policies, standards and procedures
consistently demonstrates clear and concise written and verbal communication
proven influencing and relationship management skills
proven analytical skills
education
bachelor's degree/university degree or equivalent experience
this job description provides a high-level review of the types of work performed.
other job-related duties may be assigned as required.
additional qualifications (mexico)
amplio conocimiento y cumplimiento de regulaciones mexicanas (en materia de si) (cnbv y banxico)
conocimientos técnicos relacionados con seguridad de la información y ciberseguridad
deseables certificaciones crisc, cisa, cism, cissp, iso*:*, iso*:*
experiencia en la elaboración de reportes y métricas ejecutivas dirigidas a la alta dirección
habilidades de comunicación y negociación
habilidades para identificar y resolver problemas
licenciatura en informática, ingienería en computación, sistemas computacionales (terminada/titulado)
indispensable idioma inglés al 80%
indispensable conocimientos avanzados en paquetería office (excel, power point, word)
citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.
if you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review accessibility at citi.
view citi's eeo policy statement and the know your rights poster.
#j-*-ljbffr