採用

Senior Offensive Security Malware, Lead Analyst
FORT LAUDERDALE, Florida, United States of America
·
On-site
·
Full-time
·
3w ago
About Citi:
Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.
As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients’ best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first-class customer experience. We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services.
Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We’ll enable growth and progress together.
The Team:
Are you interested in growing your career in Offensive Cyber Security?
Our team of world class, talented individuals, who are passionate about security, put their skills to the test every day on a global scale. At Citi, you will be exposed to all sorts of technologies on an enterprise-scale, so hunger for knowledge and research is greatly appreciated and rewarded.
Technology is constantly evolving, and Citi is evolving with it by adopting the latest application frameworks, migrating to cloud-based technologies, and implementing Artificial Intelligence in numerous workflows across the enterprise. Citi’s Offensive security team is at the forefront of testing and securing each of these solutions and you can make an impact on the next technology to be released.
The Role:
The Senior Offensive Security Malware Lead Analyst is a senior-level role centered on proactive and offensive cybersecurity that will lead the offensive security program for malware analysis and response. Additionally, the position will serve the broader application penetration testing domain which includes performing penetration testing engagements as well as overseeing external partner engagements to ensure that operational processes are adhered to. The primary goal is to secure Citi, its customers, and clients by proactively reviewing supply chain risks through the research, identification, validation, and exploitation of ingested malware within the software development lifecycle.
The position involves leading efforts to secure the software supply chain by analyzing open-source packages and conducting advanced security assessments on a variety of web technologies.
The ideal candidate will have deep expertise in malware analysis and application penetration testing. This is a hands-on technical role that requires a strategic mindset to drive remediation and enhance the organization's overall security posture in a dynamic, enterprise-scale environment.
Responsibilities
- Lead the offensive security program for malware analysis and response, focusing on proactively securing the software development lifecycle.
- Perform manual and dynamic analysis on potential open-source malware within NPM, Python, and other package ecosystems to identify supply chain risks.
- Act as a subject matter expert in offensive information security, performing manual security assessments on web technologies, including APIs, JavaScript Frameworks, and Artificial Intelligence systems.
- Conduct and facilitate security reviews, penetration testing engagements, and table-top/red-team/scenario analysis exercises.
- Drive remediation efforts by outlining defense-in-depth strategies and providing strategic solutions to developers on effective security controls.
- Evaluate, recommend, and assist in the selection of new and emerging external products, applications, and technologies with a focus on their security implications.
- Work closely with internal Applications Development to enhance both architecture and application security.
- Identify opportunities for enhancements to security standards, tools, and processes, and contribute to the review of internal activities for potential improvement and automation.
- Define secure configurations for network, database, server, and desktop technologies in alignment with security policies.
- Develop strong technical documentation and deliver clear presentations to articulate vulnerability assessment results to both technical and non-technical audiences.
- Assess risk during business decisions, ensuring compliance with applicable laws, rules, and regulations while safeguarding the firm's assets and reputation.
Qualifications
- Bachelor’s Degree with a minimum of 10 years' relevant experience, or a Master’s Degree with a minimum 5 years' experience in Malware analysis and/or application penetration testing
- Proven background in penetration testing and expertise in the risks associated with software supply chains and dependency trees.
- Hands-on experience with security testing tools such as BurpSuite Proxy, Postman, AppScan, WebInspect, and similar technologies.
- Must have or be willing to obtain industry-accredited security certifications such as OSCP, OSWE, CISSP, GWAPT, GPEN, or other related credentials.
- Experience leveraging Artificial Intelligence to enhance offensive security processes is highly desirable.
- Advanced analytical and problem-solving skills with a demonstrated ability to take ownership and follow up on issues.
- Proficient in interpreting and applying policies, standards, and procedures.
- Excellent written and verbal communication skills.
- Demonstrated ability to work effectively in a team environment and perform well under pressure.
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
------------------------------------------------------
Job Family Group:
Technology------------------------------------------------------
Job Family:
Information Security------------------------------------------------------
Time Type:
Full time------------------------------------------------------
Primary Location:
Fort Lauderdale Florida United States------------------------------------------------------
Primary Location Full Time Salary Range:
$145,840.00 - $218,760.00
In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.
------------------------------------------------------
Most Relevant Skills
Please see the requirements listed above.------------------------------------------------------
Other Relevant Skills
For complementary skills, please see above and/or contact the recruiter.------------------------------------------------------
Anticipated Posting Close Date:
Feb 19, 2026------------------------------------------------------
Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.
If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.
View Citi’s EEO Policy Statement and the Know Your Rights poster.
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

Manager Financial Crimes Data Analytics and Reporting
American Express · New York, New York, United States

Manager, Technical Account Management
PayPal · Chicago, Illinois, United States of America; Scottsdale, Arizona, United States of America; San Jose, California, United States of America

Channel Business Manager, IBM North America Alliance Topeka, KS 01/29/2026
Palo Alto Networks · topeka

Commodity Strats, Manager / Senior Manager, Fixed Income Division
Morgan Stanley · Mumbai, Maharashtra, India

Senior Manager-Global Payment Network Pricing Strategy
American Express · New York, New York, United States
About Citigroup

Citigroup
PublicCitigroup Inc. or Citi is an American multinational investment bank and financial services company based in New York City. The company was formed in 1998 by the merger of Citicorp, the bank holding company for Citibank, and Travelers; Travelers was spun off from the company in 2002.
10,001+
Employees
New York City
Headquarters
Reviews
3.3
4 reviews
Work Life Balance
3.0
Compensation
3.2
Culture
2.8
Career
2.5
Management
2.7
35%
Recommend to a Friend
Pros
Compensation increases for investment banking roles
Legitimate investment banking employer
Internship opportunities available
Cons
Unclear career progression paths
Limited meaningful experience in internships
Compensation raises lower than competitors
Salary Ranges
28 data points
Senior/L5
Senior/L5 · Cash & Trade Processing Senior Group Manager
2 reports
$224,732
total / year
Base
$195,245
Stock
-
Bonus
-
$218,500
$230,564
Interview Experience
5 interviews
Difficulty
2.8
/ 5
Duration
14-28 weeks
Experience
Positive 0%
Neutral 40%
Negative 60%
Interview Process
1
Application Review
2
Recruiter Screen
3
Programming Assessment
4
Hiring Manager Interview
5
Panel/Superday Interviews
6
Final Decision
Common Questions
Technical Knowledge
Case Study
Behavioral/STAR
Past Experience
Culture Fit
News & Buzz
National Pension Service Raises Stake in Citigroup Inc. $C - MarketBeat
Source: MarketBeat
News
·
4w ago
Form 424B2 CITIGROUP INC - StreetInsider
Source: StreetInsider
News
·
5w ago
Citigroup or Wells Fargo: Which Bank Stock Has More Upside in 2026? - TradingView
Source: TradingView
News
·
5w ago
Citigroup Inc. (C) is Attracting Investor Attention: Here is What You Should Know - Yahoo Finance
Source: Yahoo Finance
News
·
5w ago