At a Glance
- Tasks: Build secure AI products and conduct ethical hacking to protect our innovations.
- Company: Join Citi, a global leader in finance with a dynamic tech team.
- Benefits: Enjoy 27 days annual leave, private medical care, and a competitive salary.
- Why this job: Make a real impact in AI security while growing your career in a supportive environment.
- Qualifications: Experience in Golang, security engineering, and a passion for AI technology.
- Other info: Work in a hybrid model with opportunities for mentorship and skill development.
The predicted salary is between 36000 - 60000 ÂŁ per year.
Discover your future at Citi. Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000 dedicated people from around the globe. At Citi, you’ll have the opportunity to grow your career, give back to your community and make a real impact.
We are Citi’s Application, Platform and Engineering team, a start-up with the exciting mission of shaping the direction of travel for the entire bank under the Chief Technology Office, by defining the tech and engineering strategy for the enablement bank. We are a team of talented engineers, product managers and tech SMEs, taking ambiguous concepts and making them real by engineering cutting edge products at planetary scale! We are solely focused on the most modern technology and engineering disciplines such as generative AI, cloud, security, modern app stacks (with Golang, Gatekeeper), open source and the latest and greatest in the Kubernetes ecosystem.
Generative AI is a growing space, as a result, we ask that you share with us any specific AI engineering projects utilizing LLMs that you’re proud of in your application. Ideally these projects should show off complex and clever architectures or a systematic evaluation of an LLM’s behaviour.
You might be a good fit if you:
- Bring your deep-dive application security engineering expertise from building production systems
- Thrive in a results-driven environment, where flexibility fuels impact
- Be a game-changer, ready to step beyond your designated role
- Love the synergy of pair programming? So do we!
- Seize the opportunity to secure AI applications at scale.
- A relentless passion to learn more about AI security, LLM attacks, and bringing your knowledge to shape Citi's secure AI future.
What you’ll do within the Tech Strategy team:
- Build secure AI products from 0-1 - Engineer production-grade, business-facing AI platforms with security built-in from day one
- Conduct penetration testing, vulnerability research, and attack simulation to make our products bulletproof
- Create automated security solutions that scale across fast-paced development cycles
- Identify and mitigate LLM‑specific vulnerabilities, prompt injection attacks, and AI model security risks through hands‑on testing
- Embed security practices throughout our rapid development lifecycle while maintaining velocity
- Guide other engineers on secure coding, vulnerability remediation, and security‑first thinking
Experience That Will Help You Succeed In This Role:
- Proficient in Golang
- Production system builder with security focus - proven track record of architecting and building secure, large‑scale production applications and business‑facing platforms from the ground up
- Ethical hacking and penetration testing expertise - hands‑on experience finding and exploiting vulnerabilities, conducting red team exercises, and thinking like an attacker to strengthen defenses
- State‑of‑the‑art security engineering with Go, Python, JavaScript – you build both security tools and secure production systems in fast‑paced environments
- HashiCorp Vault mastery - deep experience writing custom plugins, creating secrets engines, implementing dynamic credentials, and extending Vault functionality for enterprise‑scale secrets management
- Enterprise authentication & authorization - designing and implementing OAuth, JWT, RBAC, and complex identity systems with fine‑grained access controls in business‑critical applications
- API security and threat modelling - securing REST/GraphQL APIs, conducting threat assessments, and implementing advanced security patterns in high‑traffic production systems
- AI/ML security and vulnerability research - understanding of LLM vulnerabilities, model security, prompt injection attacks, and AI‑specific threat vectors through hands‑on testing
- Security automation and tooling – automating manual security processes
- Cloud‑native security - securing containerized applications in Kubernetes, service mesh security, and cloud‑native security patterns at enterprise scale
- Incident response and forensics - experience investigating, analyzing, and responding to security incidents in live production systems
What We Believe In:
We do not have boundaries between security engineering and product development, and we expect all our technical staff to contribute to both as needed. We take a product-focused approach to security and care about building solutions that are robust, scalable, and easy for developers to use. We enjoy working in a fast‑paced team tackling cutting‑edge security problems by constantly testing and learning. We enjoy pair programming for our security tools; we are lean in our approach and remove bureaucracy where we see it. We believe in delivering secure solutions fast, iterating and pivoting as we go, rather than defining the perfect security framework upfront.
What we’ll provide you:
This is a unique role that will put you in the position to be part of a new venture and actively drive change. Every day there will be new challenges that will help you develop new skills that can drive your career. By joining Citi London, you will not only be part of a business casual workplace with a hybrid working model (up to 2 days working at home per week), but also receive a competitive base salary (which is annually reviewed), and enjoy a whole host of additional benefits such as:
- 27 days annual leave (plus bank holidays)
- A discretionary annual performance‑related bonus
- Private Medical Care & Life Insurance
- Employee Assistance Program
- Pension Plan
- Paid Parental Leave
- Special discounts for employees, family, and friends
Alongside these benefits, Citi is committed to ensuring our workplace is where everyone feels comfortable coming to work as their whole self, every day. We want the best talent around the world to be energised to join us, motivated to stay and thrive.
Offensive Security Engineer - (SVP) employer: 11037 Citibank, N.A. United Kingdom
Contact Detail:
11037 Citibank, N.A. United Kingdom Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Offensive Security Engineer - (SVP)
✨Tip Number 1
Network like a pro! Reach out to current employees at Citi through LinkedIn or other platforms. Ask them about their experiences and any tips they might have for landing a role in the Application, Platform and Engineering team.
✨Tip Number 2
Show off your skills! If you've worked on AI engineering projects or have experience with security tools, make sure to discuss these during interviews. Bring examples that highlight your problem-solving abilities and technical expertise.
✨Tip Number 3
Prepare for technical interviews by brushing up on your coding skills, especially in Golang and security practices. Practice common interview questions and scenarios related to offensive security to demonstrate your knowledge and readiness.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the Citi team.
We think you need these skills to ace Offensive Security Engineer - (SVP)
Some tips for your application 🫡
Show Off Your Projects: When you apply, make sure to highlight any AI engineering projects you've worked on, especially those involving LLMs. We want to see your creativity and technical skills in action!
Tailor Your Application: Don’t just send a generic application! Take the time to tailor your CV and cover letter to reflect how your experience aligns with our mission at Citi. We love seeing candidates who understand our goals.
Be Clear and Concise: Keep your application clear and to the point. We appreciate straightforward communication, so avoid jargon unless it’s necessary. Make it easy for us to see why you’re a great fit!
Apply Through Our Website: Make sure to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. We can’t wait to hear from you!
How to prepare for a job interview at 11037 Citibank, N.A. United Kingdom
✨Know Your Stuff
Make sure you brush up on your knowledge of Golang and security engineering principles. Be ready to discuss specific projects you've worked on, especially those involving AI and LLMs. This will show that you not only understand the technical requirements but also have hands-on experience.
✨Show Off Your Problem-Solving Skills
Prepare to tackle hypothetical scenarios during the interview. Think about how you would approach penetration testing or vulnerability research in a real-world context. This is your chance to demonstrate your critical thinking and creativity in solving complex security challenges.
✨Emphasise Teamwork
Citi values collaboration, so be ready to talk about your experiences with pair programming or mentoring others. Share examples of how you've worked effectively in teams to build secure applications or improve security practices. This will highlight your ability to thrive in a fast-paced environment.
✨Ask Insightful Questions
Prepare some thoughtful questions about Citi's approach to security and their tech strategy. This shows your genuine interest in the role and helps you gauge if the company culture aligns with your values. Plus, it gives you a chance to engage with your interviewers on a deeper level.