Lead Iso Analyst Resume
3.00/5 (Submit Your Rating)
SUMMARY
- Re - engineered Incident Response process, resulting in efficiencies and estimated cost savings $2.3 million per year
- Administered impact and data classification assessments for GDPR and CCPA regulations which identified and addressed data misclassifications - estimated cost savings $1.2 million per year
- Managed the development of Citi’s Information Security Risk Assessment Program taking it from an Excel Spreadsheet to a multi-module system integrated with other systems and programs
PROFESSIONAL EXPERIENCE
Lead ISO Analyst
Confidential
Responsibilities:
- Manage all aspects of Institutional Clients Group Markets & Securities Services (ICG MSS) - comprising 12 businesses with over 8000 employees for North America, Europe, Middle East & Africa, providing a broad range of capital market services to companies, governments and other institutions in approximately 80 countries
- Deliver end to end support of Information Security Risk Control Assessments as subject matter expert
- Influence and manage special initiatives for various Information Security programs with special focus on Regulatory Compliance, Data Classification, Data Protection, Privileged Access Management, Security Incident & Event Management (SIEM), Information Security Risk Assessments
- Introduce changes and enhancements relevant to the security controls of business applications and processes to enhance the Information Security profile of the business
- Ensure IS risks are proactively managed, effectively controlled, mitigated, remediated and where required obtain Senior Business Heads’ support and buy-in for residual risk acceptance
- Partner with the business to ensure information risks are identified, assessed, mitigated and controlled through the deployment of a sustainable information security risk management program
- Monitor changes in the risk profile of highly critical systems
- Assist with reporting, analyze trends, and manage exceptions in an effort to identify emerging risks and establish preventive, detective and compensating controls
- Recommend and facilitate implementation of security solutions
- Manage, Train and mentor junior information security risk managers
Subject Matter Expert
Confidential
Responsibilities:
- Coordinated end to end security activities for Confidential information security programs: Information Security Risk Assessment (ISRA), Third Party Information Security Risk Assessments (TPISA), Vulnerability Assessments (VA) and Secure System Development Lifecycle (SSDLC)
- Established and maintained effective risk culture by implementing Citi’s Information Security Risk Assessment Process and enterprise-wide roll out of the tool to manage IRSA process
Subject Matter Expert
Confidential
Responsibilities:
- Managed User Acceptance Testing (UAT), including development of test scripts, providing demonstrations of new functionality, facilitating daily checkpoint calls during test execution, researching potential defects and tracking/validating defect fixes
- Acted as primary coordinator for system level enhancement/modifications, provide bulk data entry services with business approval, and perform sanity checkouts after all system maintenance events
- Guided software development managers in Software Development Life Cycle to ensure adherence to Citi Information Security Standards
- Liaison with Information Security Risk Assessment user community and key stakeholders across all Citi global businesses, technology teams, and internal and external auditors
- Managed day-to-day support for, Information Security and Issue and corrective action plan applications leveraging a 24/5 Helpdesk, as well as a team of Subject Matter Experts responsible for resolving more complex inquiries and timely communication of key information for the end user community numbering over 26,000 unique individuals
- Served as designated subject matter expert (SME) on proprietary risk management systems: -Citi Information Security Risk Assessment system (CIRAS); Issue and Corrective Action Plan System (iCAPS); and proprietary operational risk self-assessment system (Catalyst)
- Managed all aspects of proprietary Security Incident Management Online (SIMON) program (Citi’s sunset proprietary SIEM software), including SDLC, deployment, UAT, end-user support
Senior Risk Management Consultant
Confidential
Responsibilities:
- Managed cross-functional Oracle and Global Citi teams in the first 2 major Confidential enterprise-wide roll-out projects: operational risk control self-assessment (Catalyst) and issue and corrective action plan system (iCAPS)
- Delivered Basel II capital requirements seminars and presentations to banking clients’ senior managers
- Maximized client relations and managed client services for key banking clients, including Confidential
- Seamlessly led projects and initiatives across domains, including IT risk, information security, vendor management, Basel, operational risk, and wealth management
