Full-Time

Senior Offensive Security Malware Lead Analyst

Posted on 2/21/2026

Citi

Citi

10,001+ employees

Global financial services including banking, investment

Compensation Overview

$145.8k - $218.8k/yr

+ Incentives

Fort Lauderdale, FL, USA

In Person

Category
IT & Security (1)
Required Skills
Malware Analysis
Python
JavaScript
Postman
REST APIs
penetration testing
Requirements
  • Bachelor’s Degree with a minimum of 10 years' relevant experience, or a Master’s Degree with a minimum 5 years' experience in Malware analysis and/or application penetration testing
  • Proven background in penetration testing and expertise in the risks associated with software supply chains and dependency trees.
  • Hands-on experience with security testing tools such as BurpSuite Proxy, Postman, AppScan, WebInspect, and similar technologies.
  • Must have or be willing to obtain industry-accredited security certifications such as OSCP, OSWE, CISSP, GWAPT, GPEN, or other related credentials.
  • Advanced analytical and problem-solving skills with a demonstrated ability to take ownership and follow up on issues.
  • Proficient in interpreting and applying policies, standards, and procedures.
  • Excellent written and verbal communication skills.
  • Demonstrated ability to work effectively in a team environment and perform well under pressure.
Responsibilities
  • Lead the offensive security program for malware analysis and response, focusing on proactively securing the software development lifecycle.
  • Perform manual and dynamic analysis on potential open-source malware within NPM, Python, and other package ecosystems to identify supply chain risks.
  • Act as a subject matter expert in offensive information security, performing manual security assessments on web technologies, including APIs, JavaScript Frameworks, and Artificial Intelligence systems.
  • Conduct and facilitate security reviews, penetration testing engagements, and table-top/red-team/scenario analysis exercises.
  • Drive remediation efforts by outlining defense-in-depth strategies and providing strategic solutions to developers on effective security controls.
  • Evaluate, recommend, and assist in the selection of new and emerging external products, applications, and technologies with a focus on their security implications.
  • Work closely with internal Applications Development to enhance both architecture and application security.
  • Identify opportunities for enhancements to security standards, tools, and processes, and contribute to the review of internal activities for potential improvement and automation.
  • Define secure configurations for network, database, server, and desktop technologies in alignment with security policies.
  • Develop strong technical documentation and deliver clear presentations to articulate vulnerability assessment results to both technical and non-technical audiences.
  • Assess risk during business decisions, ensuring compliance with applicable laws, rules, and regulations while safeguarding the firm's assets and reputation.
Desired Qualifications
  • Experience leveraging Artificial Intelligence to enhance offensive security processes is highly desirable.

Citi provides financial services including consumer banking, credit, investment banking, and wealth management to individuals, corporations, and governments. The company operates by earning interest on loans and collecting fees for managing investments, processing trades, and facilitating cross-border transactions through its digital platforms. Unlike many local banks, Citi maintains a physical and digital presence in over 160 countries, allowing it to serve as a single partner for clients with global financial needs. Its goal is to drive growth and profitability for its clients and shareholders while supporting environmental and social sustainability initiatives.

Company Size

10,001+

Company Stage

IPO

Headquarters

New York City, New York

Founded

1812

Your Connections

People at Citi who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Tokenized receipts open new fee pools in private-market access and distribution.
  • Citi's shared blockchain deposit network with JPMorgan and Bank of America expands reach.
  • Global corporate banking leadership in Japan, Asia North, and Australia can deepen multinational relationships.

What critics are saying

  • Tokenized receipts face regulatory scrutiny if clients reject Citi-issued wrappers over direct ownership.
  • Consumer exits in 14 overseas markets shrink deposits, revenue, and cross-sell opportunities.
  • Private-credit and macro stress can raise delinquencies, weaken deal activity, and pressure trading revenue.

What makes Citi unique

  • Citi combines global banking scale with custody, issuance, and tokenization capabilities.
  • It launched Digital Depositary Receipts on June 11, 2026, for private shares.
  • Citi has operated depositary receipt services since 1928.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

401(k) Company Match

Wellness Program

Paid Vacation

Paid Sick Leave

Paid Holidays

Company News

Green Street
Jun 18th, 2026
EQT-backed self-storage firm secures £91m loan

Citi backs Storex with facility to strengthen capital base and support growth

Broker Daily
May 31st, 2026
ScotPac closes $300M ABS transaction, raises nearly $1B in two and a half years

ScotPac has completed a $300 million asset-backed securitisation transaction, its third ABS issuance and largest to date. The deal was structured to meet UK and European Securitisation Regulation requirements, broadening the lender's access to international capital markets. Citi served as arranger, with Citi and NAB as joint lead managers. The transaction brings ScotPac's total ABS funding to nearly $1 billion over the past two and a half years. CEO Jon Sutton said it reinforces the company's commitment to supporting SMEs with flexible funding solutions during volatile economic times. The deal attracted strong demand from existing investors and new UK and European-based participants. ScotPac has been diversifying its funding platform, having secured a warehouse facility with UBS in March alongside launching a new asset-based finance solution.

Yahoo Finance
Apr 14th, 2026
Banks report strong profits but warn of rising energy prices hitting consumers

America's largest banks reported strong first-quarter profits driven by robust investment banking activity and a resilient economy, though executives warned about mounting risks from rising energy prices and geopolitical uncertainty. JPMorgan Chase posted a profit of $16.49 billion, up 13% year-on-year, whilst Wells Fargo earned $5.25 billion and Citigroup reported $5.79 billion. Investment banking fees surged, with JPMorgan seeing a 30% jump and Citigroup a 12% increase in advisory fees, fuelled by market volatility and corporate dealmaking. However, JPMorgan CEO Jamie Dimon cautioned about "an increasingly complex set of risks", including wars, energy prices and trade tensions. Wells Fargo noted customers allocating more spending to petrol whilst cutting discretionary purchases, signalling potential downstream economic impacts from elevated oil prices.

The Associated Press
Apr 14th, 2026
Banks report strong Q1 profits but warn rising energy prices threaten consumer spending

America's largest banks reported strong first-quarter profits driven by investment banking activity and a resilient economy, but executives warned about emerging economic headwinds from rising energy prices and geopolitical uncertainty. JPMorgan Chase posted a 13% profit increase to $16.49 billion, with investment banking fees jumping 30%. Wells Fargo earned $5.25 billion whilst Citigroup reported $5.79 billion in profits. The gains came amid market volatility and increased merger activity. However, JPMorgan CEO Jamie Dimon cited "an increasingly complex set of risks" including wars, energy prices and trade tensions. Wells Fargo's CFO noted consumers allocating more spending towards petrol whilst reducing discretionary purchases. Dimon warned that higher oil prices' impact "will likely take some time to materialise" if they persist.

Yahoo Finance
Apr 14th, 2026
Citi stock poised to jump as Wall Street loves the name, says Jim Cramer

Citigroup has raised interest among investors, with Jim Cramer highlighting strong market sentiment towards the stock. Following earnings, Cramer noted that Citigroup is "love, love, love by everybody on Wall Street" and expects the stock to jump higher. The bank delivered solid quarterly results, with 8% revenue growth and 35% earnings per share increase, excluding one-time charges. Net interest income rose 14%, beating expectations. However, results were mixed across divisions, with services, banking and fixed income performing well, whilst equity trading and personal banking fell short. Trading at a significant discount to peers despite rising 66% last year, Citigroup remains attractive. CEO Jane Fraser indicated the bank's transformation efforts are over 80% complete, though questions remain about future growth once self-help measures conclude.

INACTIVE