Information Security – Vulnerability Assessment Senior Analyst (AVP)
• Assist Security Incident Response Teams with incident investigations and aid in technical risk assessments
• Coordinate with system development and infrastructure units to identify Information Security (IS) risks and the appropriate controls for development, day-to-day operation, and emerging technologies
• Perform regular assessments based on changes in the threat landscape
• Monitor vulnerability assessments and ethical hacks, ensuring that issues are addressed for the applications that they support
• Provide information security support with related activities during systems development (e.g. authentication, encryption)
• Identify and develop new and improved technical procedures and process control manuals
• Identify significant IS threats and vulnerabilities
• Assume informal/formal mentorship role within teams and assist with the coaching and training of new team members
• Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency.
• Review and analyzing SAST and SCA results for applications within Citi.
• Support of scanning tools in integration with CI/CD pipelines.
• Analysis of Security Vulnerabilities related to Open Source Libraries Qualifications :
• 2-5 years of relevant experience
• Consistently demonstrates clear and concise written and verbal communication
• Proven influencing and relationship management skills
• Proven analytical skills Education :
• Bachelor's degree/University degree or equivalent experience
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required. Job Family Group:
Technology Job Family:
Information Security Time Type:
Citi is an equal opportunity and affirmative action employer.
Qualified applicants will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Citigroup Inc. and its subsidiaries ("Citi") invite all qualified interested applicants to apply for career opportunities. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi
View the " EEO is the Law
" poster. View the EEO is the Law Supplement
View the EEO Policy Statement
View the Pay Transparency Posting