Job Details – this job has expired, please see similar jobs below
Citi Technology Infrastructure (CTI) provides the products and services that enable Citi's workforce along with the majority of the financial solutions that Citi's customers rely on. We provide the critical technical foundation for Citi's operations through the infrastructure that runs business and general user computing services. We do this by working as one-team to deliver high quality reliable and modern infrastructure technologies at the right cost. We drive to optimize the functionality and capability of the infrastructure technologies.
About the Position:
The Cloud Security Operations analyst works in a multi-disciplinary team of teams driving cyber security services and solutions to enable Citi to securely adopt private, hybrid, and public Cloud platforms. This role is one of the primary security interfaces with development teams, architects, engineers, and operational teams involved in Cloud-related projects. Our operating model emphasizes DevSecOps, that is, automation, integration, and agility based on Security as a Service / Security as Code concepts.
◦ Partner with Engineering and Operations teams to create, implement, and apply DevSecOps principles and processes that are consumed by developers across all sectors in Citi.
◦ Full end to end security assurance activities including Vulnerability Assessments (pre-production, post-production), Red Team end to end exercises, and Purple Team exercises (Read and Blue team collaboration) in order to identify areas of risk and ensure any gaps are documented and remediated.
◦ Supplement Cloud monitoring tool(s) by adding new capabilities, security checks, and automation using the tool’s extension capabilities and/or the SDK/API
◦ Provide threat modeling and risk assessment services to characterize the risk and severity posture of various systems and components in the Cloud environment.
◦ Run Cloud Continuous Monitoring reporting/metrics governing all security compliance/hygiene issues across the entire Cloud ecosystem.
◦ Support the implementation of Infrastructure as Code (IaC) security checks as part of the end to end Cloud Service enablement work stream.
◦ Develop and Deploy security guardrails through reusable patterns using standardized development frameworks
◦ Run and operate Breach and Attack Simulation (BAS) platform(s) to continually simulate, validate, and remediate potential attackers’ paths to critical Cloud assets.
◦ Vulnerability and Threat Management (VTM) – Monitoring and Assessment, in the container space.
◦ Collect security-related operational metrics through automation and increase security visibility across the organization; measure the coverage and effectiveness of security tools; transparency over the security state of the Cloud)
◦ Candidates should have knowledge of the tools and processes to provide operational security support to our Cloud ecosystem. Pre-requisites for this position are at least a Bachelor's Degree with 6-10 years of experience on most of the following areas:
◦ Hands-on experience with Cloud platforms (AWS, GCP, Azure, etc.)
◦ Excellent understanding of Cloud security concepts/best practices in various Cloud Service Providers (for example: AWS GCP Azure)
◦ Hands-on experience with cloud security tools and Security as a Service solutions (Company website, Redlock, Dome9, SiftSecurity, etc.)
Industry-accredited certifications will be required. Candidates with Cloud security certifications (ex: AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, Azure Security Engineer Associate, etc.), non-security Cloud certifications (AWS SysOp Admin, AWS Solutions Architect Associate/professional, GCP Associate Cloud Engineer, GCP Professional Cloud Architect, etc.) and other security certifications (for example: OSCP,OSCE, GXPN,GPEN, GCIH, GWAPT, etc.) will be preferred. Candidates without certification must be willing to purse them during the course of employment.
Grade :All Job Level - All Job FunctionsAll Job Level - All Job Functions - US
Citi is an equal opportunity and affirmative action employer.
Minority/Female/Veteran/Individuals with Disabilities/Sexual Orientation/Gender Identity.
Company Inc. and its subsidiaries ("Citi”) invite all qualified interested applicants to apply for career opportunities. If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity CLICK HERE.
To view the "EEO is the Law" poster CLICK HERE. To view the EEO is the Law Supplement CLICK HERE.
To view the EEO Policy Statement CLICK HERE.
To view the Pay Transparency Posting CLICK HERE.
Sign up and search through 51,281 curated jobs in the Finance & Investment Edition: