At a Glance
- Tasks: Engineer secure AI products and conduct ethical hacking to protect cutting-edge applications.
- Company: Join Citi, a global leader in technology and innovation.
- Benefits: Enjoy 27 days annual leave, private medical care, and a competitive salary.
- Why this job: Be part of a dynamic team shaping the future of AI security.
- Qualifications: Experience in Golang, ethical hacking, and building secure production systems.
- Other info: Flexible hybrid working model with opportunities for career growth.
The predicted salary is between 43200 - 72000 ÂŁ per year.
Be among the first 25 applicants. Discover your future at Citi. Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000 dedicated people from around the globe. At Citi, you’ll have the opportunity to grow your career, give back to your community and make a real impact.
Job Overview
We are Citi’s Application, Platform and Engineering team, a start-up with the exciting mission of shaping the direction of travel for the entire bank under the Chief Technology Office, by defining the tech and engineering strategy for the bank. We are a team of talented engineers, product managers and tech SMEs, taking ambiguous concepts and making them real by engineering cutting edge products at planetary scale! We are solely focused on the most modern technology and engineering disciplines such as generative AI, cloud, security, modern app stacks (with Golang, Gatekeeper), open source and the latest and greatest in the Kubernetes ecosystem.
Generative AI is a growing space, as a result, we ask that you share with us any specific AI engineering projects utilising LLMs that you’re proud of in your application. Ideally these projects should show off complex and clever architectures or a systematic evaluation of an LLM’s behaviour.
You might be a good fit if:
- Bring your deep-dive application security engineering expertise from building production systems.
- Thrive in a results-driven environment, where flexibility fuels impact.
- Be a game‑changer, ready to step beyond your designated role.
- Love the synergy of pair programming? So do we!
- Seize the opportunity to secure AI applications at scale.
- A relentless passion to learn more about AI security, LLM attacks, and bringing your knowledge to shape Citi's secure AI future.
What you’ll do within the Tech Strategy team:
- Build secure AI products from 0-1 - Engineer production‑grade, business‑facing AI platforms with security built‑in from day one.
- Ethical hacking and red team activities - Conduct penetration testing, vulnerability research, and attack simulation to make our products bulletproof.
- Design and build security tools and frameworks - Create automated security solutions that scale across fast‑paced development cycles.
- Secure novel AI attack surfaces - Identify and mitigate LLM‑specific vulnerabilities, prompt injection attacks, and AI model security risks through hands‑on testing.
- Lead "shift left" security - Embed security practices throughout our rapid development lifecycle while maintaining velocity.
- Mentor security practices - Guide other engineers on secure coding, vulnerability remediation, and security‑first thinking.
Experience That Will Help You Succeed In This Role:
- Proficient in Golang.
- Production system builder with security focus - proven track record of architecting and building secure, large‑scale production applications and business‑facing platforms from the ground up.
- Ethical hacking and penetration testing expertise - hands‑on experience finding and exploiting vulnerabilities, conducting red team exercises, and thinking like an attacker to strengthen defenses.
- State‑of‑the‑art security engineering with Go, Python, JavaScript - you build both security tools and secure production systems in fast‑paced environments.
- HashiCorp Vault mastery - deep experience writing custom plugins, creating secrets engines, implementing dynamic credentials, and extending Vault functionality for enterprise‑scale secrets management.
- Enterprise authentication & authorization - designing and implementing OAuth, JWT, RBAC, and complex identity systems with fine‑grained access controls in business‑critical applications.
- API security and threat modelling - securing REST/GraphQL APIs, conducting threat assessments, and implementing advanced security patterns in high‑traffic production systems.
- AI/ML security and vulnerability research - understanding of LLM vulnerabilities, model security, prompt injection attacks, and AI‑specific threat vectors through hands‑on testing.
- Security automation and tooling – automating manual security processes.
- Cloud‑native security - securing containerized applications in Kubernetes, service mesh security, and cloud‑native security patterns at enterprise scale.
