LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
Forgot password?
Don't have an account?
or
Join Canary Wharfian
By signing up, you agree to our Terms & Conditions and Privacy Policy.
or

Senior Penetration Tester (Cyber Security) Vice President

ExperiencedNo visa sponsorship
Citi logo

at Citi

Bulge Bracket Investment Banks

Posted 3 days ago

No clicks

**Senior Penetration Tester (Cyber Security) Vice President** Lead Citi's offensive security efforts, utilizing extensive penetration testing, vulnerability research, and whitebox exploits. Key responsibilities involve sensitive vulnerability assessment, source code review, and tool development. Essential skills include deep technical expertise, in-depth knowledge of common vulnerabilities, proficiency in multiple programming languages, and proven ability to collaborate with development teams. Experience in a related role or relevant degree required. Hybrid work setup in Singapore.

Compensation
Not specified

Currency: Not specified

City
Singapore
Country
Singapore

Full Job Description

Senior Penetration Tester (Cyber Security) Vice President

Apply (opens in new window)
Save

Job Req Id:

26984754

Location(s):

Singapore, Singapore, Singapore

Job Type:

Hybrid

Posted:

Sep. 03, 2026

Discover your future at Citi

Working at Citi is far more than just a job. A career with us means joining a team of approximately 219,000 dedicated people from around the globe. At Citi, youll have the opportunity to grow your career, give back to your community and make a real impact.

Job Overview

Discover your future at Citi

Citi is a preeminent banking partner for institutions with cross-border needs, a global leader in wealth management, and a valued personal bank in its home market of the United States. Citi does business in more than 160 countries and jurisdictions, providing corporations, governments, investors, institutions, and individuals with a broad range of financial products and services.

About the job

Citi is seeking a highly skilled and experienced penetration tester with a specialized focus on vulnerability research, third-party component analysis, and advanced whitebox testing methodologies, including comprehensive source code review. The successful candidate will play a critical role in identifying, exploiting, and providing remediation guidance for complex security vulnerabilities within Citi's diverse technology landscape. This role demands deep technical expertise, a proactive approach to security challenges, and the ability to work collaboratively with development teams to enhance the security posture of our applications and infrastructure.

Who we are

This team specializes in conducting deep-dive penetration testing on a variety of Citi applications (Web, Mobile, Thick Client, and APIs) by manually identifying, researching, validating, and exploiting various known and unknown application security vulnerabilities.

What Youll Do

As a Senior Penetration Tester on our Offensive Security & Vulnerability Management team, you are responsible for:

  • Vulnerability Research & Exploitation: Conduct in-depth research to discover new attack vectors and zero-day vulnerabilities in enterprise applications, systems, and third-party components. Develop proof-of-concept exploits to effectively demonstrate risk.

  • Whitebox Penetration Testing: Perform comprehensive whitebox penetration tests, leveraging access to source code, design documentation, and internal system knowledge to uncover sophisticated security flaws that blackbox testing might miss.

  • Source Code Review: Conduct manual and automated source code reviews across various programming languages (e.g., Java, C#, Python, JavaScript) to identify security vulnerabilities, misconfigurations, and adherence to secure coding practices.

  • Third-Party Component Analysis: Evaluate the security of third-party libraries, frameworks, and open-source components integrated into Citi's applications. Identify known vulnerabilities (e.g., CVEs) and assess potential risks.

  • Remediation Guidance: Provide clear, concise, and actionable remediation recommendations to development teams, offering expert advice on secure coding, configuration, and architectural solutions.

  • Tooling & Automation: Utilize and contribute to the development of advanced security testing tools, AI-augmented static analysis, and dynamic analysis (DAST) solutions to improve efficiency and coverage.

  • Reporting & Communication: Prepare detailed technical reports outlining findings, risk levels, and recommended mitigations for both technical and non-technical audiences.

  • Stay Current: Continuously research and stay abreast of the latest security threats, vulnerabilities, attack techniques, and industry best practices.

Job Skills/Qualifications:

  • 6+ years of experience in penetration testing, ethical hacking, or application security, with a significant focus on whitebox testing and/or source code review.

  • Proven expertise in vulnerability research, including the ability to identify novel vulnerabilities and develop reliable exploits.

  • Strong proficiency in at least one major programming language (e.g., Java, C#, Python) and familiarity with others.

  • In-depth understanding of common web application vulnerabilities (OWASP Top 10) and API security best practices.

  • Experience with static application security testing (SAST) tools and dynamic application security testing (DAST) tools.

  • Excellent written and verbal communication skills, with the ability to articulate complex security issues to diverse audiences.

  • Ability to work independently and as part of a team in a fast-paced, dynamic environment.

  • Relevant industry certifications such as OSCE, GIAC GWAPT, GPEN, GXPN, or similar.

An ideal candidate will have both an engineering and security background. However, irrespective of your current role, if you have a Bachelors or Masters degree in Computer Science, Information Security, or a related field, or equivalent practical experience and meet most of the above-listed requirements, then don't miss this opportunity to join our team. Apply today!

------------------------------------------------------

Job Family Group:

Technology

------------------------------------------------------

Job Family:

Information Security

------------------------------------------------------

Time Type:

Full time

------------------------------------------------------

Most Relevant Skills

Please see the requirements listed above.

------------------------------------------------------

Other Relevant Skills

For complementary skills, please see above and/or contact the recruiter.

------------------------------------------------------

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi (opens in new window).

