Cyber Risk Director

2 tygodni temu


Warszawa, Mazovia, Polska Citigroup Inc. Pełny etat

Are you looking for a career move that will put you at the heart of a global financial institution?

By Joining Citi, you will become part of a global organisation whose mission is to serve as a trusted partner to our clients by responsibly providing financial services that enable growth and economic progress.

Team/Role Overview

The Technology and Cyber Compliance and Operational Risk Office (TCCORO) at Citi is the firm's reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report and manage operational and compliance risks while promoting the implementation of actions to address root causes which may lead to unintended operational losses or regulatory breaches. TCCORO provides the specialist subject matter experts to challenge Enterprise, Infrastructure, Operations and Technology entities across the firm. We are the technology and cyber conscience of the bank. In line with the Operational Risk Management (ORM) and Independent Compliance Risk Management (ICRM) frameworks, we aim to ensure that the internal controls that are designed to mitigate technology and cyber risks are managed, mitigated, and aligned with our risk appetite.

The Head of Cyber Risk and Compliance – Security Operations reports to The Head of Cyber Risk and Compliance within TCCORO and will provide leadership for Cyber Risk and Compliance – Security Operations team. This role is accountable for management of complex, critical professional disciplinary areas and will manage multiple teams through other managers. The role is responsible for establishing and executing the functional strategy within their organisation. They will leverage cyber subject matter expertise (particularly security operational processes), business experience, data analysis techniques, current events, and industry trends and best practices to inform the prioritisation of risks and the second-line's approach for associated challenge and influence activities. This position actively works with our ORM and Compliance partners and other stakeholders to provide subject matter expertise in line with our operational and compliance risk management frameworks.

What you'll do

A successful candidate will be a subject matter expert in cyber risk in global financial services, be able to demonstrate a comprehensive understanding of the subject matter and advise stakeholders on the application to related risks. They should have a strong track record in cyber risk management and/or a strong technical background with excellent analytical skills. The ideal candidate will be a strategic, proven leader, strong technically and with security operational experience. They will provide thought leadership, having strong industry engagement, and will be a strong relationship builder that can influence and challenge effectively. The successful candidate will have experience with building and maintaining global teams, providing guidance and mentorship.

  • Manages a staff of risk officers at various levels, with direct accountability for hiring and organisational structure. Has direct oversight for compensation, performance appraisals, staff development, training, etc. Provides input on performance and compensation recommendations for risk officers and utilities that provide risk related services on a matrix basis.
  • Accountable for internal projects on threat issues that support a variety of participants and stakeholders measuring the effectiveness and comprehensiveness of Citi's first line defences.
  • Evaluates the design of controls and communicate the impact of control weaknesses to first line teams and control implementers.
  • Oversight of the establishment and implementation of compliance and cyber policies and procedures, technology and tools, and governance processes for the coverage domains.
  • Governance and oversight of cyber risk while supporting the development of policy and standards; oversight of Key Operational Risks; challenge risk self-assessments and scenario analysis; issue management oversight and escalations.
  • Provides leadership to the Second Line influence, advisory and challenge of operational security capability domains including security incident management, fusion centre and cyber threat intelligence.
  • Represents TCCORO in various steering committees, working groups and councils relevant to the functional area.
  • Actively engaged in the industry on the latest in cyber risk, and emerging operational risks.
  • Oversight of planning, and implementation of cyber programs including their governance, identification of risks and controls.
  • Implementation of guidance for overseeing cyber operational risks, aligned with The Office of the Comptroller of the Currency (OCC) Heightened Standards and other global regulations.
  • Able to present and lead discussions with key regulators, and internal and external auditors.
  • Advises on best practices leveraging expertise and industry insights.
  • Reviews and challenges coverage area appropriately consider significant operational risk in their Management Control Assessments (MCAs).
  • Evaluates the extent to which first line of defence is aligned with internal and external control standards, as well as regulatory and audit requirements.
  • Appropriately assesses risk when business decisions are made, demonstrating knowledge for the firm's reputation and safeguarding Citigroup, its clients, and assets, by driving compliance with applicable laws, rules, and regulations, adhering to Policy, and applying sound ethical judgment.

