This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The role involves conducting deep-dive vulnerability assessments on a variety of Citi applications (Web, Mobile, Thick Client, and APIs) by manually identifying, researching, validating, and exploiting various known and unknown application security vulnerabilities.
Job Responsibility:
Act as a subject matter expert in offensive information security
Drive remediation by outlining a defense-in-depth approach
Report and articulate vulnerability assessment results
Contribute to the review of internal processes and activities
Requirements:
Bachelor’s degree with a minimum of 5 years of experience
Expertise in application security, ethical hacking using security tools (Burp Suite, AppScan), knowledge of OWASP Top 10, CWE/SANS Top 25, Threat Modeling
Industry-accredited security certifications such as GIAC GWAPT, GPEN, GXPN, OSCP and/or CISSP