Third Party Information Security Assessor

hace 2 días


Heredia, Costa Rica Citi A tiempo completo

As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients’ best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do. We keep the bank safe and provide the technical tools our workers need to be successful. We design our digital architecture and ensure our platforms provide a first-class customer experience. Our operations teams manage risk, resources, and program management. We focus on enterprise resiliency and business continuity. We develop, coordinate, and execute strategic operational plans. Essentially, Enterprise Operations & Technology re-engineers client and partner processes to deliver excellence through secure, reliable, and controlled services.

Trust is part of our DNA at Citi. As such, we take safeguarding our customer data very seriously. The Chief Information Security Office (CISO) is made up of deeply dedicated and talented colleagues who work together to ensure the safety of Citi’s and our clients’ assets and information. We manage information security as an end-to-end program - one with a clear mandate and accountability. Our mission is to continually execute and enhance a global security program that is fully anchored to modern control and security frameworks, fully aligned with the technology of the firm, threat-focused and data-driven, and deeply integrated across all Citi businesses globally.

Being talent-driven, we are focused on attracting, developing, and retaining diverse and inclusive talent with a high technical skill level. As a member of our team we will provide you with career development opportunities at all stages of your career. Our employees model a passion for protecting Citi and our clients and believe in treating others with dignity and respect.

CISO

Third Party Information Security Assessor

**Description**:
The Third Party Information Security Assessor performs detailed examinations of Citi’s North America suppliers’ information security practices and controls. IS Assessor responsibility is to confirm supplier adherence to the same high information security standards to which Citi holds itself accountable and to identify & communicate information security risks related to our customer and business sensitive information. In accordance with Citi’s established Third Party Information Security Assessment (TPISA) process and framework, the essential duties are as follows.

Coordinate with TPISA stakeholders to initiate, scope and plan controls assessments of new and existing suppliers.

Perform assessments on-site at supplier locations or remotely via conference calls.

Obtain and review supplier responses and supporting documentation to validate supplier appropriate implementation of information security controls. Analyze the information to identify information security weaknesses or non-compliance with Citi standards.

Produce detailed documentation of assessments and perform threat analyses of gaps identified.

Communicate supplier information security issues to stakeholders, ensuring their understanding of associated risks and actions needed to remediate those risks.

**Qualifications**:
Industry certification such as CISSP, CISA or CISM required.

6+ years experience in a similar IT Audit, Assessor, or Information Security Officer role.

Strong technical and/or IT audit background in/practical knowledge of a wide variety of technologies. Technologies include server infrastructure & operating systems, network & web infrastructures, database architecture and intrusion detection/prevention systems.

Self-starter with the ability to manage and prioritize responsibilities through the effective use of time management techniques.

Team player with proven skills in influencing people without having direct management authority and motivating them to successfully complete tasks within required timelines.

Self-driven performer with established skills in tracking self and project performance, anticipating and recognizing problems and escalating issues appropriately.

Exemplary ability to interact and communicate both written and verbally with people at all levels, both technical and non-technical, in a dynamic environment where interactions are not always in person.

Excellent risk analysis and problem solving skills.

Must be flexible to ensure assessments are performed by the mandated compliance date and be able to manage multiple assessments simultaneously.

**Critical competencies**:
Must be able to communicate fluently in English

Education

Bachelor’s Degree (in Technology, Information Security or related major), or equivalent work experience.
--------------------------------------------
- **Job Family Group**: Technology
--------------------------------------



  • Heredia, Costa Rica Citi A tiempo completo

    As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients’ best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals any large tech company. Our...


  • Heredia, Costa Rica Citi A tiempo completo

    This is a Third Party IS Assessment (TPISA) Analyst role where the individual will work closely with the TPISA Program management team and other stakeholders to address questions and requests related to the Third Party Information Security Assessment process. **Responsibilities**: - Individually contribute, lead or participate as a team member on projects,...


  • Heredia, Costa Rica Experian A tiempo completo

    Company DescriptionExperian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and our clients to manage their data with confidence.We help individuals to take financial control and...


  • Heredia, Costa Rica Experian A tiempo completo

    Company DescriptionExperian is the world's leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society.We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for.In addition, for the last five years we've been named in the 100 "World's Most...


  • Heredia, Costa Rica Citi A tiempo completo

    The TPM Business Risk Analyst will be responsible for executing third party risk management activities and liaising with the **Business Activity Owner **/ **Third Party Officer** to ensure that all the controls are handled in a controlled and compliant manner according to all internal policies and procedures, and external rules and regulations in support of...


  • Heredia, Costa Rica Citi A tiempo completo

    In particular, this position sits with the Regional Third Party Risk Management Group in Global OTRC / TPRM and oversees Third Party risk for external and Internal (Inter Affiliates) third parties in LATAM Region, excluding Mexico, for all legal vehicles and their branches.The group is responsible for assisting country management in LATAM Countries, to...

