This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
This is a high-impact opportunity to shape how one of the world's leading financial institutions manages third-party risk and operational resilience at an enterprise scale. As a Lead Analyst within Citi's Operational Risk Management (ORM) function, you will oversee resilience frameworks, monitor emerging risks, and deliver actionable insight to senior leadership — playing a direct role in protecting Citi's financial stability and long-term business performance. You will work across business units, first-line risk teams, and entities to ensure risk governance is consistent, effective, and continuously improving. Join our Risk Management team and play a key role in protecting Citi's financial stability and reputation. You will help shape our operational risk strategies, focusing on resilience and third-party risk to ensure the firm is fortified against potential threats.
Job Responsibility
Provide strategic support for operational risk management policies and procedures
Drive the consistent identification, measurement, monitoring, and management of risks
Oversee the development of risk monitoring programs, including key risk indicators (KRIs) and dashboards
Lead oversight reviews, including root cause analysis and regulatory compliance checks
Promote a culture of continuous improvement based on resilience testing and third-party assessments
Oversee first-line activities related to business disruption, crisis management, and continuity
Report on operational risk status, trends, and key developments to senior management
Support internal and external audits and regulatory examinations
Requirements
6+ years of experience in risk management or a related field
Strong understanding of Third-Party and Operational Resilience Frameworks and regulatory requirements
Technical knowledge of Resilience and Third-Party Risk principles, including cloud technology