This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Infrastructure Information Security Review Process (I-ISRP) Team sits in CISO and is responsible for executing the information security (IS) assessments of infrastructure products. This will ensure appropriate risk treatment while reducing the number of vulnerabilities in Citi’s production environment, in compliance with Citi, legal, regulatory and other applicable policies, standards and technical requirements. The Information Security Technology Senior Specialist is responsible for leading efforts to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with Citi's data security policy.
Job Responsibility:
Perform the information security review of infrastructure products and verify their compliance to the Citi Information Security Standards (CISS)
Take ownership of the IS certification of certain products and solutions, advising clients and making security decisions on products and solutions to be released into Citi production environment
Evaluate the security and compliance of the products by reviewing documentation and by hands-on testing
Document any findings, security breaches and non-compliant items
Assess risks of identified gaps, advise clients and partners on the feasibility of addressing them
Presenting results of an IS review, defending key points towards even senior clients, while remaining helpful, flexible and open to good solutions
Execute strict quality control measures into all processes to consistently meet standards
Generate metrics and ensure productivity to guarantee Service Level Agreements (SLAs) and client expectations are met
Support Technical Information Security Officers in their work for remediating any non-compliant items
Embracing new technologies, actively seeking out opportunities for improving efficiency of the Information Security Review Process and seek out possibilities for implementing automation for any manual efforts
Ensure essential procedures are followed, define operating standards and processes and develop procedures and process control manuals
Perform information security awareness and training activities
Coordinate any major initiatives in the team overarching multiple product reviews or affecting major process changes
Provide informal guidance or on-the-job-training to new team members
Requirements:
5-7 years working in an Information Technology related field
At least 2 years of experience in an Information Security field
Degree in a technology related discipline is strongly preferred
CISSP, CISA, CISM or equivalent exam, or commitment to obtain it in the near future
Experience with Unix-based systems
Knowledge of computer networking concepts
Familiarity with cloud-based technologies
Consistently demonstrates clear and concise written and verbal communication