Salary
💰 $113,840 - $170,760 per year
About the role
- Drive efforts to prevent, monitor and respond to information/data breaches and cyber-attacks
- Ensure execution of Information Security directives and activities in alignment with Citi's data security policy
- Identify opportunities to automate and standardize information security controls
- Resolve vulnerabilities or issues detected in applications or infrastructure
- Analyze source code to mitigate identified weaknesses and vulnerabilities
- Review and validate automated testing results and prioritize remediation based on risk
- Scan and analyze applications with automated tools and perform manual testing when necessary
- Reduce risk by analyzing root causes, impacts, and corrective actions
- Direct development and delivery of secure solutions by coordinating with business and technical contacts
- Assess risk for business decisions, drive compliance with laws, rules and regulations, and escalate/report control issues
- Lead and drive Fraud Red Team strategy, oversee prioritization of portfolios to test, and align testing launches with cross-functional teams
- Lead red team analyst and blue team mitigation efforts, test controls, provide mitigation recommendations, and lead debriefings
Requirements
- 6-10 years of relevant experience
- Advanced proficiency with Microsoft Office tools and software
- Consistently demonstrates clear and concise written and verbal communication
- Proven influencing and relationship management skills
- Proven analytical skills
- Bachelor’s degree/University degree or equivalent experience
- Master’s degree preferred
- Experience identifying opportunities to automate and standardize information security controls
- Experience resolving vulnerabilities in applications and infrastructure
- Ability to analyze source code to mitigate weaknesses and vulnerabilities
- Experience reviewing and validating automated testing results and prioritizing risk-based actions
- Experience scanning and analyzing applications with automated tools and performing manual testing
- Experience conducting vulnerability testing of technology and endpoints
- Experience leading red team and coordinating with blue team (mitigation) efforts
- Experience testing controls for fraud detection and prevention systems
- Experience providing mitigation recommendations and leading debriefs
- Ability to collaborate with cross-functional partners to ensure mitigation of detected vulnerabilities