This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Citi, a leading global bank with approximately 200 million customer accounts in over 160 countries, provides a broad range of financial products and services to consumers, corporations, governments, and institutions. The bank's Enterprise Operations & Technology division underpins these offerings, delivering secure, reliable, and efficient technology solutions that are foundational to managing global resources, ensuring safety, and providing a first-class customer experience. This reflects Citi's mission to create economic value that is systemically responsible and in its clients' best interests. Fostering a culture of diversity and inclusion, Citi is committed to a workforce that represents the clients it serves. The company values respect, promotes individuals based on merit, and ensures opportunities for personal development are widely available. Ideal candidates are passionate, innovative problem-solvers who contribute to a culture of delivering results with pride and are empowered to enable growth and progress together with the firm. The Information Security SeniorAnalyst on Citi's Social Engineering Attack Response team supports Email Security and Brand Protection functions as an intermediate-level cyber analyst responsible for supporting efforts to prevent, monitor, and respond to social engineering threats. This role is pivotal in protecting the firm, its clients, and its assets from brand and email-related threats. The Senior Analyst will provide operational support, intelligence gathering, analysis, report development, and project management for the firm's email security and brand protection functions. The position requires substantial collaboration with other members of the team and across various Cyber and Information Security teams to ensure that appropriate security solutions are enhanced, implemented, and triaged effectively.
Job Responsibility
Actively monitor and research cyber threats, including phishing, that have a direct or indirect impact or threat on Citi, its workforce, or the Citi brand
Monitor a wide range of digital channels, including e-commerce platforms, social media, and app stores, for brand abuse
Develop and manage processes to track identified incidents to resolution
Initiate and manage takedown requests on various platforms for phishing sites and brand impersonation cases
Analyze email threats and manage associated controls
Identify automation opportunities for repetitive triage, enrichment, and documentation tasks
Use approved AI/LLM tools to assist with alert summarization, IOC extraction, and case narrative drafting while critically validating all outputs for accuracy, bias, and trustworthiness prior to operational use
Develop and manage weekly, monthly, quarterly, and annual metrics and reports on brand protection activities, trends
Triage information received from vendors and process it through defined internal workflows
Actively engage in liaison activities with internal stakeholders, intelligence communities, industry associations, and peer institutions
Keep up to date with the ever-changing cybersecurity landscape to remain relevant and knowledgeable
Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citigroup, its clients, and assets
Requirements
3+ years of experience in Information Technology, Cybersecurity, brand protection, or fraud prevention
Demonstrated experience with the tools and resources available to conduct email and threat analysis
Strong technical and analytical expertise
Cross-functional understanding of email operations, security practices, and user experience
Familiarity with OSINT (Open Source Intelligence) techniques
Demonstrated ability to use approved AI/LLM tools responsibly, including prompt development, critical output validation, and documentation of analyst review in alignment with acceptable-use and governance requirements
Excellent written and verbal communication and presentation skills
Strong analytical, investigative, and problem-solving skills
Ability to organize and prioritize multiple ongoing tasks via efficient time management
Ability to work independently as well as in a team to achieve desired results
Developed communication and diplomacy skills to guide and influence decision-makers
Bachelor's degree or equivalent work experience is preferred
A degree in Cybersecurity, IT, or a related field is a plus
Cyber Certifications are desired, though optional (e.g., CISSP, GSEC, CISA, Security+)
Nice to have
Project management skills are a plus
A degree in Cybersecurity, IT, or a related field is a plus