Offensive Security Engineer - (SVP) in London
Offensive Security Engineer - (SVP)

Offensive Security Engineer - (SVP) in London

London Full-Time 36000 - 60000 ÂŁ / year (est.) Home office (partial)
C

At a Glance

  • Tasks: Engineer secure AI products and conduct ethical hacking to protect cutting-edge applications.
  • Company: Join Citi, a global leader in technology and innovation.
  • Benefits: Enjoy 27 days annual leave, private medical care, and a competitive salary.
  • Why this job: Be part of a dynamic team shaping the future of AI security.
  • Qualifications: Proficient in Golang with experience in ethical hacking and security engineering.
  • Other info: Work in a fast-paced environment with opportunities for career growth.

The predicted salary is between 36000 - 60000 ÂŁ per year.

Be among the first 25 applicants. Discover your future at Citi. Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000 dedicated people from around the globe. At Citi, you’ll have the opportunity to grow your career, give back to your community and make a real impact.

Job Overview

We are Citi’s Application, Platform and Engineering team, a start-up with the exciting mission of shaping the direction of travel for the entire bank under the Chief Technology Office, by defining the tech and engineering strategy for the bank. We are a team of talented engineers, product managers and tech SMEs, taking ambiguous concepts and making them real by engineering cutting edge products at planetary scale! We are solely focused on the most modern technology and engineering disciplines such as generative AI, cloud, security, modern app stacks (with Golang, Gatekeeper), open source and the latest and greatest in the Kubernetes ecosystem.

Generative AI is a growing space, as a result, we ask that you share with us any specific AI engineering projects utilising LLMs that you’re proud of in your application. Ideally these projects should show off complex and clever architectures or a systematic evaluation of an LLM’s behaviour.

You might be a good fit if:

  • Bring your deep-dive application security engineering expertise from building production systems.
  • Thrive in a results-driven environment, where flexibility fuels impact.
  • Be a game‑changer, ready to step beyond your designated role.
  • Love the synergy of pair programming? So do we!
  • Seize the opportunity to secure AI applications at scale.
  • A relentless passion to learn more about AI security, LLM attacks, and bringing your knowledge to shape Citi's secure AI future.

What you’ll do within the Tech Strategy team:

  • Build secure AI products from 0-1 - Engineer production‑grade, business‑facing AI platforms with security built‑in from day one.
  • Ethical hacking and red team activities - Conduct penetration testing, vulnerability research, and attack simulation to make our products bulletproof.
  • Design and build security tools and frameworks - Create automated security solutions that scale across fast‑paced development cycles.
  • Secure novel AI attack surfaces - Identify and mitigate LLM‑specific vulnerabilities, prompt injection attacks, and AI model security risks through hands‑on testing.
  • Lead "shift left" security - Embed security practices throughout our rapid development lifecycle while maintaining velocity.
  • Mentor security practices - Guide other engineers on secure coding, vulnerability remediation, and security‑first thinking.

Experience That Will Help You Succeed In This Role:

  • Proficient in Golang.
  • Production system builder with security focus - proven track record of architecting and building secure, large‑scale production applications and business‑facing platforms from the ground up.
  • Ethical hacking and penetration testing expertise - hands‑on experience finding and exploiting vulnerabilities, conducting red team exercises, and thinking like an attacker to strengthen defenses.
  • State‑of‑the‑art security engineering with Go, Python, JavaScript - you build both security tools and secure production systems in fast‑paced environments.
  • HashiCorp Vault mastery - deep experience writing custom plugins, creating secrets engines, implementing dynamic credentials, and extending Vault functionality for enterprise‑scale secrets management.
  • Enterprise authentication & authorization - designing and implementing OAuth, JWT, RBAC, and complex identity systems with fine‑grained access controls in business‑critical applications.
  • API security and threat modelling - securing REST/GraphQL APIs, conducting threat assessments, and implementing advanced security patterns in high‑traffic production systems.
  • AI/ML security and vulnerability research - understanding of LLM vulnerabilities, model security, prompt injection attacks, and AI‑specific threat vectors through hands‑on testing.
  • Security automation and tooling – automating manual security processes.
  • Cloud‑native security - securing containerized applications in Kubernetes, service mesh security, and cloud‑native security patterns at enterprise scale.
  • Incident response and forensics - experience investigating, analyzing, and responding to security incidents in live production systems.

