The Operational Risk Management (ORM) Group at Citi is the firms reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report and manage operational risks while promoting the implementation of actions to address root causes, which may lead to unintended operational losses. The ORM Technology and Cyber (ORM T/C) team provides the specialist subject matter experts to challenge Enterprise, Infrastructure, Operations and Technology entities across the firm. We are the technology and cyber conscious of the bank. In line with the ORM framework, we aim to ensure that the internal controls that are designed to mitigate technology and cyber risks are managed, mitigated and aligned with our risk appetite.
The Enterprise Tech/Cyber risk function is responsible to influence, challenge, and provide oversight to Enterprise systems and platforms including Cloud. The Operational Risk Sr Officer I - Enterprise Platforms and Infrastructure Risk is part of the Second Line function providing oversight including influencing, and challenging the First Line and the businesses on risks with enterprise systems, infrastructure, and IaaS/PaaS. Oversight areas includes, but is not limited to, governance, identification of risks, developing remediation strategies, and influencing the strategy and execution of the program. This position will be actively working with the ORM Business and Regional teams to provide subject matter expertise and align the oversight and challenge activities with the components of the operational risk management framework.
The objective of the Operational Risk Sr Officer I - Enterprise Platforms and Infrastructure Risk is to reduce operational losses while enabling the objectives of the program at Citi, through front ending the initiatives in firm regarding internal platforms and Infrastructure, and IaaS/PaaS to identify operational risks and recommend mitigations.
The role will leverage subject matter expertise, business experience, data analysis techniques, current events, and industry trends and best practices to inform the prioritization of risks and the second-line's approach for associated challenge and influence activities. The role will engage business and technology risk managers and process owners, and analyze technology risk and control data, to perform independent risk reviews from a global perspective.
The candidate must bring expertise in technology and cyber risk to set and drive high standards; perspective that fosters risk identification and mitigation techniques, and a commitment to transparency and learning that build a strong risk culture. The expected result is to help protect the firm and its reputation while enabling progress.
The role will be responsible for building engagement with key stakeholders, anticipating, challenging, and mitigating risks that could affect business objectives.
Identify risks and challenge existing platforms and infrastructure standards, and implementations.
Influence the evolving technology standards to provide oversight, and challenge on their effectiveness, alignment to industry standards.
Influence and challenge observability in platforms and infrastructure including IaaS/PaaS. Assess and challenge alignment across platforms and infrastructure with organization's Observability and Data strategies
Review and identify risks with global virtualization environment hosting private cloud and VDI desktops
Influence and challenge software-defined infrastructure, and networking.
Provide oversight, and conduct reviews on management of the multi-tenant complex hybrid platforms
. Overview of enterprise strategy for platforms and infrastructure and challenge their appropriateness and effectiveness. Provide oversight and challenge First Line on integration of technology standards with LoBs.
Maintain and apply a broad and current industry perspective on technology trends in platforms and infrastructure, and leading best practices,
Qualifications:The Senior Technology and Cyber Risk position requires over 10 years of technology/cyber risk and controls experience in enterprise platforms, infrastructure, and IaaS/PaaS within globally complex, dispersed and diverse organizations.
More specific experience, knowledge and skills are outlined below:
• Experience in a technology infrastructure risk and control role with extensive experience in infrastructure technologies and platforms, and virtualization environment.
• Experience with enterprise technology architecture as a holistic structure that includes people, process, and technology components combined to achieve business goals for automation.
• Strong knowledge/experience in risk assessment and measurement of enterprise platforms, infrastructure, and virtualization environment.
• Strong knowledge of software-defined infrastructure and networking, including their risk identification, and assessments
• Extensive knowledge of and experience in identification and management of risks for PaaS/IaaS
• Strong experience leading operational risk reviews including identification of potential issues, and coordination with various teams including leadership
• Ability to interact with and influence people/groups of widely varying disciplines and backgrounds.
• Ability and confidence to exercise influence over a wide range of individuals at all levels of technical & business leadership.
• Strong presentation skills: able to use data to tell a clear, compelling story
• Strong analytical and problem-solving skills.
• Comfortable with public speaking across various forums and be able to effectively and logically communicate when ideas are being challenged in an open forum.
• Comfortable interacting directly with technology executive leadership
• Builds partnerships across functions and regions; collaborates well with others.
• The role is global, and the incumbent must be proactive and capable of leading solutions to global issues with others in different regions and time zones.
• The successful candidate will need to be a hands-on, self-starter, and able to manage tasks/timelines for self and others.
Job Family Group:
Citi is an equal opportunity and affirmative action employer.
Qualified applicants will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Citigroup Inc. and its subsidiaries ("Citi") invite all qualified interested applicants to apply for career opportunities. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.
View the "EEO is the Law" poster. View the EEO is the Law Supplement.
View the EEO Policy Statement.
View the Pay Transparency Posting