Legal Support Officer - Third Party Management- Assistant Vice President
Citigroup
- Location
- Mumbai Maharashtra India
- Work model
- On-Site
- Level
- Staff
- Posted
- 21h ago
About this role
The Global Legal Solutions team within Citi Legal plays a pivotal role in supporting Citi's legal professionals by ensuring robust risk management and operational excellence. This role, as a Third-Party Management (TPM) Analyst, is central to safeguarding sensitive information and maintaining the integrity of Citi's legal operations when engaging with external partners The Global Legal Solutions (GLS) Third Party Management (TPM) Analyst role is an intermediate level, non-attorney role responsible for managing, monitoring and minimizing operational risk vulnerabilities by effectively overseeing third party management controls. The team is responsible to ensure monitoring mechanisms are effective, and possess efficient balance enterprise risk with business growth for legal external third parties as well as relationships between Citi legal entities and their internal affiliates. On a day-to-day basis, the TPM Analyst will be responsible for executing and supporting information security controls assessments for external law firms that fall within Citi's Legal Risk Profile and Citi Legal Technology vendors. This involves a critical assessment of these firms' information security posture to identify, evaluate, and mitigate potential risks to Citi's confidential data and systems. A key aspect of this position is the strong collaborative partnership with various programs within Citi's Chief Information Security Office (CISO). The TPM Analyst will act as a crucial liaison, working closely with CISO stakeholders to align third-party security practices with Citi's overarching information security policies and standards. This collaboration is essential to ensure comprehensive and effective risk management for Citi Legal, protecting the firm against evolving cyber threats and regulatory challenges. This position requires a proactive individual with a keen understanding of information security principles, risk management frameworks, and the ability to foster strong inter-departmental relationships. The TPM Analyst will contribute directly to maintaining Citi's reputation for security and compliance in its legal engagements Responsibilities Contribute to a global strategy, process and governance framework for all aspects of law firm risk oversight. Legal Third Party Management (TPM) - Working both individually and with other Citi teams to deliver on corporate wide TPM initiatives Responsible for all TPM related activities for legal suppliers within Citi (Supplier Onboarding, Ongoing Monitoring and Supplier Off-boarding) Drive and support a best in class Regional Legal TPM Infrastructure and respectively coordinate with Country Counsel and local attorneys in addressing inquiries as it relates to policy applicability Perform periodic reviews of law firm relationships to maintain accurate record of the vendor relationship (classification of data shared, use of 4th parties, changes in data storage location) Collaborate with legal BISO to address non-compliant findings resulting from Citi’s risk assessments of Legal vendors (TPISA, VA, CART, Cyber) Work with the applicable vendor / third party to mitigate and remediate identified gaps/issues (IS policies, cyber security, assess controls, etc.) Support the Legal BAO (Business Activity Owner) in preparing written assessments highlighting misalignments between the vendor’s processes/policies and those of Citi while effectively describing areas of potential risk. Drive Cross Border Data Clearance (CBDC) initiatives for Citi Legal projects requiring data store and access Drive of the Intra-Citi Service Agreement (ICSA) /Non-Cash Inter-affiliate Agreement (NCIA) end-to-end process for legal services provide to various Citi businesses Provide business unit management support for law firm third party risk issues Contribute to team efforts that evaluate and identify the operating models that offer the best view of risks and key drivers for achieving strategic objectives Provide standardized