The Info Sec Prof Senior Analyst is an intermediate level position responsible for leading efforts to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with Citi's data security policy.Responsibilities:
- Identify potential information security (IS) risks and make recommendations for enhancement
- Collect and analyze security risk evidence and coordinate with internal and external compliance and auditing agencies / officials
- Execute meetings and communicate complex security topics and safe IS practices with all levels of the organization
- Ensure that controls are utilized daily and that non-compliance remediation is addressed
- Provide IS consulting services, including interpreting and/or clarifying information security policy, procedures, standards or concepts
- Assist with defining and implementing IS standards to align procedures and practices in compliance with Citi standards
- Educate and advise on safe information security practices and current, changing, and/or recommended information security requirements
- Validate compliance with IS policies, practices, and procedures, and resolve a variety of IS related issues in coordination with the business
- Assume informal/formal mentorship role within teams and assist with the coaching and training of new team members
- Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency.
Qualifications:
- 5-8 years of relevant experience
- Applicable Certifications or willingness to earn within 12 months of joining
- Consistently demonstrates clear and concise written and verbal communication
- Proven influencing and relationship management skills
- Proven analytical skills
Education:
- Bachelor’s degree/University degree or equivalent experience
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
Citi is committed to continuously strengthening the controls around the protection of sensitive data. This role is part of the CISO Global Data Redaction Team which works with Application Teams in safeguarding and protecting sensitive data in non-Production environments for all of Citi. This is a critical position responsible for working as a partner with business segments to properly redact and test at-risk applications and will have the opportunity to work on redacting applications, in multiple platforms, using best practice and established methodologies. The candidate will be responsible for working with Applications Teams to help identify and secure the sensitive data within the non-production environments and will work to continuously improve client service and seek strategic solutions and enhancements to identifying and securing personally identifiable information. The candidate will need to be able to work proactively and independently to understand the customer requirements and provide effort estimation on planned tasks and propose technical solutions.
Responsibilities:
- Gain experience working with Talend, an extract, transform, and load (ETL) tool.
- Work with various types of databases, such as Oracle, SQL Server, as well as redaction of files on Windows, Unix, and Mainframe platforms.
- Develop and implement algorithms, scripts, and processes to continuously improve client service and seek strategic solutions and enhancements to identifying and securing personally identifiable information (PII).
- Gain knowledge of all phases of the Software Development Life Cycle process by being fully involved in analysis, design, development, implementation, and maintenance of various application projects.
- Learn about information security and data transformation techniques, as well as, identifying and securing sensitive data (i.e.: PII).
- Research new products/tools and provide recommendations to streamline the Redaction Team's process and solve new client requirements.
- Work with information security officers and application development community to assist in identifying and reducing IS risk within applications and ensure adherence to policies.
- Work with business teams, information security officers, infrastructure, engineering, and architecture teams, and DBAs/SAs to ensure appropriate solutions are implemented in a timely manner to support our business users.
Qualifications:
- 7+ years of experience working in a database environment (Oracle, SQL Server, or Sybase)
- Extensive hands-on experience with Unix and shell scripting.
- Experience in writing reusable, testable, and efficient code with proper error and exception handling.
- Understanding of all phases of the Software Development Life Cycle process.
- Experience with source code management and deployment, and release management are a plus.
- Must be able to work independently, as well as in a team environment and ability to prioritize tasks and projects so that deadlines are met.
- Highly effective verbal and written communication skills.
- Excellent organizational and project management skills.
- Strong analytic and troubleshooting skills.
- Ability to demonstrate both technical and functional/business knowledge regarding past projects.
- Understanding and experience with ETL tools and data processing, such as Talend, Ab Initio, or Informatica is a big plus
- Knowledge of connectivity/file transfer protocols, such as NDM, SCP, SSH is a big plus
- Experience creating/scheduling jobs in Autosys is a plus
- Knowledge/experience working with CyberArk is a plus
- Knowledge/experience with Mainframe files, copy jobs and data handling is a plus
- .Experience in creating Requirement/Specification documents is a big plus.
- Prior working experience with Citigroup is a big plus
-------------------------------------------------
Job Family Group:
Technology
-------------------------------------------------
Job Family:
Information Security
------------------------------------------------------
Time Type:
Full time
------------------------------------------------------
Citi is an equal opportunity and affirmative action employer.
Qualified applicants will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Citigroup Inc. and its subsidiaries ("Citi”) invite all qualified interested applicants to apply for career opportunities. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.
View the "EEO is the Law" poster. View the EEO is the Law Supplement.
View the EEO Policy Statement.
View the Pay Transparency Posting