- Incident response and forensics - experience investigating, analyzing, and responding to security incidents in live production systems.
What We Believe In:
We do not have boundaries between security engineering and product development, and we expect all our technical staff to contribute to both as needed. We take a product‑focused approach to security and care about building solutions that are robust, scalable, and easy for developers to use. We enjoy working in a fast‑paced team tackling cutting‑edge security problems by constantly testing and learning. We enjoy pair programming for our security tools; we are lean in our approach and remove bureaucracy where we see it. We believe in delivering secure solutions fast, iterating and pivoting as we go, rather than defining the perfect security framework upfront.
What We’ll Provide You:
This is a unique role that will put you in the position to be part of a new venture and actively drive change. Every day there will be new challenges that will help you develop new skills that can drive your career. By joining Citi London, you will not only be part of a business casual workplace with a hybrid working model (up to 2 days working at home per week), but also receive a competitive base salary (which is annually reviewed), and enjoy a whole host of additional benefits such as:
- 27 days annual leave (plus bank holidays).
- A discretionary annual performance related bonus.
- Private Medical Care & Life Insurance.
- Employee Assistance Program.
- Pension Plan.
- Paid Parental Leave.
- Special discounts for employees, family, and friends.
Alongside these benefits Citi is committed to ensuring our workplace is where everyone feels comfortable coming to work as their whole self, every day. We want the best talent around the world to be energized to join us, motivated to stay and empowered to thrive.
Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.
Offensive Security Engineer - (SVP) employer: Citi
Contact Detail:
Citi Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Offensive Security Engineer - (SVP)
✨Tip Number 1
Network like a pro! Reach out to current employees at Citi through LinkedIn or other platforms. A friendly chat can give you insider info and might even lead to a referral, which is always a bonus!
✨Tip Number 2
Show off your skills! If you've worked on any AI security projects or ethical hacking exercises, make sure to discuss them in interviews. Real-world examples can set you apart from the crowd.
✨Tip Number 3
Prepare for technical challenges! Brush up on your Golang and security concepts, as you might face some hands-on tests. Practising coding problems and security scenarios can help you ace those tricky questions.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, you’ll have access to all the latest job openings and updates directly from Citi.
We think you need these skills to ace Offensive Security Engineer - (SVP)
Some tips for your application 🫡
Show Off Your Projects: When applying, make sure to highlight any AI engineering projects you've worked on, especially those involving LLMs. We want to see your creativity and technical skills in action!
Tailor Your Application: Don’t just send a generic application! Tailor your CV and cover letter to reflect the specific skills and experiences that match the Offensive Security Engineer role. We love seeing how you fit into our team!
Be Clear and Concise: Keep your application clear and to the point. Use bullet points for your achievements and make it easy for us to see why you’re the perfect fit for the job. We appreciate straightforward communication!
Apply Through Our Website: Make sure to apply through our official website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates from our team!
How to prepare for a job interview at Citi
✨Know Your Stuff
Make sure you brush up on your knowledge of Golang and security engineering. Be ready to discuss specific projects you've worked on, especially those involving AI and LLMs. This will show that you not only understand the technical aspects but also have hands-on experience.
✨Show Off Your Problem-Solving Skills
Prepare to tackle hypothetical scenarios during the interview. Think about how you would approach ethical hacking or penetration testing in a real-world situation. This will demonstrate your ability to think like an attacker and your readiness to secure applications effectively.
✨Emphasise Teamwork
Citi values collaboration, so be prepared to talk about your experiences with pair programming and mentoring others. Share examples of how you've worked with teams to embed security practices into development cycles, as this aligns with their 'shift left' security philosophy.
✨Ask Insightful Questions
At the end of the interview, don’t shy away from asking questions. Inquire about the team’s current challenges with AI security or how they implement security automation. This shows your genuine interest in the role and helps you gauge if it's the right fit for you.