What we'll need from you

  • Relevant technical experience and experience managing a team of professionals.
  • Practical experience managing, assessing or auditing security operations processes and technologies including Security Operations Centre, Security Information and Event Management, Fusion Centre, Incident Response, etc.
  • In-depth knowledge of products within the coverage area, including a technical understanding of current and emerging trends as well as the ability to apply in-depth understanding of the business impacts of technical contributions.
  • Experience in cyber risk assessments, metrics, enterprise technology services, risks, and controls within globally complex, dispersed, and diverse organisations.
  • In-depth knowledge of cyber risks and controls across various information system architecture and engineering domains including: data protection, identity and access management, vulnerability management, network security, endpoint security, logging and monitoring, incident management, and third-party management; preferred expertise in security operations.
  • Subject matter expert in one or more industry standard risk management frameworks (including ISO27001, COBIT, TOGAF and CRI for example), and an in-depth understanding of cyber risk mitigation strategies.
  • Self-motivated and goal-oriented with the ability to seize the initiative, garner consensus and develop and implement an effective strategy. Demonstrates a high level of analytical rigor in formulating strategies, goals and measuring results.
  • Sense of urgency in implementing programs and evaluating priorities; decisive, action-oriented and practical.
  • Willingness to challenge and question the status quo, making recommendations for options and best solutions.
  • Demonstrated strategic thinking skills. Organisationally astute, with influencing, collaboration and communication skills. Personal presence, intellect, energy and drive to succeed in a high-performance environment.
  • Able to analyse and think through highly complex issues, but then appropriately execute and implement against a well thought through framework in a seamless manner. A global citizen who is comfortable in all geographies, regions and cultures.
  • Strong leadership, communication, and presentation skills including the ability to adapt his/her style to suit the different needs of any audience.
  • Bachelor's/University degree, Master's degree preferred
  • Relevant certifications (in CISM, CRISC, CISSP, etc.) a plus

What we can offer you

By joining Citi Solutions Centre Poland, you will not only be part of a business casual workplace with a hybrid working model (up to 2 days working at home per week), but also receive a competitive base salary (which is annually reviewed) and enjoy a whole host of additional benefits such as:

  • Private Medical Care Programme
  • Life InsuranceProgramme
  • Pension Plan contribution (PPE Programme)
  • Employee Assistance Programme
  • Paid Parental Leave Programme (maternity and paternity leave)
  • Sport Card
  • Holidays Allowance
  • Sport and team recreation activities
  • Special offers and discounts for employees
  • Access to an array of learning and development resources
  • A discretional annual performance related bonus
  • A chance to make a difference with various affinity networks and charity initiatives

Alongside these benefits Citi is committed to ensuring our workplace is where everyone feels comfortable coming to work as their whole self every day. We want the best talent around the world to be energised to join us, motivated to stay, and empowered to thrive.

Sounds like Citi has everything you need? Then apply to discover the true extent of your capabilities.

#LI-JD2

Job Family Group:

Risk Management

Job Family:

Operational Risk

Time Type:

Full time

Citi is an equal opportunity and affirmative action employer.

Qualified applicants will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Citigroup Inc. and its subsidiaries ("Citi") invite all qualified interested applicants to apply for career opportunities. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.

View the "EEO is the Law" poster. View the EEO is the Law Supplement.

View the EEO Policy Statement.

View the Pay Transparency Posting


#J-18808-Ljbffr

  • Warszawa, Mazovia, Polska 11101 Citibank Europe plc Poland Pełny etat

    Come and join our newly established Cyber Risk Team in WarsawThe Technology and Cyber Compliance and Operational Risk Office (TCCORO) at Citi is the firm's reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report, and manage operational and compliance risks while promoting the...


  • Warszawa, Mazovia, Polska Citi Pełny etat

    Come and be part of our newly established Cyber Risk Team in Warsaw!The Technology and Cyber Compliance and Operational Risk Office (TCCORO) at Citi is like having a trustworthy second set of eyes. Our goal is to drive comprehensive practices to identify, measure, monitor, report, and manage operational and compliance risks while promoting actions to address...


  • Warszawa, Mazovia, Polska 11101 Citibank Europe plc Poland Pełny etat

    Come be a part of our newly established team focusing on Cyber Risk in WarsawThe Technology and Cyber Compliance and Operational Risk Office (TCCORO) at Citi acts as a crucial second pair of eyes for the firm. We are dedicated to implementing consistent practices to detect, measure, monitor, and manage operational and compliance risks while also addressing...


  • Warszawa, Mazovia, Polska 11101 Citibank Europe plc Poland Pełny etat

    Come and be part of our newly established Cyber Risk Team in Warsaw The Tech and Cyber Compliance and Operational Risk Office (TCCORO) at Citi is the firm's reliable second set of eyes. Our goal is to drive comprehensive and consistent practices to identify, measure, monitor, report, and manage operational and compliance risks while encouraging the...


  • Warszawa, Mazovia, Polska Citigroup Inc. Pełny etat

    Come and join our newly established Cyber Risk Team in WarsawThe Technology and Cyber Compliance and Operational Risk Office (TCCORO) at Citi is the firm's reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report and manage operational and compliance risks while promoting the...

  • Tech Risk

    2 tygodni temu


    Warszawa, Mazovia, Polska Goldman Sachs Pełny etat

    WHO WE ARE Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our efforts,...

  • Senior Compliance Risk

    2 tygodni temu


    Warszawa, Mazovia, Polska 11101 Citibank Europe plc Poland Pełny etat

    Come and join our newly established Cyber Risk Team in Warsaw The Technology and Cyber Compliance and Operational Risk Office (TCCORO) at Citi is the firm's reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report and manage operational and compliance risks while promoting...


