About This Role
<p><b>Discover your future at Citi</b></p><p></p><p>Citi is a preeminent banking partner for institutions with cross-border needs, a global leader in wealth management, and a valued personal bank in its home market of the United States. Citi does business in more than 160 countries and jurisdictions, providing corporations, governments, investors, institutions, and individuals with a broad range of financial products and services.</p><p></p><p><b>About the job</b></p><p></p><p>Citi is seeking a highly skilled and experienced penetration tester with a specialized focus on vulnerability research, third-party component analysis, and advanced whitebox testing methodologies, including comprehensive source code review. The successful candidate will play a critical role in identifying, exploiting, and providing remediation guidance for complex security vulnerabilities within Citi's diverse technology landscape. This role demands deep technical expertise, a proactive approach to security challenges, and the ability to work collaboratively with development teams to enhance the security posture of our applications and infrastructure.</p><p></p><p><b>Who we are</b></p><p></p><p>This team specializes in conducting deep-dive penetration testing on a variety of Citi applications (Web, Mobile, Thick Client, and APIs) by manually identifying, researching, validating, and exploiting various known and unknown application security vulnerabilities.</p><p></p><p><b>What You’ll Do</b></p><p></p><p>As a Senior Penetration Tester on our Offensive Security & Vulnerability Management team, you are responsible for:</p><p></p><ul><li><p><span>Vulnerability Research & Exploitation: Conduct in-depth research to discover new attack vectors and zero-day vulnerabilities in enterprise applications, systems, and third-party components. Develop proof-of-concept exploits to effectively demonstrate risk.</span></p></li><li><p><span>Whitebox Penetration Testing: Perform comprehensive whitebox penetration tests, leveraging access to source code, design documentation, and internal system knowledge to uncover sophisticated security flaws that blackbox testing might miss.</span></p></li><li><p><span>Source Code Review: Conduct manual and automated source code reviews across various programming languages (e.g., Java, C#, Python, JavaScript) to identify security vulnerabilities, misconfigurations, and adherence to secure coding practices.</span></p></li><li><p><span>Third-Party Component Analysis: Evaluate the security of third-party libraries, frameworks, and open-source components integrated into Citi's applications. Identify known vulnerabilities (e.g., CVEs) and assess potential risks.</span></p></li><li><p><span>Remediation Guidance: Provide clear, concise, and actionable remediation recommendations to development teams, offering expert advice on secure coding, configuration, and architectural solutions.</span></p></li><li><p><span>Tooling & Automation: Utilize and contribute to the development of advanced security testing tools, </span><span>AI-augmented static analysis</span><span>, and dynamic analysis (DAST) solutions to improve efficiency and coverage.</span></p></li><li><p><span>Reporting & Communication: Prepare detailed technical reports outlining findings, risk levels, and recommended mitigations for both technical and non-technical audiences.</span></p></li><li><p><span>Stay Current: Continuously research and stay abreast of the latest security threats, vulnerabilities, attack techniques, and industry best practices.</span></p></li></ul><p></p><p><b>Job Skills/Qualifications:</b></p><ul><li><p><span>6+ years of experience in penetration testing, ethical hacking, or application security, with a significant focus on whitebox testing and/or source code review.</span></p></li><li><p><span>Proven expertise in vulnerability research, including the ability to identify novel vulnerabilities and develop reliable exploits.</span></p></li><li><p><span>Strong proficiency in at least one major programming language (e.g., Java, C#, Python) and familiarity with others.</span></p></li><li><p><span>In-depth understanding of common web application vulnerabilities (OWASP Top 10) and API security best practices.</span></p></li><li><p><span>Experience with static application security testing (SAST) tools and dynamic application security testing (DAST) tools.</span></p></li><li><p><span>Excellent written and verbal communication skills, with the ability to articulate complex security issues to diverse audiences.</span></p></li><li><p><span>Ability to work independently and as part of a team in a fast-paced, dynamic environment.</span></p></li><li><p><span>Relevant industry certifications such as OSCE, GIAC GWAPT, GPEN, GXPN, or similar.</span></p></li></ul><p></p><p>An ideal candidate will have both an engineering and security background. However, irrespective of your current role, if you have a Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience and meet most of the above-listed requirements, then don't miss this opportunity to join our team. Apply today!</p><p></p><p style="text-align:inherit"><span><span><span><span><span><span><span><span><span><span><span><span class="WHR0">------------------------------------------------------</span></span></span></span></span></span></span></span></span></span></span></span></p><h2><b>Job Family Group: </b></h2>Technology<p style="text-align:inherit"><span><span><span><span><span><span><span><span><span><span><span><span class="WHR0">------------------------------------------------------</span></span></span></span></span></span></span></span></span></span></span></span></p><h2><b>Job Family:</b></h2>Information Security<p style="text-align:inherit"><span><span><span><span><span><span><span><span class="WHR0">------------------------------------------------------</span></span></span></span></span></span></span></span></p><h2><b>Time Type:</b></h2>Full time<p style="text-align:inherit"><span><span class="WHP0">------------------------------------------------------</span></span></p><h2><b>Most Relevant Skills </b></h2>Please see the requirements listed above.<p>------------------------------------------------------</p><h2><b>Other Relevant Skills </b></h2>For complementary skills, please see above and/or contact the recruiter.<p>------------------------------------------------------</p><p style="text-align:left"><i><span>Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.</span></i></p><p style="text-align:inherit"><i><span> </span></i></p><p style="text-align:left"><i><span>If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review </span></i><i><a href="https://www.citigroup.com/citi/accessibility/application-accessibility.htm" target="_blank">Accessibility at Citi</a><span>.</span></i><br /><br /><i><span>View Citi’s </span><a href="https://www.citigroup.com/global/eeo-aa-policy" target="_blank">EEO Policy Statement</a><span> and the </span><a href="https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12ScreenRdr.pdf" target="_blank">Know Your Rights</a><span> poster.</span></i></p>