CrawlJobs Logo

Senior Vice President, Cloud Security Threat Modeler

https://www.citi.com/ Logo

Citi

Location Icon

Location:
United States, Irving

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Employment contract

Salary Icon

Salary:

156160.00 - 234240.00 USD / Year

Job Description:

Citi is looking for a security-focused person with a strong understanding of cybersecurity principles to join the Cloud Threat Modeling team. The role involves using threat modeling to identify and mitigate risks in Citi's cloud operations. Key deliverables include threat models, technical feedback, and supervision of junior team members. The position allows for opportunities to influence the threat modeling process and collaborate with technical teams across Citi.

Job Responsibility:

  • Threat Modeling using a documented process
  • Development of automation tools as required
  • Maintain a high standard of work in identifying threats and specifying mitigating controls
  • Attending to the lifecycle of identified threats and controls
  • Delivery of threat models and supporting tasks within existing timeframes
  • Provide feedback, support, and improvements to the existing threat modeling process
  • Present work to seniors, the team, and other technical teams
  • Train newer members of the team
  • Supervise junior members of the team
  • Run parts of our threat model service
  • Assist in the wider threat modeling activities across Citi
  • Work with little supervision to complete work

Requirements:

  • 10+ years of experience in a Cybersecurity or Information Security role
  • 5+ years of Experience specifically focused on Threat Modeling in Cloud Environments
  • Expertise in Threat Modeling Methodologies like STRIDE, PASTA, Attack Trees, and the MITRE ATT&CK framework, as well as threat modeling tools (e.g., IriusRisk, ThreatModeler, Microsoft Threat Modeling Tool)
  • Proven ability to identify and analyze vulnerabilities using CWE or OWASP frameworks
  • Deep understanding of security principles related to authentication, authorization, logging/monitoring, encryption, infrastructure security, and network segmentation
  • Mastery of Operating Systems (e.g., Windows, Linux) and their hardening best practices
  • Strong familiarity with Development Concepts such as CI/CD pipelines, and SDLC
  • Extensive experience with major Cloud Platforms (e.g., AWS, Azure, GCP), including their security services and best practices
  • Proficiency in scripting languages (e.g., Python, Bash, PowerShell) or Infrastructure as Code (IaC) tools (e.g., Terraform, CloudFormation)
  • Proven ability to design, review, and critique technical architectures for security vulnerabilities and risks
  • Excellent written and verbal communication skills, with a demonstrated ability to collaborate effectively with diverse teams
  • Strong analytical and problem-solving skills, with a meticulous attention to detail

Nice to have:

  • Experience with Docker, Kubernetes, Serverless Technologies (e.g., AWS Lambda, Azure Functions, Google Cloud Functions), and Helm
  • Familiarity with Cloud Development Kit (CDK) and GitOps principles
  • Experience supporting or performing Penetration Testing activities (e.g., vulnerability scanning, network penetration testing, web application testing, mobile application testing)
  • Experience with Snowflake, MongoDB, Terraform Cloud, GitHub, or Databricks
  • Experience working in a regulated environment (e.g., financial services)
What we offer:
  • Medical, dental & vision coverage
  • 401(k)
  • Life, accident, and disability insurance
  • Wellness programs
  • Paid time off packages, including planned time off, unplanned time off, and paid holidays
  • Discretionary and formulaic incentive and retention awards

Additional Information:

Job Posted:
July 16, 2025

Expiration:
August 18, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.