Group Information Security Officer (GISO) recruitment
Job Background/context:
The ICG Global Information Security group is part of the ICG OT - CAO organization. The team is responsible for the oversight and the execution of the Citigroup Information Security Program across ICG Ops. There is significant Senior Management interaction needed to execute this position. This position will be the point person for EMEA SB Ops. Candidates will need to understand the business and be able to interpret the IT Risk policies on the business' behalf.
Key Responsibilities:
- Engage and ensure agreement with business and technology executives to drive the information security program and information risk management activities across EMEA SB Ops.
- Provide strategic risk guidance for EMEA SB Ops business and technology projects, including the evaluation and recommendation of IS controls.
- Manage security incidents and events to protect corporate IT assets, including intellectual property, regulated data and the company's reputation.
- Work directly with the EMEA SB Ops business units to facilitate the IS risk assessment and risk management processes, and work with stakeholders on identifying acceptable levels of residual risk.
- Leadership and management, including hiring, training, staff development, and performance management of EMEA SB Ops IS officer staff.
- Drive risk-based processes for IS, including assessment and treatment for risks that may result from business processes, technology, vendors, partners, consultants and other service providers.
- Develop and manage information security budgets, and proactively monitor them for variances.
- Participate in the management of information security awareness training programs for employees, contractors and approved system users.
- Continue to improve the IS risk profile of the EMEA SB Ops business and operations areas and work to develop a method of measuring and reporting success.
- Engage in, and facilitate, the following IS risk processes;
- Information Security Risk Assessments,
- Third Party Information Security Assessments,
- Identity Access Management,
- EntitlementAccess Control Review Activities,
- Data Protection Functions,
- Application Vulnerability Assessments,
- Audit Reviews.
- Strong leadership and influence management skills and the ability to work effectively across a large multi-national organization.
Skills
- The ability to build strong relationships at all levels and across all EMEA SB Ops business units and technology and support organizations, while understanding business priorities.
- Ability to strike the critical balance between Citi's information protection requirements, risk mitigation, as well as often competing business priorities.
- Strong management abilities, with the capability to develop and guide information security team members and work with minimal supervision.
- Experience working with legal, audit and compliance staff as well as external regulators.
- Experience developing and maintaining policies, procedures, standards and guidelines.
- Familiarity with applicable legal and regulatory requirements.
- Significant experience in an information security or risk management role and at least four years in a management capacity. Financial services experience strongly preferred.
- Undergraduate degree required. Master's degree a plus.
- CISSP, CISM, or CISA preferred.
- Excellent project management skills.
- Excellent verbal, written and interpersonal communication skills, including the ability to communicate effectively with the business and IT organization, project and application development teams, management and business personnel, as well as external clients and business partners.
- Advanced analytical and problem solving skills. Must be able to net-out the significant amount of IS and IT Risk data and metrics into a business context which is clear and actionable by SB and OT Senior Management.
-
Exceptional candidates who do not meet these criteria may be considered for the role provided they have the necessary skills and experience.
Valuing Diversity:
Demonstrates an appreciation of a diverse workforce. Appreciates differences in style or perspective and uses differences to add value to decisions or actions and organizational success.