AI & Offensive Security Analyst

Citi
Irving, TX, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Software System Penetration Testing Burp Suite Static Program Analysis Cyber Security Data Auditing Software Engineering Large Language Models Information Technology Machine Learning Operations Static Application Security Testing Vulnerability Analysis
+1 more
Dynamic Application Security Testing

Job description

The AI & Offensive Security Analyst is a hands-on practitioner role within Citi’s Advanced Pentesting & Research team. This position is responsible for driving offensive security research, vulnerability discovery, and the development of AI-powered security tooling and automation. The ideal candidate combines deep adversarial security expertise with hands-on AI engineering capability - someone who can identify and exploit weaknesses in complex systems, then build intelligent solutions to defend against them at scale. mindset The successful candidate will bring a strong R&D, with a natural curiosity and discipline to stay at the forefront of the security and AI research landscape - actively identifying new research opportunities.

You will work closely with engineering, architecture, and risk teams to embed security intelligence across the firm’s technology landscape.

Responsibilities:

  • Perform deep vulnerability research on emerging attack surfaces including LLM-based systems, AI pipelines, model inference endpoints, and prompt injection vectors.
  • Design, build, and maintain AI harnesses capable of performing security-related tasks, including autonomous vulnerability scanning agents, AI-driven exploit classification systems, intelligent threat detection models, and LLM-assisted code analysis engines.
  • Research and prototype novel attack techniques and defensive countermeasures, contributing findings to internal knowledge bases, threat models, and security engineering standards - driven by a proactive R&D mindset and continuous lookout for new research opportunities.
  • Analyze source code using both manual review and AI-augmented static analysis to identify and mitigate security weaknesses, logic flaws, and injection vulnerabilities across polyglot codebases.
  • Conduct offensive security assessments and penetration testing against applications, infrastructure, and AI/ML systems to identify exploitable vulnerabilities before adversaries do.
  • Identify opportunities to automate and standardize information security controls using AI-driven pipelines, reducing manual effort and improving detection fidelity across supported groups.

Requirements

6+ years of experience in Cyber Security or related field., Master’s degree in computer science, Cyber Security or related field with a minimum of 3 years of experience in a penetration testing or application development role OR

  • Bachelor’s degree in computer science, Cyber Security or related field with a minimum of 5 years of experience in a penetration testing or application development role
  • Hands-on experience with security & Software engineering tooling : Burp Suite, SAST/DAST scanners, Claude Code, GH copilot & custom exploit development from CVE advisories
  • Demonstrated proficiency in penetration testing across web, network, and binary domains
  • Strong R&D mindset - demonstrated ability to independently identify new research opportunities, follow emerging academic and industry security research, and translate findings into actionable tooling or defensive improvements
  • Good proficiency in reading, understanding, and working with code and its features - including the ability to navigate unfamiliar codebases, reason about code behaviour, identify logic flaws, and leverage language-specific constructs in security analysis and tool development

Education:

  • Bachelor’s degree/University degree or equivalent experience

About the company

Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.

As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients’ best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first-class customer experience. We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services.

Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We’ll enable growth and progress together.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:16 min

Advantages of reproducible configurations and instantaneous rollbacks

Álvaro Martín Lozano · LIVE

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:08 min

Conducting data audits and adversarial testing on models

Toju Duke · WWC 2022

Videos

See all

Related articles

See all