Skip to main content



The health and safety of our colleagues and candidates for employment are our highest priority. Accordingly, Citi continues to monitor the COVID-19 situation closely. We have implemented precautionary measures across our firm globally, including conducting all candidate interviews virtually on a temporary basis until further notice where needed.

ORM Technology and Cyber Risk Manager -SVP

Job Req ID 22538359 Primary Location New York, New York; Rutherford, New Jersey; Tampa, Florida Job Category Risk Management
Apply Now


The Operational Risk Management (ORM) Group at Citi is the firms reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report and manage operational risks while promoting the implementation of actions to address root causes which may lead to unintended operational losses. The ORM Technology and Cyber (ORM-T/C) team provides the specialist subject matter experts to provide oversight, challenge and proactively identify risks with Engineering, Infrastructure, Operations and Technology entities across the firm. We are the technology and cyber conscious of the bank. In line with the ORM framework, we aim to ensure that the internal controls that are designed to mitigate technology and cyber risks are managed, mitigated and aligned with our risk appetite.


The Operational Risk Sr Officer I will have oversight over Global Functions (Finance, HR, Risk, Legal, Compliance etc.), and Global Functions Technology. The oversight includes influencing and challenging the processes by which Citi's Technology Operational Entities provide technology services and products; independent assessment of the comprehensiveness and effectiveness of those processes, the inherent operational risks in technology process execution, the complete suite of control components in the information technology realm, and the acceptability of residual risk.

The role will leverage subject matter expertise, business experience, data analysis techniques, current events, and industry trends and best practices to inform the prioritization of risks and the second-line’s approach for associated challenge and influence activities.  The role will engage business and technology risk managers and process owners, and analyze technology risk and control data, to perform independent risk reviews from a global perspective.

The candidate must bring expertise in technology and cyber risk to set and drive high standards; perspective that fosters risk identification and mitigation techniques, and a commitment to transparency and learning that build a strong risk culture. The expected result is to help protect the firm and its reputation while enabling progress.

Key Responsibilities:

This role will interact on a regular basis with business management, operational risk managers, technology leads, and colleagues within Technology/Cyber risk management. The candidate will lead independent challenge and influence Technology/Cyber activities in Global Functions Technology, and Global Functions; their capabilities to proactively identify and remediate technology risks, using technology risk metrics to both verify and validate Technology/Cyber risks and control in the context of business processes, applications, and infrastructure. The candidate will be responsible for assessing the quality of technology management processes and corresponding metrics data. The candidate will identify gaps, inconsistencies and other integrity issues in technology controls and risk metrics and recommend solutions. The candidate will verify and validate technology control measures in the context of technology processes, support applications, and infrastructure. 

Specific responsibilities include:

• Guide and influence the coverage area activities leveraging subject matter knowledge to drive organizations mission and value proposition

• Independently assess inherent technology and cyber risks relevant to corporate business process execution, the suite of control components in the IT realm, and the acceptability of residual risk.

• Analyze data and leverage existing tools to identify risks, and develop appropriate response

• Advise on continuous monitoring and control test methods and recommend technology metrics in support of decisions concerning technology control objectives.

• Oversee the business’s identification and management of Key Operational Risks, related indicators, and associated thresholds

• Challenge business and technology risk self-assessments

• Challenge technology scenario analysis activities

• Challenge lessons learned reviews performed by the business and technology

• Perform independent operational risk reviews

• Oversee the management of technology control issues 

• Advice on best practices leveraging expertise and industry insights


The Operational Risk Sr Officer I will have over 10 years of hands-on technical experience in IT management, Risk and controls within globally complex, dispersed and diverse organizations.  He/she will be well versed in technology management and information security best practices and will proactively remain abreast of emerging technology and cyber risks.  Ideal candidate would have had strong experience in technology/cyber risk management with previous experience with corporate functions or similar applications (e.g.  Systems supporting Human Resources, Legal, Risk, Compliance, Corporate Treasury, etc.)

More specific proven experience, knowledge and skills are outlined below:

• Experience with enterprise technology architecture as a holistic structure that includes people, process, and technology components combined to achieve business goals for automation.

• Strong knowledge/experience in risk assessment and measurement of cloud applications, infrastructure components, and database management systems

• Strong knowledge of system, software, and security/software development lifecycle including their risk identification, and assessments

• Working familiarity with data warehousing and big data environments.

• Strong experience leading operational risk reviews including identification of potential issues, and coordination with various teams including leadership

• Working familiarity with automated monitoring tools and incident tracking tools to effectively communicate and manage incidents, defects, and data quality issues.


• Ability to interact with and influence people/groups of widely varying disciplines and backgrounds.

• Ability and confidence to exercise influence over a wide range of individuals at all levels of technical & business leadership.

• Strong presentation skills: able to use data to tell a clear, compelling story

• Strong analytical and problem-solving skills.

• Comfortable with public speaking across various forums and be able to effectively and logically communicate when ideas are being challenged in an open forum.

• Comfortable interacting directly with technology executive leadership, including in a high stress environment.

• Understands the perspective of regulators and has the ability to shape messages and content to respond to the requirements.

• Strong planning, organization and time management experience that is strategically oriented, an innovative thinker, and a demonstrated and decisive decision maker.

• Able to collaboratively manage initiatives that span multiple geographic locations and time zones.

• Navigates organizational complexity; demonstrates organizational savvy.

• Builds partnerships across functions and regions; collaborates well with others.


• The role is global, and the incumbent must be proactive and capable of leading solutions to global issues with others in different regions and time zones.

• The successful candidate will need to be a hands-on, self-starter, and able to manage tasks/timelines for self and others.


Job Family Group:

Risk Management


Job Family:

Operational Risk


Time Type:

Full time


Primary Location:

New York New York United States


Primary Location Salary Range:

$152,050.00 - $228,080.00


Citi is an equal opportunity and affirmative action employer.

Qualified applicants will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Citigroup Inc. and its subsidiaries ("Citi”) invite all qualified interested applicants to apply for career opportunities. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.

View the "EEO is the Law" poster. View the EEO is the Law Supplement.

View the EEO Policy Statement.

View the Pay Transparency Posting


Effective November 1, 2021, Citi requires that all successful applicants for positions located in the United States or Puerto Rico be fully vaccinated against COVID-19 as a condition of employment and provide proof of such vaccination prior to commencement of employment.

Apply Now
  • Join our team
    of 220,000+
    strong diverse employees

  • Socially minded employees volunteering in communities across 90 countries

  • Meaningful career opportunities thanks to a physical presence in over 95 markets

We foster a culture that embraces all individuals and encourages diverse perspectives, where you can make an impact and grow your career. At Citi, we value colleagues that demonstrate high professional standards, a strong sense of integrity and generosity, intellectual curiosity, and rigor. We recognize the importance of owning your career, with the commitment that if you do, we promise to meet you more than half way.

Saved Jobs

You have no saved jobs

Previously Viewed Jobs

You have no viewed jobs