
Head of Data Risk Appetite Oversight and Analysis, Director
- Getzville, NY
- Permanent
- Full-time
- Operating model, staffing, and culture
- Operational risk appetite
- Control objectives and standards
- Operational risk and control assessments and reporting
- Strategic decision-making
- The effective execution of Citi's Enterprise Data transformation
- Lead primary oversight of the firm’s Data Risk Appetite, including assessment of factors of risk, assessing and monitoring path-to-green efforts, management of metrics that measure risk, and all associated analysis.
- Work with 1LOD to define clear path-to-green and drive execution of agreed plans.
- Be accountable for identifying and executing independent second-line risk assessments in coordination with other ORM teams where needed (e.g., leading challenges of specific risk appetite metrics) to meet internal commitments, leveraging the hub-and-spoke model.
- Champion internal knowledge sharing for Data Risk Appetite efforts. Ensure that this multidisciplinary and cross-cutting risk area is well understood and that the implications of firm-wide remediation efforts are understood in terms of path-to-green efforts.
- Negotiate and remediate resulting risk and control concerns identified.
- Escalate significant or unaddressed risk issues and control environment concerns to appropriate governance forums and Risk leadership.
- As needed, serve as the primary interface to key stakeholders such as regulators, senior management, and the Board, as it relates to 2LOD assessment/point of view for the Risk Category.
- Broad experience in risk management, including a successful track record of managing large, complex, enterprise-wide risk management programs at a large financial services organization.
- Focused experience in assessing risk appetite for non-financial risks aligned with regulatory expectations. Proficient in risk assessment principles and supervisory expectations in terms of the quantity and quality of operational risk management.
- Subject matter expertise in Non-Financial Risk Management with a proven track record in risk and control related to technology, data, and/or reporting risk.
- Track record of managing internal relationships and partnering with a range of stakeholders (e.g., business, functions) in leading sustained change and change management efforts.
- Strong technical problem-solving skills and an ability to identify conflicts, discrepancies, and other issues, and bring together the right team to solve them.
- Well-developed listening skills and a strong ability to communicate and engage at the senior management level, both orally and in writing.
- Ability to constructively challenge others at all levels and across boundaries to deliver better results.
- Continuous improvement mind-set to solve for root causes, assess the impact of actions, and adjust as needed; simplify and standardize at every opportunity.
- Regulatory engagement experience.
- 10+ years of direct experience as a senior Non-Financial Risk professional (data, technology, or reporting risk) or relevant 1LOD function in a large financial services organization.
- 8-10+ years' managerial experience
- Extensive experience with risk metrics, including providing oversight of design, delivery, and sustainability.
- Well-versed in executing risk management monitoring routines, tracking identification to resolution.
- Extensive experience applying operational risk management frameworks in a global organization.
- Strong track record in leading teams to deliver technical risk and control assessments and negotiate outcomes at scale.
- Demonstrable understanding of Data fundamentals, including Data architecture, Data principles, and a deep appreciation of intersectionality and interdependency with enterprise Technology and systems architecture.
- Deep knowledge of financial and risk data, along with an understanding of regulatory, compliance, risk management, and financial management concerns.
- Subject matter expertise in operational risk management as applied to Data risk.
- Bachelor's degree in Computer Science, Data Science, Information Technology, Business, or a related field.
- Master's degree preferred