CrawlJobs Logo

Senior Application Security Lead

https://www.citi.com/ Logo

Citi

Location Icon

Location:
United States, Jacksonville

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Employment contract

Salary Icon

Salary:

113840.00 - 170760.00 USD / Year

Job Description:

Senior Application Security Lead position at Citi's Chief Information Security Office (CISO), responsible for ensuring application security through automated security testing, source code review, and vulnerability assessment. The role involves interfacing with development organizations, performing secure code reviews, and working to implement Secure-SDLC across the enterprise.

Job Responsibility:

  • Perform analysis and execution of scans for Software Composition Analysis findings, mobile scanning vulnerabilities
  • Review and validate automated testing results and prioritize actions that resolve issues based on overall risk
  • Perform application security tests using binary analysis
  • Perform manual source code review for security vulnerabilities
  • Analyze source code to mitigate identified weaknesses and vulnerabilities within the system
  • Identify opportunities to automate and standardize information security controls
  • Participate in conference calls with engineering team to ensure proper scan coverage and effective results
  • Write formal security assessment report for each application
  • Direct the development and delivery of secure solutions by coordinating with business and technical contacts
  • Collaborate with application teams to ensure that any identified security vulnerabilities are remediated in a timely manner
  • Manage and execute security assessments for multiple projects simultaneously
  • Research and explore new testing tools and methodologies
  • Act as a mentor to the junior team members
  • Actively participate in research and knowledge sharing discussions

Requirements:

  • 6+ years of relevant experience in web development, source code review, or application security testing
  • Basic understanding of application security and associated vulnerabilities
  • Development background in Java/J2EE, C#, .NET in an enterprise environment
  • Development experience with modern JavaScript frameworks, Python, JSON, Lambda
  • Good understanding of the Software Development Life Cycle – including unit testing, code scanning
  • Experience using ALM and CICD tools like Bitbucket, GitHub, Jenkins, udeploy, BMC RLM, tekton or related tools in an agile methodology
  • Familiarity with static analysis (source code review) and application pen-testing techniques
  • Bachelor's degree in technology, Computer Science, Engineering, or related field
  • Professional certifications, such as CISSP, CSSLP, GIAC, CEH, or willingness to obtain

Nice to have:

  • Experience using commercial enterprise automated security testing tools such as Checkmarx, Snyk, AppScan Source, Fortify, Veracode, Blackduck, Sonatype, Contrast, Seeker, NowSecure
  • Knowledge with mobile platforms and languages including Android, Kotlin, Objective-C, Swift
  • Experience using or testing cloud platforms (AWS, Google, Azure, etc.)
  • Master's degree
  • Proven influencing and relationship management skills
What we offer:
  • Medical, dental & vision coverage
  • 401(k)
  • Life, accident, and disability insurance
  • Wellness programs
  • Paid time off packages including vacation, sick leave, and paid holidays
  • Discretionary and formulaic incentive and retention awards

Additional Information:

Job Posted:
August 27, 2025

Expiration:
September 02, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.