The Role:
Citi is looking for a security focused person with a good understanding of cybersecurity principles to work in the Cloud Threat Modeling team. Using threat modeling you will identify threats and specify mitigating controls which will directly reduce the risk of Citi operating in the public cloud.
Responsibilities
- Perform Threat Modeling using a documented process
- Development of automation tools as required
- Maintain a high standard of work in identifying threats and specifying mitigating controls
- Attending to the lifecycle of identified threats and controls
- Delivery of threat models and supporting tasks within existing timeframes
- Provide feedback, support, and improvements to the existing threat modeling process
- Present work to seniors, the team, and other technical teams
Qualifications
The ideal candidate is expected to have at least1-2 years’experience inseveralof the following technologies/processes:
- Jira or other ticketing systems – must
- Experience working in a cyber-security role – must
- Security practices pertaining to authentication, authorization, logging/monitoring, encryption, infrastructure security, network/segmentation – must
- Experience with Scripting languages or Infrastructure as Code (Terraform, CloudFormation) – must
- Threat Modeling (STRIDE, PASTA, Attack trees, tooling, Att&ck)
- Identifying vulnerabilities using CWE or OWASP
- Operating systems and their hardening
- Development concepts (such as: CICD, Pipelines, SDLC)
- Cloud Development Kit (CDK), GitOps
- Operating in a DevOps / agile team structure
- Understanding of docker/K8S/serverless/helm
- Support or perform pen testing
- Snowflake/MongoDB/Terraform Cloud/GitHub/Databricks
- Design and review technical architectures
- Analytical, diligence and attention to detail
- Eagerness to research using vendor documentation
- Create and maintain quality documentation
- Experience of regulated environment
- Adversary mindset
- Work with diverse set of people and teams
- Constant learner of new technologies and methodologies
- Relationship building across multiple cross-functional teams
Education
- Bachelor's degree in computer related field or equivalent work experience
- Ideal candidate is expected to have afoundationalorpractitionerlevel cloud certification from either AWS, GCP or Azure
- Ideal candidate is also expected to have a foundational cyber-security certification (defined below):
Foundational or practitioner level cloud certification
- AWS Certified Cloud Practitioner
- CompTIA Cloud Essentials+, CompTIA Network+
- Google Cloud Digital Leader
- Oracle Cloud Infrastructure Foundations Certified Associate
- Microsoft Certified: Azure Fundamentals
Foundational cyber-security certification
- ISACA Cybersecurity Fundamentals
- GIAC Information Security Fundamentals (GISF)
- Associate of ISC2
- CompTIA Security+
- Microsoft Certified: Security, Compliance, and Identity Fundamentals
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
Information SecurityFull timeIrving Texas United States$96,400.00 - $144,600.00
Anticipated Posting Close Date:
Nov 07, 2024View the " " poster. View the .
View the .
View the