What We Believe In:

We do not have boundaries between security engineering and product development, and we expect all our technical staff to contribute to both as needed. We take a product‑focused approach to security and care about building solutions that are robust, scalable, and easy for developers to use. We enjoy working in a fast‑paced team tackling cutting‑edge security problems by constantly testing and learning. We enjoy pair programming for our security tools; we are lean in our approach and remove bureaucracy where we see it. We believe in delivering secure solutions fast, iterating and pivoting as we go, rather than defining the perfect security framework upfront.

What We’ll Provide You:

This is a unique role that will put you in the position to be part of a new venture and actively drive change. Every day there will be new challenges that will help you develop new skills that can drive your career. By joining Citi London, you will not only be part of a business casual workplace with a hybrid working model (up to 2 days working at home per week), but also receive a competitive base salary (which is annually reviewed), and enjoy a whole host of additional benefits such as:

  • 27 days annual leave (plus bank holidays).
  • A discretionary annual performance related bonus.
  • Private Medical Care & Life Insurance.
  • Employee Assistance Program.
  • Pension Plan.
  • Paid Parental Leave.
  • Special discounts for employees, family, and friends.

Alongside these benefits Citi is committed to ensuring our workplace is where everyone feels comfortable coming to work as their whole self, every day. We want the best talent around the world to be energized to join us, motivated to stay and empowered to thrive.

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

Offensive Security Engineer - (SVP) in London employer: Citi

Citi is an exceptional employer that fosters a dynamic and inclusive work culture, where innovation meets collaboration. As part of our London team, you'll enjoy a hybrid working model, competitive salary, and extensive benefits including 27 days of annual leave and private medical care. We prioritise employee growth through hands-on challenges in cutting-edge technology, ensuring you can thrive while making a meaningful impact in the world of AI security.
C

Contact Detail:

Citi Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Offensive Security Engineer - (SVP) in London

✨Tip Number 1

Network like a pro! Reach out to current employees at Citi through LinkedIn or other platforms. Ask them about their experiences and any tips they might have for landing the Offensive Security Engineer role.

✨Tip Number 2

Show off your skills! Prepare a portfolio of your AI engineering projects, especially those involving LLMs. This will give you a leg up during interviews and show that you're ready to tackle the challenges at Citi.

✨Tip Number 3

Practice makes perfect! Brush up on your ethical hacking and penetration testing skills. You might even want to simulate some red team exercises to get in the right mindset for the role.

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining the team at Citi.

We think you need these skills to ace Offensive Security Engineer - (SVP) in London

Golang
Ethical Hacking
Penetration Testing
Vulnerability Research
Security Tool Development
AI Security
LLM Vulnerabilities
API Security
Threat Modelling
Cloud-Native Security
Incident Response
Forensics
Security Automation
OAuth
RBAC

Some tips for your application 🫡

Show Off Your Projects: When you apply, make sure to highlight any AI engineering projects you've worked on, especially those involving LLMs. We want to see your creativity and technical skills in action!

Tailor Your Application: Don’t just send a generic application! Take the time to tailor your CV and cover letter to reflect how your experience aligns with the role. We love seeing candidates who understand our mission and values.

Be Clear and Concise: Keep your application clear and to the point. Use bullet points where possible to make it easy for us to read through your achievements and skills. We appreciate straightforward communication!

Apply Through Our Website: Make sure to apply through our website for the best chance of getting noticed. It’s the easiest way for us to track your application and get back to you quickly!

How to prepare for a job interview at Citi

✨Know Your Stuff

Make sure you brush up on your knowledge of Golang and security engineering principles. Be ready to discuss specific projects you've worked on, especially those involving AI and LLMs. This will show that you not only understand the technical aspects but also have hands-on experience.

✨Show Off Your Problem-Solving Skills

Prepare to tackle hypothetical scenarios during the interview. Think about how you would approach ethical hacking or penetration testing in a real-world context. This is your chance to demonstrate your critical thinking and creativity in solving complex security challenges.

✨Emphasise Teamwork

Citi values collaboration, so be ready to talk about your experiences with pair programming and mentoring others. Share examples of how you've worked with teams to embed security practices into development cycles, highlighting your ability to communicate effectively and foster a security-first mindset.

✨Ask Insightful Questions

Prepare thoughtful questions about Citi's approach to security and their tech strategy. This shows your genuine interest in the role and helps you gauge if the company culture aligns with your values. Plus, it gives you a chance to engage with the interviewers on a deeper level.

Offensive Security Engineer - (SVP) in London
Citi
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

C
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>