This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Head of Cybersecurity Technology & AI Security Engineering is an executive level position responsible for delivering technology solutions in support of Citi’s core cybersecurity teams, including the critical cybersecurity operations organization. This includes overseeing architecture, product management, engineering and technology operations for the tools and products that help deliver our core cybersecurity capabilities. In addition, the role leads the AI security engineering capability to leverage AI to transform the way cybersecurity capabilities and services are delivered and to empower an AI led cyber workforce.
Job Responsibility:
Build, mentor and inspire a high performing cybersecurity team, growing both the current and the next generation of leadership talent
Lay out a clear vision for Cybersecurity Technology in partnership with the leaders of Cyber Security Operations, BFT-CISO, and Cyber Risk and Controls
Lead significant initiatives within and help deliver the CISO and BFT cyber strategies, and securely enable business and technology activities and programs
Work with the assigned Enterprise Security Architects, vendors and engineers to develop and document an effective architecture that aligns with Citi’s architecture principles and overall Enterprise Architecture
Lead a product mgmt. function that engages stakeholders to prioritize features and capabilities in the Cybersecurity Technology roadmap, delivering value and user experience
Build an AI capability that maintains an “agent first” mindset to solve security problems
Manage the budget, resource planning, and delivery of end results through executing the functional strategy
Leverage the team to rapidly respond to emerging threats, security incidents and critical business activities
Lead and securely enable significant business change in complex global environments, managing complex multiple risk dimensions
Partner with peer leadership to drive cyber strategy and unify global processes and functions
Implement an effective problem management process to identify recurring issues or potential upcoming issues to assure the long-term effectiveness of the environment
Maintain a responsible compliance program
Requirements:
15+ years of relevant experience in an Engineering role in the cybersecurity, digital or AI fields
Experience working in Financial Services or Technology or a large complex and/or global environment
Comprehensive knowledge of design metrics, analytics tools, benchmarking activities and related reporting to identify best practices
Proven track record of building and running resilient service driven technology capabilities
Demonstrated use of driving AI delivery and engineering to transform capabilities and services to deliver value to customers and stakeholders
Proven ability to engage and influence senior stakeholders across business, risk, technology, and governance functions in a banking context
Demonstrated success in building, leading, and scaling global cybersecurity teams
Nice to have:
Deep, demonstrable experience leading security engineering and operations at scale — not just policy and governance
A track record of building and mentoring high-performing, diverse security teams
Hands-on fluency across cloud-native architectures (Kubernetes, Terraform, service mesh), modern CI/CD, and infrastructure-as-code
A sharp understanding of the AI threat landscape, including risks specific to generative AI and large language models
Experience operating or transforming a SOC — with a bias toward automation, detection engineering, and measurable outcomes
Strong DFIR fundamentals and the ability to lead under pressure during major incidents
Active engagement with the open-source security community — whether as a contributor, maintainer, or power user of projects like Sigma, Velociraptor, Falco, MISP, Semgrep, or similar
The ability to communicate risk to boards and business leaders without reliance on jargon or frameworks
What we offer:
medical, dental & vision coverage
401(k)
life, accident, and disability insurance
wellness programs
paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays