Our Ability Jobs

Job Information

Citizens Risk Cybersecurity Sr Manager in Boston, Massachusetts

Description

Citizens currently has an opening on Operational Risk Management team focused on Cybersecurity risk. The role will provide independent oversight, review, and challenge of information security and technology related risks. The colleague works with key stakeholders across the enterprise ensuring material risks within these groups are well defined and managed appropriately. It is expected that this colleague has strong domain knowledge of emerging technology risks, information security standards, best practices, US regulatory requirements, and the external environment.

Responsibilities:

  • This colleague will be focused on the information security and technology space. Primary responsibilities include independent oversight, review, and challenge of risk management activities within the first line of defense, including the effectiveness of the formal risk program activities. Activities include Risk and Control Self-Assessments, Issues Management, Material Risk Identification, Change Management, new business initiative risk assessments, and other formal programs.

  • Advise first line risk partners on complex risk issues and challenges, while identifying and assessing aggregate enterprise-wide risks. Working with key stakeholders, including all three lines of defense, escalate emerging risk issues that require remediation and work directly with stakeholders while driving accountability. Maintain strong relationships with all three lines of defense, as well as the regulatory agencies.

  • Understand the external environment, including emerging risks within the industry and the priorities of the regulatory agencies. Determine how these changes affect the risk profile of the enterprise and work with appropriate stakeholders to ensure mitigation strategies are underway.

  • Participate in the cybersecurity incident response activities to ensure risks are properly assessed in real time and mitigating actions are appropriate. Post incident, lead or participate in root cause analysis and opine on next steps.

  • Lead targeted risk assessments on emerging issues to provide an independent opinion on the impact to the enterprise.

  • Operate within existing governance structures with an eye towards making these processes more efficient and effective. Manage applicable policy and program governance, while performing assurance activities to assess corporate wide compliance.

  • The role may be co-located as needed with the relevant business and must be actively engaged to support the business with providing domain-relevant advice, monitoring, and credible expert challenge to ensure the independent Operational Risk Management Program is effectively implemented.

  • Required Experience

  • 4+ years risk management experience from working in financial services industry.

  • 4+ years demonstrated domain expertise and experience within the information security and technology risk areas.

  • Experience in an organization that is under strong regulatory oversight and scrutiny.

  • Proven ability to develop and maintain high impact relationships with senior executives.

  • Expert knowledge of internal controls and risk assessment

  • Deep understanding of banking products and operations; regulatory requirements; and key processes, controls, and exposure areas

  • Influencing and conflict resolution skills

  • Excellent business writing skills

  • Proficient use of MS Word, Excel and PowerPoint

Education:

  • Bachelor’s degree Required.

  • Certifications Preferred: Certified Information System Security Professional, Certified Information Security Manager Certified Information Systems Auditor, Certified in Risk and Information System Controls, or other relevant risk certifications.

Hours & Work Schedule: Hybrid - 3 days in the office, 2 working from home.

  • Hours per Week: 40

  • Work Schedule: Monday - Friday

    #LI-CITIZENS2

Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.

Equal Employment Opportunity

At Citizens, we are committed to fostering an inclusive culture that enables colleagues to bring their best selves to work every day. Employment decisions are based solely on experience, performance, and ability. Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression (including transgender individuals who are transitioning, have transitioned, or are perceived to be transitioning to the gender with which they identify), genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws.

Equal Employment and Opportunity Employer

Citizens is a brand name of Citizens Bank, N.A. and each of its respective affiliates.

Why Work for Us

At Citizens, you'll find a customer-centric culture built around helping our customers and giving back to our local communities. When you join our team, you are part of a supportive and collaborative workforce, with access to training and tools to accelerate your potential and maximize your career growth

Background Check

Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.

DirectEmployers