Senior Application Security Analyst, VP jobs in United States
cer-icon
Apply on Employer Site
company-logo

Citi · 4 hours ago

Senior Application Security Analyst, VP

Citi, the leading global bank, is seeking a Senior Application Security Analyst (VP) to support Application Security Programs within their Cybersecurity organization. The role involves performing deep-dive manual source code reviews and guiding stakeholders on secure coding practices while integrating security controls into the software development lifecycle.

BankingFinanceFinancial Services
check
H1B Sponsor Likelynote

Responsibilities

Perform static application security testing (SAST) and manual source code reviews (Java-focused) to identify vulnerabilities, malicious code, and hardcoded secrets
Review and validate automated scan results, prioritize remediation based on risk, and provide actionable guidance
Develop custom detection rules for secrets and malicious code
Collaborate with development teams to ensure timely remediation and promote secure coding and secrets management best practices
Design and implement AI/ML-driven utilities to enhance code analysis and automate detection of secrets and vulnerabilities
Prepare formal security assessment reports using standard templates
Research emerging threats, tools, and methodologies to continuously improve detection capabilities
Mentor junior team members and contribute to knowledge sharing within the security organization

Qualification

SASTJava developmentApplication security principlesSecrets managementDevSecOpsSAST toolsAI/ML skills.NETPythonDynamic Application Security TestingFortifySnykBurp Suite

Required

6+ years of experience in secure software development, or SAST
Strong understanding of application security principles, common vulnerabilities (OWASP Top 10, CWE), and secure coding practices
Hands-on development experience in Java/J2EE (required); experience with other enterprise languages such as C#, .NET, Python, or JavaScript is a plus
Familiarity with DevSecOps practices, CI/CD pipelines, and integrating security tools into the SDLC
Experience with SAST tools (e.g., Fortify, Checkmarx) and manual code review techniques
Knowledge of secrets management best practices and detection tools
Exposure to AI/ML concepts for security automation is a plus
Bachelor's degree or equivalent experience in Computer Science, Information Security, or a related field

Preferred

Secrets Scanning and secrets management best practices
DevSecOps principles and CI/CD integration
AI/ML skills for security automation
Experience with .NET, Python, or other enterprise languages
Familiarity with security tools such as Fortify, Snyk, Burp Suite
Knowledge of DAST (Dynamic Application Security Testing) is a plus

Benefits

Medical, dental & vision coverage
401(k)
Life, accident, and disability insurance
Wellness programs
Paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays

Company

Citi's mission is to serve as a trusted partner to our clients by responsibly providing financial services that enable growth and economic progress.

H1B Sponsorship

Citi has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (1386)
2024 (849)
2023 (1375)
2022 (1117)
2021 (876)
2020 (901)

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
James Monahan
Managing Director / Global Head of Asset Servicing
linkedin
leader-logo
Naveed Sultan
Managing Director, Chairman, Institutional Clients Group
linkedin
Company data provided by crunchbase