  • Third Party Risk

    hace 3 días


    Heredia, Costa Rica Moody'S Investors Service A tiempo completo

    The Third Party Risk - Manager will work directly with the SVP of Third party risk to operationalize an approach to tier, monitor, assess and drive mitigating actions related to third party risk.Working with the business areas to understand their requirements and implement an approach to identify critical suppliers and use internal and external resources to...


  • Heredia, Costa Rica Sysco Costa Rica A tiempo completo

    This role is responsible for executing Cybersecurity M&A due diligence and leading cyber integration planning, coordination, and reporting while partnering across multiple Cyber, business, and technology cross function teams.**Requirements**:- Execute Cybersecurity M&A due diligence activities partnering with business and technology deal teams to identify...

  • Third-party Management

    hace 5 días


    Heredia, Costa Rica Citi A tiempo completo

    The Third-Party Management (TPM) Risk and Performance Officer will join Citi’s Enterprise Third Party Risk Management group, which is accountable for the end-to-end Third-Party Management program at Citi, covering both external suppliers and internal (Inter-Affiliate) service providers. The TPRM Risk and Performance Officer is responsible for the...

  • Third-Party Management

    hace 3 días


    Heredia, Costa Rica Citi A tiempo completo

    The Third-Party Management (TPM) Risk and Performance Officer will join Citi's Enterprise Third Party Risk Management group, which is accountable for the end-to-end Third-Party Management program at Citi, covering both external suppliers and internal (Inter-Affiliate) service providers.The TPRM Risk and Performance Officer is responsible for the development,...

  • Third Party Management

    hace 3 días


    Heredia, Costa Rica Citi A tiempo completo

    **Responsibilities**:- Independently assess' risks and drive actions to address the root causes that persistently lead to operational risk losses by challenging both historical and proposed practices.- Governance and oversight may include (not limited to) technology operational risk, risk for example.- Resolves transactional level escalations coming from the...

  • Business Sr. Analyst

    hace 2 días


    Heredia, Costa Rica Citi A tiempo completo

    The Business Sr. Analyst - Third Party and Financial Market Infrastructure is a seasoned professional global role. Applies in-depth disciplinary knowledge, contributing to the development of new techniques and the improvement of processes and work-flow for the area or function. This is an opportunity to implement and drive solutions globally. The position...


  • Heredia, Costa Rica Experian A tiempo completo

    Company DescriptionExperian is the world's leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society.We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for.In addition, for the last five years we've been named in the 100 "World's Most...


  • Heredia, Costa Rica Experian A tiempo completo

    Company DescriptionExperian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we empower consumers and our clients to manage their data with confidence.We help individuals to take financial control and...


  • Heredia, Costa Rica Experian A tiempo completo

    Full-timeEmployee Status: RegularRole Type: HybridDepartment: Legal & ComplianceSchedule: Full TimeShift: Day Shift**Company Description**:Experian is the world's leading global information services company.During life's big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers - we...


  • Heredia, Costa Rica Citi A tiempo completo

    **Responsibilities**: - Independently assess risks and drive actions to address the root causes that persistently lead to operational risk losses by challenging both historical and proposed practices. - Assist with the resolution of TPM Process-level escalations coming from internal partners. - Analyze various scorecards/performance management tools to...


  • Heredia, Costa Rica Stryker A tiempo completo

    **Why join Stryker?**: Our total rewards package offering includes bonuses, healthcare, insurance benefits, retirement programs, wellness programs, as well as service and performance awards - not to mention various social and recreational activities, all of which are location specific. **Know someone at Stryker?**: **Who we Want**: - ** Analytical problem...


  • Heredia, Costa Rica Re:Sources Global A tiempo completo

    Company Description**Job Description**:This position is an active member of the Global Security Office (GSO), the security organization of Publicis Groupe under Re: Sources, responsible for supporting security compliance activities globally to Groupe agencies.This position supports security requirements of Publicis Groupe, it's agencies, and ensures the...


  • Heredia, Costa Rica Dhl A tiempo completo

    **About the role**:We're looking for an experienced and passionate Consultant, Information Security "Threat and Vulnerability Management" to join our Information Security Services team!Being part of this team, you will drive our threat and vulnerability management across the technology stack.Your job is to identify and help remediating security threats and...


  • Heredia, Costa Rica Citi A tiempo completo

    **Responsibilities**:- Ensures compliance with the Citi's Third Party Risk Management objectives.- Gathering data and documentation necessary to complete the Third Party onboarding and ongoing Citi security policy requirements.- Planning and facilitating meetings with Third Party and internal stakeholders, taking all meeting minutes and managing any follow...