About this role
The Technology and Cyber Compliance and Operational Risk Office (TCCORO) at Citi is the firm’s reliable second set of eyes. Our mission is to drive comprehensive and consistent practices designed to identify, measure, monitor, report and manage operational and compliance risks while promoting the implementation of actions to address root causes which may lead to unintended operational losses or regulatory breaches. TCCORO provides the specialist subject matter experts to challenge Enterprise, Infrastructure, Operations and Technology entities across the firm. We are the technology and cyber conscience of the bank. In line with the Operational Risk Management (ORM) and Independent Compliance Risk Management (ICRM) frameworks, we aim to ensure that the internal controls that are designed to mitigate technology, cyber and AI risks are managed, mitigated, and aligned with our risk appetite.
The Tech 2LOD Risk Sr Officer is part of the Finance, Risk and End User Computing Second Line of Defense (2LOD) within TCCORO and provides independent oversight of technology, cyber and AI risk across applications, agentic workflows, digital assistants, end user computing tools, associated processes and control environments The role will leverage technology subject matter expertise, business experience, data analysis techniques, current events, and industry trends and best practices to inform the prioritization of risks and the second-line’s approach for associated challenge and influence activities. This position actively works with our ORM and Compliance partners and other stakeholders to provide subject matter expertise in line with our operational and compliance risk management frameworks. A successful candidate will have expertise in technology, cyber and AI risk in global financial services and be able to demonstrate a comprehensive understanding of the subject matter and how it applies to related risks. They should have a strong track record in technology, cyber and AI risk management and/or a strong technical background with excellent analytical skills. A successful candidate should also demonstrate a strong interest in the field and a passion for risk management.
Responsibilities :
- Assesses technology, cyber, data, and AI risks associated with new initiatives, strategic programs, digital transformation efforts, emerging technologies, cloud implementations, and third-party solutions, providing credible challenge to ensure risks are appropriately identified, assessed, and managed.
- Reviews and evaluates compliance, technology, cybersecurity, data, and AI governance policies, standards, procedures, technologies, tools, and governance processes to assess their design and effectiveness and ensure alignment with regulatory requirements and the firm's risk appetite.
- Leads and partners with stakeholders across Technology, Cyber, Compliance, and Risk Management to conduct risk-based monitoring reviews, independent assessments, control evaluations, and sample-based testing, including the development of workpapers, observations, issues, and executive reporting.
- Challenges the design, adequacy, and effectiveness of technology, cyber, data, and AI controls, recommending actions to address control weaknesses, emerging risks, and the root causes of operational risk events.
- Evaluates Artificial Intelligence (AI), Generative AI (GenAI), Machine Learning (ML), Agentic AI, AI Agents, Digital Assistants, AI-enabled software development, large language models (LLMs), third-party AI services, and emerging AI technologies to assess governance, security, privacy, data management, resiliency, model risk, regulatory compliance, and responsible AI practices.
- Provides independent oversight and challenge of AI agent development, deployment, monitoring, and decision-making frameworks, including autonomous and semi-autonomous workflows, human-in-the-loop controls, agent orchestration, prompt management, and accountability mechanisms.
- Knowledge of emerging technology, cybersecurity, and AI regulatory requirements, industry standards, and supervisory expectations, including technology resilience, cloud computing, cyber defense, secure software development, identity and access management, AI governance, and responsible AI practices.
- Reviews risks associated with program and project delivery and challenges implementation readiness, governance, resiliency, and control effectiveness for technology, cyber, and AI-enabled solutions.
- Monitors and challenges Key Risks, Key Risk Indicators (KRIs), and emerging risk trends, including those related to AI adoption, agent performance, automation, and technology resiliency, and drives timely remediation of identified issues.
- Executes deep-dive reviews, thematic assessments, audit and regulatory support activities, and executive communications, while ensuring compliance with applicable laws, regulations, policies, and ethical standards.
Recommended Qualifications :
- Minimum of 6-10 years experience in technology risk and/or cyber risk management, information security, information technology or related field
- Previous experience supporting risk management, compliance, governance, or controls related roles.
- Demonstrated experience performing independent technology, cyber, data, and operational risk assessments, monitoring reviews, control evaluations, and assurance activities within large, complex financial services or highly regulated environments. Experience developing risk assessments, testing strategies, workpapers, observations, issues, and executive-level reporting.
- Strong understanding of technology, cyber, cloud, data, and AI risk management practices, including governance, risk assessment, control design, control testing, issue management, and remediation validation.
- Knowledge of Artificial Intelligence (AI), Generative AI (GenAI), Machine Learning (ML), AI Agents, Agentic AI, digital assistants, and AI-enabled business processes, including associated risks related to model governance, privacy, security, data management, regulatory compliance, resiliency, explainability, and responsible AI practices.
- Knowledge of products within the coverage area, including an understanding of current and emerging trends as well as the ability to apply understanding of the business impacts of technical contributions.
- Experience in technology and cyber risk assessments, metrics, enterprise technology services, risks, and controls within globally complex, dispersed and diverse organizations.
- In-depth knowledge of technology risks and controls across various information system architecture and engineering domains including: data protection, identity and access management, vulnerability management, network security, endpoint security, logging and monitoring, incident management, and third-party management; preferred expertise in application development, software development lifecycle (SDLC), identity and access management, cloud technologies, enterprise and technology architecture, end-user computing (EUC), technology governance, AI governance, AI-enabled software development, and AI/Agentic AI control frameworks.
- Proficient in industry standard risk management frameworks (including ISO27001, COBIT, TOGAF and CRI for example), and an in-depth understanding of technology and cyber risk mitigation strategies.
- Consistently demonstrates clear and concise written and verbal communication skills
- Developed communication and diplomacy skills are required to guide, influence, and convince others, in particular colleagues in other areas and occasional external customers. Requires good analytical skills to filter, prioritize and validate potentially complex material from multiple sources.
Education :
- Bachelor's/University degree, Master's degree preferred
- Relevant certifications in CISM, CRISC, AAIA, AAIR, CISSP and CISA a plus
------------------------------------------------------
## Job Family Group:
Risk Management
------------------------------------------------------
## Job Family:
Operational Risk
------------------------------------------------------
## Time Type:
Full time
------------------------------------------------------
## Primary Location:
Tampa Florida United States
------------------------------------------------------
## Primary Location Full Time Salary Range:
$113,840.00 - $170,760.00
In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.
------------------------------------------------------
## Most Relevant Skills
Analytical Thinking, Controls Lifecycle, Credible Challenge, Governance, Policy, Procedure, and Regulation, Risk Management Lifecycle.
------------------------------------------------------
## Other Relevant Skills
For complementary skills, please see above and/or contact the recruiter.
------------------------------------------------------
## Anticipated Posting Close Date:
Oct 13, 2026
------------------------------------------------------
Automated Processing and AI
We use automated processing, including artificial intelligence, for our legitimate business interests (or our reasonable and appropriate business purposes) to identify and align the candidate's skills and abilities with a specific job opening. Additionally, if you so choose, or consent, we can match your skills and abilities to other suitable roles at Citi.
Importantly, all our hiring processes and decisions, including determining your suitability for a role, are conducted, checked, and decided by individuals. Our automated processing and AI do not involve relying on automatic or autonomous decision-making. Please refer to any Jurisdictional Considerations, with specific provisions for your country (where relevant) for further details.
Illinois residents – AI Notice and Right
------------------------------------------------------
Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.
If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi .
View Citi’s EEO Policy Statement and the Know Your Rights poster.