CrawlJobs Logo

Red Team Operation Analyst

https://www.citi.com/ Logo

Citi

Location Icon

Location:
United States, Fort Lauderdale

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

The Offensive Security & Vulnerability Management Analyst - Red Team, AVP will participate in the Adversary Emulation program by emulating cyber and criminal threat actors targeting Citi. The candidate will conduct Intelligence-led Red Team Testing and Penetration Testing targeting people, process, and technology. The candidate may also conduct regulatory driven Red Team Testing. The role involves analyzing security vulnerabilities and crafting solutions, leveraging industry frameworks, tools, and practices.

Job Responsibility:

  • Support Citi’s Red, Blue, and Purple Teams during the execution of offensive security assessment operations
  • Participate in advanced exploitation operations against a large global enterprise, including Red and Purple Team operations
  • Identify opportunities to automate and standardize information security controls and for the supported groups
  • Resolve any vulnerabilities or issues detected in an application or infrastructure
  • Analyze source code to mitigate identified weaknesses and vulnerabilities within the system
  • Review and validate automated testing results and prioritize actions that resolve issues based on overall risk
  • Scan and analyze applications with automated tools, and perform manual testing if necessary
  • Reduce risk by analyzing the root cause of issues, their impact, and required corrective actions
  • Assist the development and delivery of secure solutions by coordinating with business and technical contacts
  • Leveraging the MITRE ATT&CK Framework
  • Helping with Vulnerability Assessments and Penetration Testing (application and/or infrastructure) and articulating security issues to technical and non-technical audience
  • Proficiencies with Social Engineering Campaigns - phishing , vishing, smishing etc
  • Understanding with OS Security : Unix/Linux, Windows, OSX
  • Assist in assessing risk when making business decisions
  • Demonstrate consideration for the firm's reputation and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency.

Requirements:

  • 2+ years’ experience or equivalent knowledge and exposure with Network Penetration Testing Or Infrastructure pen testing
  • Familiarity with industry Adversary Emulation Frameworks like PTES, CBEST, iCAST, GFMA
  • Understanding of the OSI model
  • Knowledge of tools and processes used to expose known and undocumented vulnerabilities in various systems
  • Familiarity with Red Team testing tools: Cobalt Strike, Red Team Toolkit
  • Familiarity with Vulnerability Assessment tools: Nessus, Qualys, etc.
  • Familiarity with Exploitation frameworks: Metasploit, CANVAS, Core Impact
  • Familiarity with OS Security: Unix/Linux
  • Understanding of common protocols: HTTP, LDAP, SMTP, DNS
  • Some Web development and programming experience: Python, Perl, Ruby, Java, .Net ETC.

Nice to have:

Industry-accredited security certifications highly preferred but not required (e.g. PNPT, OSCP, OSCE, GXPN, GPEN, GCIH, GWAPT, GCFA, or CISSP).

What we offer:
  • Medical, dental & vision coverage
  • 401(k)
  • life, accident, and disability insurance
  • wellness programs
  • paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays.

Additional Information:

Job Posted:
August 21, 2025

Expiration:
August 27, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.