CrawlJobs Logo

Senior Application Security Analyst

https://www.citi.com/ Logo

Citi

Location Icon

Location:
United States, Irving

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Employment contract

Salary Icon

Salary:

125760.00 - 188640.00 USD / Year

Job Description:

The Senior Application Security Analyst, VP position is part of CISO organization and provide application security services to Citi businesses in Software Development Life Cycle (SDLC). Candidates perform deep-dive source code review for the development organizations and collaborate with teams to ensure proper remediation.

Job Responsibility:

  • Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)
  • Conduct in-depth manual source code reviews to identify vulnerabilities
  • Review and validate automated testing results and prioritize actions that resolve issues based on overall risk
  • Identify opportunities to automate, develop custom rules and standardize information security controls
  • Design, develop, and implement AI/ML-driven utilities and models to enhance source code analysis
  • Write formal security assessment report for each application
  • Direct the development and delivery of secure solutions by coordinating with business and technical teams
  • Manage and execute security assessments for multiple projects simultaneously
  • Research and explore new testing tools and methodologies
  • Act as a mentor to the junior team members

Requirements:

  • At least 6+ years of relevant experience in web development, source code review, or application security testing
  • Deep understanding and proven expertise in application security principles, common vulnerabilities (e.g., OWASP Top 10, CWE), and secure coding practices
  • Development background in Java/J2EE, C#, .NET (and other relevant enterprise languages like Python, JavaScript/Node.js) in an enterprise environment
  • Strong understanding of DevSecOps principles, CI/CD pipelines, and integrating automated security tools, including AI/ML-driven solutions, into the Software Development Life Cycle
  • Experience using commercial enterprise automated security testing tools such as Burp, Fortify, Checkmarx, Blackduck, Snyk
  • Proficiency in leveraging SAST tools and experience with manual code review techniques and tools/IDEs to identify complex vulnerabilities
  • Demonstrated experience in AI/ML development, including data modeling, algorithm design, and implementation using Python and relevant libraries/frameworks (e.g., TensorFlow, PyTorch, scikit-learn)
  • Professional certifications, such as CISSP, CSSLP (highly preferred), GIAC, CEH or willingness to obtain
  • At least Bachelor's degree/University degree or equivalent experience

Nice to have:

  • Familiarity with natural language processing (NLP) techniques for code analysis
  • AI/ML skills
  • DevSecOps
  • Secrets Scanning
  • .NET
  • Burp
  • DAST
  • Fortify
  • Snyk
What we offer:
  • Medical, dental & vision coverage
  • 401(k)
  • Life, accident, and disability insurance
  • Wellness programs
  • Paid time off packages including vacation, sick leave, and paid holidays
  • Discretionary and formulaic incentive and retention awards

Additional Information:

Job Posted:
September 04, 2025

Expiration:
December 31, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.