Estimated team size800–1500 peopleModerate confidence
The CISO reports to the Chief Information Officer, who sits on the Executive Committee. The security organization is centralized but aligned with global business units.
Major functions
Cybersecurity Operations and Incident ResponseIdentity and Access Management (IAM)Cyber Governance, Risk and Compliance (GRC)Application and Product SecurityCloud Security EngineeringFraud and Security Analytics
Maturity indicators
- Public bug bounty program (HackerOne)
- Dedicated Cyber Defense Center (CDC)
- ISO/IEC 27001 certification for specific business units
- Active participation in FS-ISAC
Highly mature organization operating under strict banking regulations (OCC, Federal Reserve) and PCI-DSS compliance requirements. Known for a strong emphasis on identity-centric security.
Organization figures are CLI estimates, not disclosures. High confidence