View Citis EEO Policy Statement (opens in new window) and the Know Your Rights (opens in new window) poster.

Apply (opens in new window)
Save

Senior Penetration Tester (Cyber Security) Vice President

Compensation

Not specified

City: Singapore

Country: Singapore

Citi logo
Bulge Bracket Investment Banks

3 days ago

No clicks

at Citi

ExperiencedNo visa sponsorship

**Senior Penetration Tester (Cyber Security) Vice President** Lead Citi's offensive security efforts, utilizing extensive penetration testing, vulnerability research, and whitebox exploits. Key responsibilities involve sensitive vulnerability assessment, source code review, and tool development. Essential skills include deep technical expertise, in-depth knowledge of common vulnerabilities, proficiency in multiple programming languages, and proven ability to collaborate with development teams. Experience in a related role or relevant degree required. Hybrid work setup in Singapore.

Full Job Description

Senior Penetration Tester (Cyber Security) Vice President

Apply (opens in new window)
Save

Job Req Id:

26984754

Location(s):

Singapore, Singapore, Singapore

Job Type:

Hybrid

Posted:

Sep. 03, 2026

Discover your future at Citi

Working at Citi is far more than just a job. A career with us means joining a team of approximately 219,000 dedicated people from around the globe. At Citi, youll have the opportunity to grow your career, give back to your community and make a real impact.

Job Overview

Discover your future at Citi

Citi is a preeminent banking partner for institutions with cross-border needs, a global leader in wealth management, and a valued personal bank in its home market of the United States. Citi does business in more than 160 countries and jurisdictions, providing corporations, governments, investors, institutions, and individuals with a broad range of financial products and services.

About the job

Citi is seeking a highly skilled and experienced penetration tester with a specialized focus on vulnerability research, third-party component analysis, and advanced whitebox testing methodologies, including comprehensive source code review. The successful candidate will play a critical role in identifying, exploiting, and providing remediation guidance for complex security vulnerabilities within Citi's diverse technology landscape. This role demands deep technical expertise, a proactive approach to security challenges, and the ability to work collaboratively with development teams to enhance the security posture of our applications and infrastructure.

Who we are

This team specializes in conducting deep-dive penetration testing on a variety of Citi applications (Web, Mobile, Thick Client, and APIs) by manually identifying, researching, validating, and exploiting various known and unknown application security vulnerabilities.

What Youll Do

As a Senior Penetration Tester on our Offensive Security & Vulnerability Management team, you are responsible for:

  • Vulnerability Research & Exploitation: Conduct in-depth research to discover new attack vectors and zero-day vulnerabilities in enterprise applications, systems, and third-party components. Develop proof-of-concept exploits to effectively demonstrate risk.

  • Whitebox Penetration Testing: Perform comprehensive whitebox penetration tests, leveraging access to source code, design documentation, and internal system knowledge to uncover sophisticated security flaws that blackbox testing might miss.

  • Source Code Review: Conduct manual and automated source code reviews across various programming languages (e.g., Java, C#, Python, JavaScript) to identify security vulnerabilities, misconfigurations, and adherence to secure coding practices.

  • Third-Party Component Analysis: Evaluate the security of third-party libraries, frameworks, and open-source components integrated into Citi's applications. Identify known vulnerabilities (e.g., CVEs) and assess potential risks.

  • Remediation Guidance: Provide clear, concise, and actionable remediation recommendations to development teams, offering expert advice on secure coding, configuration, and architectural solutions.

  • Tooling & Automation: Utilize and contribute to the development of advanced security testing tools, AI-augmented static analysis, and dynamic analysis (DAST) solutions to improve efficiency and coverage.

  • Reporting & Communication: Prepare detailed technical reports outlining findings, risk levels, and recommended mitigations for both technical and non-technical audiences.

  • Stay Current: Continuously research and stay abreast of the latest security threats, vulnerabilities, attack techniques, and industry best practices.

Job Skills/Qualifications:

  • 6+ years of experience in penetration testing, ethical hacking, or application security, with a significant focus on whitebox testing and/or source code review.

  • Proven expertise in vulnerability research, including the ability to identify novel vulnerabilities and develop reliable exploits.

  • Strong proficiency in at least one major programming language (e.g., Java, C#, Python) and familiarity with others.

  • In-depth understanding of common web application vulnerabilities (OWASP Top 10) and API security best practices.

  • Experience with static application security testing (SAST) tools and dynamic application security testing (DAST) tools.

  • Excellent written and verbal communication skills, with the ability to articulate complex security issues to diverse audiences.

  • Ability to work independently and as part of a team in a fast-paced, dynamic environment.

  • Relevant industry certifications such as OSCE, GIAC GWAPT, GPEN, GXPN, or similar.

An ideal candidate will have both an engineering and security background. However, irrespective of your current role, if you have a Bachelors or Masters degree in Computer Science, Information Security, or a related field, or equivalent practical experience and meet most of the above-listed requirements, then don't miss this opportunity to join our team. Apply today!

------------------------------------------------------

Job Family Group:

Technology

------------------------------------------------------

Job Family:

Information Security

------------------------------------------------------

Time Type:

Full time

------------------------------------------------------

Most Relevant Skills

Please see the requirements listed above.

------------------------------------------------------

Other Relevant Skills

For complementary skills, please see above and/or contact the recruiter.

------------------------------------------------------

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi (opens in new window).

View Citis EEO Policy Statement (opens in new window) and the Know Your Rights (opens in new window) poster.

Apply (opens in new window)
Save