368,958open jobs
9,466companies
48,032added this week
Browse all
Salary
$117k – $176k per year
Location
Remote/Hybrid (Tampa, United States)
Seniority
Staff · 6+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Citi is a leading global financial services company headquartered in New York City, offering a broad range of banking, investment, and wealth management services to consumers, corporations, and institutions. As one of the world's largest banking institutions, it operates across more than 160 countries and jurisdictions, serving as a critical facilitator of global commerce. Through its primary consumer division, Citibank, alongside its institutional businesses, the company provides everyday banking, credit cards, capital markets solutions, and cross-border payment infrastructure worldwide.

We're looking for a sharp, drivenIntelligence Lead Analyst to join a team that doesn't just analyze intelligence - itbuilds the tools that collect it.

In this senior-level role, you'll take ownership of maintaining and enhancing our link analysis frameworks while engineering in-house solutions to automate intelligence collection at scale. Your work will directly shape how we identify, pursue, and neutralize threats across one of the world's largest financial institutions.

This role is fundamentally about two things: CyberOSINT mastery andtechnical innovation. If you thrive at the intersection of intelligence analysis and software development, this is your opportunity.

CSIS Intelligence Advanced Analytics and Cyber OSINT - Program Description

Citi Security and Investigative Services (CSIS) is a full-service security and investigative team that protects the assets, integrity, and reputation of Citi and its clients as the industry-leading provider of security, investigations, and intelligence. The CSIS Advanced Analytics and Cyber OSINT program delivers timely, actionable intelligence to Citi stakeholders through collection and analysis using both open-source and internal data sources, supporting complex financial crime investigations, cyber-enabled fraud matters, and high-risk security events. The program drives efficiencies through the creation, integration, and deployment of custom analytical tools and intelligence capabilities into the hands of analysts and investigators across the enterprise.

Job Description:

The Intelligence Senior Analyst is an senior-level position responsible for collection/analysis of IoCs and TTPs, maintaining and updating existing link analysis frameworks while also developing in-house solutions to automate intelligence collection. The primary objective of this role is to leverage Open Source Intelligence (OSINT) and development skills to build and operate advanced intelligence capabilities. While familiarity with the cyber domain is welcome, the core focus is on OSINT analysis and the creation of automated collection tools.

Responsibilities:

  • Fulfill cyber OSINT requests by applying advanced analysis tools and techniques to surface timely, actionable intelligence.

  • Proactively anticipate gaps in our intelligence posture and develop innovative solutions, collaborating with internal and external stakeholders on open-source methodologies and tooling.

  • Design (develop), implement, and maintain in-house solutions for collecting, processing, and analyzing open source data.

  • Automate intelligence collection capabilities, leveraging existing link analysis frameworks and actively identifying and evaluating alternative solution providers.

  • Apply in-depth disciplinary knowledge to triage, process, and analyze intelligence alerts, reports, and briefings.

  • Engage in liaison activities with developers, intelligence communities, law enforcement, industry partners, peer financial institutions, and information sharing communities.

  • Manage multiple projects simultaneously with a proactive, self-motivated approach, ensuring timely delivery of high-quality results while collaborating effectively with global teams.

  • Complete the daily operational components of the intelligence mission.

  • Assume an informal/formal mentor role within teams and assist with the coaching and training of new team members.

Qualifications:

  • 6-10 years of relevant experience

  • Should have a working knowledge in one or more of the following areas: Advanced Persistent Threat, Third Party Risks/Threats, Cybercrime, Extremist Groups and Cyber Terrorists, Hacktivism, Distributed Denial of Service attacks, Fraud, Malware, Mobile Threats

  • Proven track record of operationalizing cyber threat intelligence - translating raw intelligence into detections, hunt packages, and risk-relevant reporting.

  • Consistently demonstrates clear and concise written and verbal communication

  • Proven influencing and relationship management skills

  • Proven analytical skills

Education:

  • Bachelor’s degree/University degree or equivalent experience

  • Master’s degree preferred (Advanced degree preferred, ideally in Computer Science, Cybersecurity, Information Security, or a related STEM discipline)

  • Additional valued certifications include: CREST CCTIM, Recorded Future Certified Analyst, CISSP, CEH, or OSCP.

Required Skills:

  • Proficiency in the MITRE ATT&CK framework - mapping adversary TTPs, building hunt hypotheses, and driving detection coverage analysis.

  • Hands-on experience with Threat Intelligence Platforms including Recorded Future, Mandiant Advantage, ThreatConnect, MISP, or OpenCTI.

  • Experience with scripting and automation languages including Python, PowerShell, and Bash for intelligence collection, enrichment pipelines, and hunt tooling development.

