Onsite
Posted 2 hours ago
Save Job

Job Details

The Information Security Operations (ISO) Sr Manager is a senior management level position responsible for accomplishing results through the management of a team or department in an effort to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with Citi's data security policy.

Responsibilities:

  • Support the implementation of Information Security (IS) Training Plan, by verifying training participants completed the training and understand IS requirements
  • Coordinate with cross-functional Operations and Technology (O&T) counterparts and teams to improve O&T risk oversight
  • Attend and participate in internal/external IS forums and risk committees when necessary and provide IS updates to the business
  • Ensure stakeholders are held accountable for IS controls, and understand responsibilities in risk mitigation and remediation
  • Improve processes, remove IS deficiencies and enhance current tools that reduce an overall risk profile
  • Ensure security practices and standards compliance to reduce the likelihood of audit, regulatory and legal liabilities and reduce security risks by enhancing controls and minimizing weaknesses in Citi’s applications portfolio
  • Ensure non-compliant items are addressed through coordination with Business Manager and business staff
  • Support the Global Information Security (GIS) policies, standards, and initiatives development and implementation
  • Provide guidance on IS aspects of projects in support of business initiatives
  • Establish communication channels with cross-sector ISOs to efficiently tackle security issues that span multiple businesses
  • Manage project deadlines, deliverables, planning, budgeting and policy formulation for the team, including short-term resource planning
  • Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency, as well as effectively supervise the activity of others and create accountability with those who fail to maintain these standards.


Qualifications:

  • 6-10 years of relevant experience
  • Knowledge of Scripting and Programming Languages preferred
  • Demonstrated ability to interpret and apply information security policies, standards and procedures
  • Consistently demonstrates clear and concise written and verbal communication
  • Proven influencing and relationship management skills
  • Proven analytical skills


Education:

  • Bachelor’s degree/University degree or equivalent experience
  • Master’s degree preferred


This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.

El participante seleccionado deberá asumir la implementación, operación y mejora continua de los siguientes componentes para el control de accesos:

I.            Gestión de Identidades
- Alta, modificación y baja de usuarios (empleados, contratistas, terceros).   
- Integración con los sistemas de Información del banco y/o directorios existentes (ej. SAP, Oracle HCM, Workday, otro).

- Soporte a usuarios (resolución de problemas).

II.   Gestión de Accesos
- Control de acceso basado en roles (RBAC), atributos (ABAC).
- Gestión de accesos privilegiados (PAM) y gestión de ID funcionales.
- Automatización Robótica de procesos  (RPA) / gestión de ID de Bot.

- Gestión de acceso federado (SSO, SAML, OIDC).
- Acceso seguro a sistemas on-premise y en la nube.

III.         Autenticación y Autorización

- Administración de contraseñas
- MFA (autenticación multifactor).
- Integración con soluciones de autenticación existentes.

IV.         Revisión de facultades y acceso
- Revisión periódica de accesos y facultades.
- Auditoría y monitoreo continuo.
- generación de reportes

V.          Integraciones Requeridas
- Active Directory
- Aplicaciones internas y de terceros
- Sistemas core bancarios

  • Project management experience.
  • Other Risk Management activities should be as Sector or business IS SME or some risk management role.
  • Excellent consulting and problem solving skills.
  • In depth knowledge of IS programs.
  • Advanced presentation skills, program management, and relationship management skills.
  • Able to work with senior business management to implement IS strategy.
  • University degree, in any technical or adminstration career is desirable
  • Professional certification, such as CISSP, CISM , CISA or willingness to obtain certification within 12-18 months of start date
  • Exhibit strong influencing / negotiation skills as well as written/verbal communication skills.
  • English 80%

------------------------------------------------------

Job Family Group:

Technology

------------------------------------------------------

Job Family:

Information Security

------------------------------------------------------

Time Type:

Full time

------------------------------------------------------

Most Relevant Skills

Please see the requirements listed above.

------------------------------------------------------

Other Relevant Skills

For complementary skills, please see above and/or contact the recruiter.

------------------------------------------------------

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

 

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.

View Citi’s EEO Policy Statement and the Know Your Rights poster.

Mission
We're connecting diverse talent to big career moves. Meeting people who boost your career is hard - yet networking is key to growth and economic empowerment. We’re here to support you - within your current workplace or somewhere new. Upskill, join daily virtual events, apply to roles (it’s free!).
Are you hiring? Join our platform for diversifiying your team
BANAMEX - Access Control Sr Manager - VP
Save Job