Onsite
Mid-Level
Save Job

Job Details

About the job

If you are passionate and curious about security and want to use your offensive security skills to help keep our firm’s application and infrastructure safe, we want to speak with you.

 

Who You Are

You are talented in solving problems and identifying security weaknesses, and you have experience collaborating with engineers who remediate the vulnerabilities you identified. You adapt well to changes, and speak up to ask questions to clarify when things don’t look right.

As someone with an offensive security mindset, you work closely with others to listen to ideas and share suggestions to collectively devise the best approach to remediate vulnerabilities, continuously learn and enhance skillsets, techniques and methods.

You should have a bachelor’s degree with minimally 3 years of relevant experience. Have a good understanding of industry frameworks and methodologies such as OWASP, OSSTMM, PTES, MITRE ATT&CK, threat modeling, etc. Be certified, or intend to be certified, in accredited security certifications such as OSCP, OSWE, GXPN, GCPN, CISSP, etc.

 

What You’ll Do

As an individual contributor on our penetration testing team, you are responsible for:

·       Preparing and executing penetration testing assignments on our infrastructure assets and applications

·       Working closely with the engineering teams to provide expert guidance and advice on the remediation of identified vulnerabilities

·       Verifying newly discovered vulnerabilities in the environment

·       Reporting security vulnerabilities to businesses, clearly articulating security issues to technical and non-technical stakeholders

 

This role focuses strongly on your ability to perform manual penetration testing on infrastructure related systems and devices.  To be a good fit for this role, you should be able to identify security weaknesses and vulnerabilities in various platforms, and efficiently deliver security assessment assignments.

 

What You’ll Bring

Identify vulnerabilities and zero-day exploits though various means of analysis using:

·       Vulnerability assessment tools such as Nessus, Qualys, Kali Linux, AppScan, Burp Suite, etc.

·       Familiar with scripting languages such as: Python

·       Good knowledge of:

  • TCP/IP, IDS/IPS, firewalls, AAA systems, SSH, PKI
  • OS Security - Unix, Linux, Windows, Android/IOS
  • Common protocols - LDAP, SMTP, DNS, routing etc.
  • Web application infrastructure - application servers, web servers, databases, cloud services, containers technologies etc.

 

How You’ll Succeed

Be conscientious and consistent in identifying security vulnerabilities and working with the respective engineering teams and stakeholders to provide sound guidance and remediations. Be a team player, and a keen learner.

#LI-Hybrid

------------------------------------------------------

Job Family Group:

Technology

------------------------------------------------------

Job Family:

Information Security

------------------------------------------------------

Time Type:

Full time

------------------------------------------------------

Most Relevant Skills

Please see the requirements listed above.

------------------------------------------------------

Other Relevant Skills

For complementary skills, please see above and/or contact the recruiter.

------------------------------------------------------

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

 

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.

View Citi’s EEO Policy Statement and the Know Your Rights poster.

Company Details

About Citi Working at Citi is far more than just a job. A career with us means joining a team of more than 200,000 dedicated people from around... Read more

Mission
We're connecting diverse talent to big career moves. Meeting people who boost your career is hard - yet networking is key to growth and economic empowerment. We’re here to support you - within your current workplace or somewhere new. Upskill, join daily virtual events, apply to roles (it’s free!).
Are you hiring? Join our platform for diversifiying your team
Penetration Tester - (Assistant Vice President)
Save Job