  • Warszawa, Mazovia, Polska Cyber Crime Pełny etat

    Security Engineer for Cloud-Native Security Enhancements SimCorp We provide integrated, best-in-class, multi-asset investment management solutions to the world's leading asset managers. View company page For over 50 years, we have worked closely with investment and asset managers to become the world's leading provider of integrated investment management...

  • Risk Assessor Lead

    2 tygodni temu


    Warszawa, Mazovia, Polska Goldman Sachs Pełny etat

    WHO WE ARE Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our efforts,...


  • Warszawa, Mazovia, Polska Bayer Pełny etat

    Job Opening: IT Security Risk Consultant Key Tasks & Responsibilities: Collaborate with CSRM stakeholders, IT, and business to design security and Risk Assessment strategies for Bayer globally. Assist in creating security policies, standards, and guidance. Stay updated on emerging security technologies and solutions, participate in educational...

  • Operational Risk Officer

    2 tygodni temu


    Warszawa, Mazovia, Polska 11101 Citibank Europe plc Poland Pełny etat

    Operational Risk Management (ORM) within Citi focuses on meeting its Transformation mandate under the regulatory Consent Order. As a part of the ORM Transformation and Controls Team, the Operational Risk Officer-Transformation and Controls role entails managing and overseeing ORM's Risk & Control Self Assessments, particularly in Control Design, Monitoring,...


  • Warszawa, Mazovia, Polska JTI Pełny etat

    We are JTI, Japan Tobacco International, and we are present in 130 countries. We have spent years innovating, creating new and better products for the consumers to choose from . This is our business. But not only. Our business is our people. Their talent. Their potential. We believe that when they are free to be themselves , and they are given the...

  • Finance Director

    2 tygodni temu


    Warszawa, Mazovia, Polska Jones Lang LaSalle Incorporated Pełny etat

    Job TITLE: Foreign, Commonwealth & Development Office for Europe - Finance DirectorBusiness Unit: Workplace Management EMEAWork location: PolandType: PermanentRole summaryThe FCDO European Finance Director is a senior leadership role, managing for the Client Property Operating expenses (POE) (Rent, rates, utilities etc) and non-POE costs otherwise known as...

  • Project Director

    2 tygodni temu


    Warszawa, Mazovia, Polska Innovaderm Research Pełny etat

    The Project Director is responsible for oversight of the conduct of a program or portfolio of clinical studies or large global multicentered trials with large study budgets. The portfolio may comprise studies for specific customers, and/or a group of studies within the same therapeutic area or indication for more than one customer. The Project Director...


  • Warszawa, Mazovia, Polska BAE Systems Pełny etat

    The Jacksonville Ship Repair (JSR) Contracts Director reports to the Senior Director of Contracts for the BAE Systems Ship Repair business area and is responsible for oversight of the JSR Contracts team. The JSR Contracts Director is a key part of the JSR business management team and directly supports the JSR Vice President/General Manager. This role also...

  • Finance Director

    2 tygodni temu


    Warszawa, Mazovia, Polska JLL Pełny etat

    JLL WPM CLIENT FINANCE JOB DESCRIPTION Job TITLE : Foreign, Commonwealth & Development Office for Europe - Finance Director Business Unit : Workplace Management EMEA Work location : Poland Type : Permanent Role summary The FCDO European Finance Director is a senior leadership role, managing for the Client Property Operating expenses (POE)...

  • Senior Analyst

    2 tygodni temu


    Warszawa, Mazovia, Polska Fortrea Pełny etat

    Responsibilities : As a Senior Analyst, Cybersecurity Risk Management you will help build, maintain, and manage Fortrea's cyber risk management program.You will play a pivotal role in enhancing the cyber risk management framework and mitigation of cyber risks across the organization.You will also get involved in third-party vendor risk assessments,...

  • Transportation Director

    2 tygodni temu


    Warszawa, Mazovia, Polska CDM Smith Pełny etat

    CDM Smith Transportation Director Jacksonville , Florida Apply Now CDM Smith has an exciting opportunity for our National Transportation Director. This position will be responsible for:Leading our National Transportation Group's sales team to achieve profitable growth inline with our short and long term growth strategies and market opportunities.Leading our...


  • Warszawa, Mazovia, Polska BAXTER Pełny etat

    Vantive: A New Company Built On Our LegacyBaxter is on a journey to separate our ~$5B Kidney Care segment into a standalone company. Vantive* will build on our nearly 70-year legacy in acute therapies and home and in-center dialysis to provide best-in-class care to the people we serve. We believe Vantive will not only build our leadership in the kidney care...


  • Warszawa, Mazovia, Polska HAYS POLAND Sp. z o.o. Pełny etat

    Senior Cyber Defense Incident Responder Warsaw, Masovian Voivodeship Your new companyInternational company from the healthcare technologies industry. Your new roleYou will act as a local member of an international cybersecurity team. Senior Cyber Defense Incident Responder Warszawa Warszawa, Mazowieckie, Polska Your new companyInternational company from the...