Cloud Security Incident Responder (VP)
CitiAbout the role
About Citi:
Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.
As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients’ best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first-class customer experience. We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services.
Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We’ll enable growth and progress together.
Citi’s Cloud Incident Response (Cloud IR) team seeks a Cloud Incident Responder to own the assigned security incidents that occur within Citi’s public cloud environments. You will work closely with stakeholders to ensure effective security incident response with an aim to safeguard the integrity of services and data within Citi’s public cloud platforms. Your role is critical in ensuring a proactive and coordinated approach in responding to cloud security incidents and managing security risks in a timely and effective manner. You will align your objectives with the wider Cyber Security Operations priorities at Citi while owning the evolution of our processes, procedures and tools to ensure the firm is ready to tackle critical security incident response challenges within the cloud ecosystem.
Responsibilities
Related activities include but are not limited to:
Lead and/or support in-depth triage and investigations of assigned cyber incidents in cloud.
Perform incident response functions including but not limited to
Detailed cloud focused investigations by analyzing logs relevant to the underlying cloud service provider (CSP)
Execution of automation to gather forensic artifacts such as memory, disk, etc. for in-depth analysis and investigations.
Execution of cloud-native automation to run resource containment actions as relevant to sources of compromise and/or malicious activities in scope.
Conduct host-based analytical functions (e.g. digital forensics, metadata and data analysis) to uncover Indicators of Compromise (IOCs) and/or Tactics, Techniques and Procedures (TTPs)
Documentation of investigation analysis objectively capturing the Who, What, When, Where, Why and How related to the incident
Develop, document and maintain operationally effective playbooks to deal with cloud-based incidents.
Take ownership for and drive the development of new automation capabilities and supporting playbooks as per assigned domains within cloud.
Work with application and infrastructure stakeholders to identify key components and information sources such as cloud environments, instances, middleware, applications, databases, logs, etc.
Collaborate with global multidisciplinary groups for triaging, defining the scope and investigating large-scale security incidents.
Build and nurture key stakeholder relationships with partners in the CISO business function that are essential to the IR team success.
Actively participate in Threat modeling of new services/capabilities, readiness exercises such as purple team, tabletops, CTF’s etc.
This role requires occasional flexibility to support critical security incidents when they occur out of regular office hours
Qualifications:
Strong technical expertise in relevant Cloud securi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s