About this role
IT Security - Information Systems Security Office Team (‘ISSO Team’) is a group-wide resource, which covers all the divisions within the Citco Group of companies as defined on www.citco.com. The ISSO Team strategy is to uphold, maintain and continuously improve the Role Based Access Group (RBAG) framework within Citco’s User Access Management process.
The ISSO Team has resources based in Amsterdam (The Netherlands), Manila (The Philippines), Hyderabad (India) and Toronto (Canada).
The Junior Information Systems Security Officer (Junior ISSO) will support access governance for production applications under the Role Based Access Group (RBAG) framework which is within Citco’s User Access Management process. The Junior ISSO will assist with access reviews, onboarding/offboarding of applications to Citco’s Intake/Outtake/RBAG process, monitoring production application access, and remediation activities while operating in a second-line, check and-challenge capacity.
- Work within the ISSO Team for providing an efficient and effective method to manage information security risk,
improve the effectiveness of information security and user access control to ensure the organization’s information
and information systems are protected from unauthorized access, use and disclosure. This includes:
o Partner with the business and other group functions to develop and execute the User Access Management Framework.
o Conduct monthly monitoring reviews in accordance with the monitoring plans and report results to relevant stakeholders.
- Engage with Business and Support Function Management across the Citco Divisions to further improve the control
environment in a collaborative manner.
- Complete the tasks assigned by ISSO Management and effectively achieve the established goals and objectives.
- Collaborate with IT Security team members to effectively and efficiently accomplish departmental goals and
objectives.
- Reports to ISSO Management and cultivates and maintains positive, professional working relationships with ISSO
staff.
- Supports access governance processes by reviewing access requests and approvals for production applications in
accordance with Citco’s User Access Management and Role-Based Access Group (RBAG) processes.
- Assists with client access certification campaigns and reviews Active Directory (AD) security groups to ensure
appropriate access and compliance with established security policies and procedures.
- Monitors application access records, identifies potential anomalies or irregularities, and escalates issues to the ISSO
Management for investigation and resolution.
- Validates access provisioning activities against approved access requests and collaborates with provisioning teams
to investigate and resolve discrepancies.
- Maintains accurate and up-to-date documentation of access controls, remediation activities, and related security
processes.
- Supports audit and compliance requests by providing accurate documentation, access records, and relevant
information in a timely manner.
- Participate in the onboarding of new applications to Citco’s User Access Management and Role-Based Access Group
(RBAG) processes, ensuring alignment with established access control and security requirements.
- Attends meetings with business and technical stakeholders, documents action items, and tracks assigned owners to
support timely completion.
- Completes assigned ISSO tasks within agreed timelines and in line with function objectives.
- Monitors ACL control effectiveness and work with the team to improve application match rates 100%.
- Identifies root causes of control breaks and supports preventive actions.
- Maintains expertise through continuous learning and training to stay abreast of emerging and proposed developments in Information Security, Risk Management, and Auditing, leveraging insights from various industryorganizations and assessing their potential impact on the company.
Requirements
Education:
- The candidate should possess at least a relevant bachelor’s degree.
Optional Qualification(s)/Certification(s):
- CIA, CISA, CRISC, or other relevant IT/Risk/Audit/IT Security certifications.
Professional Experience:
- One up to three years of experience in progressive Risk Management, Internal
Controls, Internal Audit, or IT Audit function within a financial institution or Big 4
audit firm, ideally with experience in IT and/or IT Security functions.
Computer Application(s):
- Hands-on experience with automated internal audit applications and tools, such as
ACL Analytics and SQL, is an advantage. Proficiency in Microsoft Word, Excel,
PowerPoint, and Visio is also expected.
Language(s):
Excellent written and spoken English is required.
Key Competencies:
Client Focus.
Effective Communication.
Sound Decision-Making.
Results-Oriented
Personal Characteristics:
Confident and articulate, with the ability to communicate clearly, concisely, and
effectively, both oral and written.
Strong attention to detail, with a commitment to accuracy and quality.
Diplomatic and professional, with the tenacity and persistence required to
achieve objectives and complete tasks.
A strong team player who works effectively within the ISSO function and
collaborates successfully with colleagues and stakeholders to deliver a high
quality service.
Creative, innovative, and open to new ideas and approaches.
Willing to take on responsibility and work independently with minimal
supervision.
Working Hours/Conditions :
This role requires flexibility in providing cross-regional support. Prepared to
partake on a shifting schedule -- APAC, EMEA and Americas. Occasional public
holidays or weekend support may be required.
Note: This job description is not intended to be all-inclusive.
Employees may perform other related duties to meet the ongoing needs of the organisation.
Your Benefits
Your well-being is of paramount importance to us, and central to our success. We provide a range of benefits, training and education support, and flexible working arrangements to help you achieve success in your career while balancing personal needs. Ask us about specific benefits in your location.
We embrace diversity, prioritizing the hiring of people from diverse backgrounds. Our inclusive culture is a source of pride and strength, fostering innovation and mutual respect.
Citco welcomes and encourages applications from people with disabilities. Accommodations are available upon request for candidates taking part in all aspects of the selection.