$87,280 – $212,160
Listed on Citigroup’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
This role combines offensive security testing expertise with AI system evaluation, requiring practitioners to assess vulnerabilities in AI applications while leveraging AI tools to enhance penetration testing and vulnerability management. It suits security professionals with hands-on testing experience who are curious about AI safety and comfortable building solutions in an emerging domain without established playbooks.
Our summary, not Citigroup’s wording. The full posting is on their site.
Skills this role names
Log in to see which of these are already on your profile.
What they ask for
Required
- Practical penetration testing or vulnerability assessment experience against web applications, APIs, or mobile applications
- Familiarity with common security testing tools such as Burp Suite, nuclei, or nmap
- Working knowledge of OWASP Top 10 and exposure to OWASP LLM Top 10 or MITRE ATLAS
- Ability to triage findings and communicate risk clearly
- Hands-on experience using LLM tools for security testing, research, or workflows
- Understanding of how LLMs work including context windows, tool use, RAG, and agentic chaining
- Ability to write clearly including test plans, findings reports, and risk summaries
- Comfortable working on problems without established playbooks
- Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience
Nice to have
- Familiarity with AI testing tools or frameworks such as Garak, PyRIT, PromptBench, or Inspect AI
- Red Team experience running adversary simulations
- Master's degree