CrawlJobs Logo

Senior API Security Vulnerability Analyst

https://www.citi.com/ Logo

Citi

Location Icon

Location:
United States, Fort Lauderdale, Florida

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

117440.00 - 176160.00 USD / Year

Job Description:

Citi is looking for a Senior API Security Vulnerability Analyst to join their team of world class, talented individuals who are passionate about security. The role involves conducting various types of vulnerability assessments on a variety of Citi applications by manually identifying, researching, validating, and exploiting various known and unknown application security vulnerabilities.

Job Responsibility:

  • Act as a subject matter expert in offensive information security performing dynamic and manual security assessments on APIs
  • Drive remediation by outlining a defense-in-depth approach to business stakeholders and providing strategic solutions to developers on effective preventive and detective security controls and counter measures
  • Have strong technical writing and presentation skills to report and articulate the vulnerability assessment results to any audience
  • Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement and automation

Requirements:

  • Master’s Degree with a minimum of 3 years of experience or a Bachelor’s Degree with a minimum of 5 years of experience
  • Background in enterprise software development with expertise in technologies such as: Java/J2EE (Spring, Struts), .NET (ASP.NET, C#, Webflow, MVC, WebAPI), JavaScript Frameworks (NodeJS, AngularJS), Web Applications, REST/SOAP APIs/Web Services, Mobile Applications, Thick Clients, Microservices Architecture based applications running on containers/cloud (GCP, AWS, Azure), or Blockchain and smart contracts implementations
  • Background in penetration testing with expertise in API security testing such as: hands-on ethical hacking using security tools (BurpSuite, AppScan), knowledge of OWASP Top 10 API Security Risks, OWASP Top 10, CWE/SANS Top 25, Threat Modeling, understanding microservice application architecture, design and functionalities
  • Must have or be willing to obtain Industry-accredited security certifications such as: BSCP, GWAPT, GPEN, OSCP, OSWE, CISSP, or other related certifications

Nice to have:

  • Experience in developing custom security scripts for offensive security tooling and/or CI/CD tooling for shifting security testing earlier within the SDLC
  • Working knowledge of API specific security tools such as Traceable and Akamai
  • Experience with hands on security testing tools such as Postman, ReadyAPI, BurpSuite Proxy, AppScan, WebInspect
What we offer:
  • medical, dental & vision coverage
  • 401(k)
  • life, accident, and disability insurance
  • wellness programs
  • paid time off packages including planned time off (vacation), unplanned time off (sick leave), and paid holidays

Additional Information:

Job Posted:
April 30, 2025

Expiration:
May 03, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.