CrawlJobs Logo

AppSec Source Code Analyst

https://www.citi.com/ Logo

Citi

Location Icon

Location:
United States, Irving

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

125760.00 - 188640.00 USD / Year

Job Description:

The AppSec Source Code Analyst, VP position is a part of the CISO organization and provide application security services to Citi businesses in Software Development Life Cycle (SDLC). Candidates perform deep-dive source code review for the development organizations and collaborate with teams to ensure proper remediation.

Job Responsibility:

  • Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)
  • Review and validate automated testing results and prioritize actions that resolve issues based on overall risk
  • Perform application binary analysis when source code is not available
  • Identify opportunities to automate, develop custom rules and standardize information security controls
  • Participate in conference calls with engineering team to ensure proper scan coverage and effective results
  • Write formal security assessment report for each application, using our company's standard reporting format
  • Direct the development and delivery of secure solutions by coordinating with business and technical teams
  • Collaborate with application teams to ensure that any identified security vulnerabilities are remediated in a timely manner
  • Manage and execute security assessments for multiple projects simultaneously and ensure project timelines are met
  • Research and explore new testing tools and methodologies
  • Act as a mentor to the junior team members
  • Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency

Requirements:

  • At least 6+ years of relevant experience in web development, source code review, or application security testing
  • Basic understanding of application security and associated vulnerabilities
  • Development background in Java/J2EE, C#, .NET in an enterprise environment
  • Good understanding of the DevSecOps, Pipeline, Software Development Life Cycle – including unit testing, code scanning
  • Experience using commercial enterprise automated security testing tools such as Burp, Fortify, Checkmarx, Blackduck, Snyk
  • Professional certifications, such as CISSP, CSSLP, GIAC, CEH or willingness to obtain
  • At least Bachelor’s degree/University degree or equivalent experience

Nice to have:

DAST, DevSecOps, .NET code reviews, Burp, Fortify, Snyk

What we offer:
  • medical, dental & vision coverage
  • 401(k)
  • life, accident, and disability insurance
  • wellness programs
  • paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays

Additional Information:

Job Posted:
April 23, 2025

Expiration:
July 31, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.