IS COB Ctrls Sr. Tech Spec Job in New York, New York US

Reference Code: 11043783
Location: New York, NY, USA
Education Level: Bachelor's Degree
Description
This position will be part of a team of BISO's, CoB coordinators, Supplier Management Liaisons and Records Management Coordinators for ICG OPS and GTS.

The Business Information Security Officer (BISO) supports both the business and the program office the in implementation of corporate-wide information security program including policy awareness, entitlement management, investigations, and assessments.

The Continuity of Business Coordinator (CoB) supports the business and the program office in the implementation of Business Continuity policies, recovery programs, testing and reporting. This person ensures that the business units have a well-documented, communicated resilient recovery program.

The SM Liaison (Supplier Management Liaison) supports the business in the compliance of the Supplier Selection Management Policy. This person ensures that the business has a completed all the necessary activities to reduce supplier risk.

The Records Management Role supports the business in the compliance of the Citi Records Management Policy. They will ensure that the business retains, destroys and retrieves business records as necessary.

• Monitor the entitlement review program to enable reviews of access to systems and resources
• Escalate security incidents and monitor remediation, educating staff on how to recognize and report an incident and complying with assessment, reporting, recording, and monitoring defined by the Citigroup SIRT process
• Assist in Risk Acceptances when gaps are identified or review corrective action plans (CAPS)
• Organize third party IS assessments (TPISAs), validating third party processes against Citigroup's standards, identifying gaps, and helping the area track issues to closure
• Independently track status of supplier management processes and deliverables (information security assessments, maintenance of supplier entries in Firm's centralized supplier inventory, contract validity/expirations, NDAs)
• Review suppliers for business criticality and access to confidential data, and confirm related eligibility for assessment processes and process type
• Ensuring that all interdependent business recovery requirements are being addressed and included in the strategy and planning process.
• Maintain and update a robust Recovery plan that adapts to the dynamic needs of the business.
• Coordinate all data center, application, and Recovery Site tests.

• Experience with interpretation, creation, and application of IS policy and standards (e.g., ISO 2700x, ITIL, CobiT, OWASP)
• Past experience with 2 or more IS program element areas, including risk assessment, training and awareness, third party assessment, identify and entitlement, secure workplace, incident management
• Development, assessment, or implementation of experience business continuity management programs.
• Experience with supplier management including purchasing cycle, supplier assessment and SAS70.
• Experience with records management including information life-cycle management, SEC Rule 17a-4
• Experience with metrics and data mining. Specific skills in SQL and database technology.
• CISSP, CISA, ITIL certifications a plus.
• Strong risk analysis and problem solving skills
• Must have excellent communication skills, both verbal and written.
• Individual must be analytical, self-motivated, and detail oriented.
• Seeking a team player able to lead by example.
• Must have the ability to work well under pressure and comfortable dealing with senior managers.
• Must be a self-starter.