採用
This is a senior level professional position responsible for serving as a liaison between Citi Stakeholders and External Penetration Testing vendors to address testing challenges, drive vulnerability discussions with Citi Stakeholders, drive operational health of the penetration testing vendors along with their adherence to Citi procedures, analyze vulnerability trends to better improve the root cause model of existing testing mechanisms and maintain the overall security hygiene for the organization. This role will also require the candidate to manage the end-to-end Vulnerability Disclosure Process for Citi that would involve onboarding applications with vendors, triaging and driving lessons learned as part of the public disclosure and Private Bug Bounty program. The overall objective of this role is to ensure the execution of Information Security directives and activities is in alignment with Citi's data security policy.
Responsibilities:
Be the central liaison between Citi stakeholders and the external penetration testing vendor, acting as a collaborator to ensure smooth execution of the end-to-end engagement.
Manage the end-to-end process of Vulnerability Disclosure activities that involves onboarding applications, triaging, retesting and identifying lessons learned from the vulnerabilities reported through this channel.
Knowledge of OWASP Top 10 and SANS top 25
Perform Yearly Quality Checks on the vendors to ensure adherence to technical and process quality.
Act as an application security subject matter expert to assist both Citi stakeholders and third-party vendors during vulnerability risk discussions.
Focus and drive quality as it relates to the information submitted by the businesses who are requesting Penetration testing services and ensuring that the provided information is accurate and complete.
Focus on maintaining a high level of operational oversight with all vendors and ongoing penetration testing activities in order to ensure that engagements are progressing forward with the right level of attention.
Have strong communication skills in order to effectively communicate expectations and resolve challenges.
Have strong technical writing and presentation skills to articulate the penetration testing process end-to-end to any audience.
Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement and automation.
Reduce risk by analyzing the root cause of issues, their impact, and required corrective actions to existing processes.
Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citibank, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency.
Qualifications:
Minimum of 5 years of relevant experience in Information Security and/or relevant Technology role.
Advanced proficiency with Microsoft Office tools and software
Consistently demonstrates clear and concise written and verbal communication
Proven influencing and relationship management skills
Proven analytical skills
Plus:
Familiarity or hands-on experience in application security testing
Basic understanding of Web/ Mobile / API security and relevant testing tools
Relevant Certifications is a plus not a requirement: GPEN, GWAPT, GMOB, GWEB
Education:
Bachelor’s degree/University degree or equivalent experience
Master’s degree preferred
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
#LI-Hybrid
------------------------------------------------------
Job Family Group:
Technology------------------------------------------------------
Job Family:
Information Security------------------------------------------------------
Time Type:
Full time------------------------------------------------------
Most Relevant Skills
Please see the requirements listed above.------------------------------------------------------
Other Relevant Skills
For complementary skills, please see above and/or contact the recruiter.------------------------------------------------------
Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.
If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.
View Citi’s EEO Policy Statement and the Know Your Rights poster.
総閲覧数
1
応募クリック数
0
模擬応募者数
0
スクラップ
0
類似の求人

Lead Security Engineer
JPMorgan Chase · Singapore, SG

DE Software & Cybersecurity Lead, East Asia
Schneider Electric · Singapore

Manager - Information Security
Hulu (Disney) · Singapore, Singapore

Manager - Information Security
ESPN (Disney) · singapore

Cloud Security Architect, Lead
Booz Allen Hamilton · Singapore
Citigroupについて

Citigroup
PublicCitigroup Inc. or Citi is an American multinational investment bank and financial services company based in New York City. The company was formed in 1998 by the merger of Citicorp, the bank holding company for Citibank, and Travelers; Travelers was spun off from the company in 2002.
10,001+
従業員数
New York City
本社所在地
$86B
企業価値
レビュー
3.7
10件のレビュー
ワークライフバランス
4.0
報酬
2.8
企業文化
4.2
キャリア
3.5
経営陣
3.3
68%
友人に勧める
良い点
Good work-life balance
Supportive management and colleagues
Good benefits
改善点
Low/uncompetitive salary and pay
Poor management and lack of direction
Heavy workload and long hours
給与レンジ
38件のデータ
Mid/L4
Senior/L5
Staff/L6
Mid/L4 · Business Risk Intermediate Analyst
1件のレポート
$77,165
年収総額
基本給
$67,100
ストック
-
ボーナス
-
$77,165
$77,165
面接体験
3件の面接
難易度
3.3
/ 5
期間
14-28週間
体験
ポジティブ 0%
普通 33%
ネガティブ 67%
面接プロセス
1
Application Review
2
HR Screen
3
Technical Assessment
4
Hiring Manager Interview
5
Final Round Interview
6
Offer Decision
よくある質問
Technical Knowledge
Behavioral/STAR
Past Experience
Problem Solving
Culture Fit
ニュース&話題
Citigroup Tokenized Stock (Ondo): Latest News, Social Media Updates and Insights - CryptoRank
CryptoRank
News
·
3d ago
Citigroup Inc. $C Stock Position Raised by Merit Financial Group LLC - MarketBeat
MarketBeat
News
·
3d ago
Top Citigroup Insiders Quietly Cash Out Millions in Stock Sales - TipRanks
TipRanks
News
·
3d ago
Citigroup (C) Valuation Check After Strong Q1 Earnings Beat And Decade High Quarterly Revenue - Yahoo Finance
Yahoo Finance
News
·
4d ago