CrawlJobs Logo

Soc Insider Threat Hunter Operations Analyst

https://www.citi.com/ Logo

Citi

Location Icon

Location:
Hungary, Budapest

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

The Insider Threat Cyber Ops (ITCO) team sits in the SOC actively monitoring Citi's network against malicious attempts to harm the organization utilizing cybersecurity tools and trend analysis. The SOC Insider Threat Hunter Operations Analyst is an intermediate level position responsible for leading efforts to prevent, monitor and respond to information/data breaches and cyber-attacks. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with Citi's data security policy.

Job Responsibility:

  • Monitor and analyze logs and alerts on a variety of different technologies across multiple platforms to identify security incidents
  • Proactively hunt for insider threat utilizing large datasets, tools, and detections
  • Continually assess and refine insider threat detections
  • Execute analysis of email-based threats to include understanding of email communications, platforms, headers, transactions, and identification of malicious tactics, techniques, and procedures
  • Utilize a variety of security tools and technologies to analyze potential threats to determine impact, scope, and recovery
  • Leverage network security tools and capabilities to support Cyber Threat Monitoring activities
  • Assist Security Incident Response Teams with incident investigations and aid in technical risk assessments
  • Identify and develop new and improved technical procedures and process control manuals
  • Identify significant IS threats and vulnerabilities
  • Perform regular assessments based on changes in the threat landscape as needed
  • Appropriately assess and prioritize risk
  • Demonstrate appropriate consideration for the firm's reputation and safeguarding Citigroup, its clients, and assets by driving compliance with applicable laws, regulations, and Citi Policy
  • Most have a strong analytical and problem-solving skills to detect and respond to insider threats effectively
  • Proficiency in cybersecurity tools and technologies, as well as knowledge of data loss prevention (DLP) and user behavior analytics (UBA) tools
  • Maintaining a strong code of ethics and respecting privacy while investigating insider Threat related incidents is essential

Requirements:

  • 3+ years' hands-on relevant experience
  • Cybersecurity experience is an absolute requirement
  • Experience working with DLP tools, UEBA, and SIEM technologies (i.e., Splunk, CrowdStrike)
  • Strong proficiency with threat analysis tools
  • Consistently demonstrates clear and concise written and verbal communication
  • Strong working knowledge of Threat Monitoring Procedures
  • Knowledge and exposure in creating use cases
  • Direct experience working with large datasets
  • Direct experience in threat hunting in a corporate environment
  • Ability to work cohesively in a team setting with minimal supervision
  • Proven analytical skills

Nice to have:

  • Knowledge and exposure to SOAR technology
  • Scripting/coding is a plus
  • Previous experience as an insider threat analyst and/or threat hunter
  • Certifications: CISA, CISSP, ITPM (Insider Threat Program Manager), SANs
What we offer:
  • Cafeteria Program
  • Home Office Allowance (for colleagues working in hybrid work models)
  • Paid Parental Leave Program (maternity and paternity leave)
  • Private Medical Care Program and onsite medical rooms at our offices
  • Pension Plan Contribution to voluntary pension fund
  • Group Life Insurance
  • Employee Assistance Program
  • Access to a wide variety of learning and development programs, online course libraries and upskilling platforms, such as Udemy and Degreed
  • Flexible work arrangements to support you in managing work - life balance
  • Career progression opportunities across geographies and business lines
  • Socially active employee communities with diverse networking opportunities

Additional Information:

Job Posted:
September 05, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.