  • Advanced OSINT tradecraft including dark web monitoring, social media intelligence, infrastructure pivoting, and digital footprint analysis.

  • Experience with link analysis platforms such as Palantir, Maltego, and i2 Analyst's Notebook, including building custom extractors, web scrapers, and automation workflows to support investigative and analytical tasks.

  • Solid understanding of network forensics, log analysis, and reverse engineering in support of hunt operations.

  • Working knowledge of malware analysis (static and dynamic) and adversary infrastructure analysis.

  • Exceptional written and verbal communication skills with the ability to produce intelligence products for both technical and executive audiences, consistently demonstrating clarity, conciseness, and attention to detail.

  • Proven influencing, relationship management, and analytical skills with a track record of driving outcomes across cross-functional teams.

This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.

------------------------------------------------------

Job Family Group:

Technology

------------------------------------------------------

Job Family:

Information Security

------------------------------------------------------

Time Type:

Full time

------------------------------------------------------

Primary Location:

NC-CHARLOTTE (BALLANTYNE)

------------------------------------------------------

Primary Location Full Time Salary Range:

$117,440.00 - $176,160.00

In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.

------------------------------------------------------

Most Relevant Skills

Please see the requirements listed above.

------------------------------------------------------

Other Relevant Skills

For complementary skills, please see above and/or contact the recruiter.

------------------------------------------------------

Anticipated Posting Close Date:

Sep 02, 2026

------------------------------------------------------

Automated Processing and AI

We use automated processing, including artificial intelligence, for our legitimate business interests (or our reasonable and appropriate business purposes) to identify and align the candidate's skills and abilities with a specific job opening. Additionally, if you so choose, or consent, we can match your skills and abilities to other suitable roles at Citi.

Importantly, all our hiring processes and decisions, including determining your suitability for a role, are conducted, checked, and decided by individuals. Our automated processing and AI do not involve relying on automatic or autonomous decision-making. Please refer to any Jurisdictional Considerations, with specific provisions for your country (where relevant) for further details.

Illinois residents - AI Notice and Right

------------------------------------------------------

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.

View Citi’s EEO Policy Statement and the Know Your Rights poster.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,958 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Tampa
Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Riga
PowerShell
Python
DevOps
AWS
Azure
Azure AKS
Azure DevOps
Bicep
CI/CD
Configuration Management
Docker
FinOps
GCP
Git
GitLab
Jenkins
Kubernetes
Terraform
Apply
$60k – $108k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • United States
PowerShell
Python
DevOps
AWS
Azure
IAM
Splunk
Cybersecurity
Crowdstrike
ISO 27001
Microsoft Defender
Microsoft Entra ID
Microsoft Sentinel
NIST CSF
Qualys Cloud Platform
Apply
$16k – $34k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Mumbai • Bengaluru
JavaScript
PowerShell
SQL
C#
C#
.NET
Databases
Azure SQL Database
MS SQL
DevOps
Azure
Rest API
Cybersecurity
Microsoft Entra ID
QA
Postman
Swagger
Apply
$33k – $85k per year (Estimated) • Remote/Hybrid • Full-Time • Brazil
PowerShell
DevOps
Azure
IAM
Cybersecurity
CyberArk
Microsoft Entra ID
Apply
$90k – $184k per year (Estimated) • Equity • Remote • Full-Time • 3+ years exp • United States
AI/ML
Red Teaming
Cybersecurity
Burp Suite
Cobalt Strike
Crowdstrike
Metasploit
MITRE ATT&CK
Nessus
Nmap
Apply
$24k – $54k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Mexico City
Apply
$139k – $208k per year • Remote/Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • Irving
Management
Confluence
Apply
$35k – $77k per year (Estimated) • Remote/Hybrid • Full-Time • Warsaw
Apply
$23k – $53k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Guadalajara
SQL
Apply
$23k – $53k per year (Estimated) • In office • Full-Time • Mexico City
SQL
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$118k – $162k per year • Remote • Full-Time • 10+ years exp • Bachelor's Degree • Louisville • Fort Lauderdale • Washington • Chicago • Tampa
DevOps
Azure
GCP
Cybersecurity
HIPAA
Apply
$133k – $262k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Tampa
Apply
$110k – $201k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Tampa
DevOps
SLI/SLO/SLA
Apply
$91k – $177k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Tampa • Arlington
PowerShell
SQL
Java
Java
Apache Tomcat
Databases
MS SQL
MySQL
PostgreSQL
AI/ML
Copilot
DevOps
Azure
CentOS Stream
Hyper-V
Kubernetes
Nagios
Nginx
SLI/SLO/SLA
Ubuntu
VMWare
Apply
See all jobs
This is one of many
368,958 more open roles from verified company boards, updated every day.