SIGN IN
Senior Offensive Security Malware, Lead Analyst jobs in United States
cer-icon
Apply on Employer Site
company-logo

Citi · 17 hours ago

Senior Offensive Security Malware, Lead Analyst

Citi, the leading global bank, is seeking a Senior Offensive Security Malware Lead Analyst to lead the offensive security program for malware analysis and response. The role focuses on securing the software development lifecycle and conducting penetration testing engagements to protect Citi and its clients from cybersecurity threats.
FinanceBankingFinancial Services
check
H1B Sponsor Likelynote

Responsibilities

Lead the offensive security program for malware analysis and response, focusing on proactively securing the software development lifecycle
Perform manual and dynamic analysis on potential open-source malware within NPM, Python, and other package ecosystems to identify supply chain risks
Act as a subject matter expert in offensive information security, performing manual security assessments on web technologies, including APIs, JavaScript Frameworks, and Artificial Intelligence systems
Conduct and facilitate security reviews, penetration testing engagements, and table-top/red-team/scenario analysis exercises
Drive remediation efforts by outlining defense-in-depth strategies and providing strategic solutions to developers on effective security controls
Evaluate, recommend, and assist in the selection of new and emerging external products, applications, and technologies with a focus on their security implications
Work closely with internal Applications Development to enhance both architecture and application security
Identify opportunities for enhancements to security standards, tools, and processes, and contribute to the review of internal activities for potential improvement and automation
Define secure configurations for network, database, server, and desktop technologies in alignment with security policies
Develop strong technical documentation and deliver clear presentations to articulate vulnerability assessment results to both technical and non-technical audiences
Assess risk during business decisions, ensuring compliance with applicable laws, rules, and regulations while safeguarding the firm's assets and reputation

Qualification

Malware analysisApplication penetration testingSecurity testing toolsIndustry-accredited certificationsArtificial IntelligenceAnalytical skillsProblem-solving skillsCommunication skillsTeamwork

Required

Bachelor's Degree with a minimum of 10 years' relevant experience, or a Master's Degree with a minimum 5 years' experience in Malware analysis and/or application penetration testing
Proven background in penetration testing and expertise in the risks associated with software supply chains and dependency trees
Hands-on experience with security testing tools such as BurpSuite Proxy, Postman, AppScan, WebInspect, and similar technologies
Must have or be willing to obtain industry-accredited security certifications such as OSCP, OSWE, CISSP, GWAPT, GPEN, or other related credentials
Advanced analytical and problem-solving skills with a demonstrated ability to take ownership and follow up on issues
Proficient in interpreting and applying policies, standards, and procedures
Excellent written and verbal communication skills
Demonstrated ability to work effectively in a team environment and perform well under pressure

Preferred

Experience leveraging Artificial Intelligence to enhance offensive security processes is highly desirable

Benefits

Medical, dental & vision coverage
401(k)
Life, accident, and disability insurance
Wellness programs
Paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays

Company

Citi's mission is to serve as a trusted partner to our clients by responsibly providing financial services that enable growth and economic progress.

H1B Sponsorship

Citi has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (1386)
2024 (849)
2023 (1375)
2022 (1117)
2021 (876)
2020 (901)

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
James Monahan
Managing Director / Global Head of Asset Servicing
linkedin
leader-logo
Naveed Sultan
Managing Director, Chairman, Institutional Clients Group
linkedin
Company data provided by crunchbase