Head of Cybersecurity Technology & AI Security Engineering
Role details
Job location
Tech stack
Job description
The Head of Cybersecurity Technology&AI SecurityEngineeringis an executive level position responsible for delivering technology solutions in support of Citi'score cybersecurity teams, includingthe critical cybersecurity operations organization. This includes overseeing architecture, product management,engineeringand technology operations for the tools and products that help deliver our core cybersecurity capabilities.In addition, the role leads the AI security engineering capability toleverageAI to transform the way cybersecurity capabilities and services are delivered and to empower an AI led cyber workforce.Thisrole reports to theChief Information Security Officer: Business, Functions & Technology(BFT).The person must be a strong leader, with deep integrity and ethics, and understand the power inhuman centeredleadership and the potential of high performing teams., * You default to engineering solutions over checkbox compliance.
-
You default to engineering solutions to problems vspurchasingtools
-
You attract talent because people want to workwithyou, notforyou.
-
You treat threat intelligence as an input to action, not a report.
-
You'vecontributed to or activelyleverageopen-source security tooling - you understand the community, not just the vendor landscape.
-
You'veoperatedsuccessfullyinchallengingenvironments and have themedals andscars to prove it.
Why This Role Is Different
Thisisn'ta CISO seat whereyou'llspend your timeinadministration.You will be expected to be close to the work - to understand the code, the architecture, the threats, and find solutions.You'llhave the mandate and the backing to build something meaningful. We want a leader who makes security a competitive advantage.
Responsibilities:
-
Build,mentorand inspire a high performing cybersecurity team, growing both the current and the next generation of leadership talent
-
Lay outa clear visionfor Cybersecurity Technology in partnership with the leaders of Cyber Security Operations, BFT-CISO, and Cyber Risk and Controls.
-
Lead significant initiatives within and help deliver the CISO and BFT cyber strategies, and securely enable business and technology activities and programs
-
Work with the assigned Enterprise Security Architects,vendorsand engineers to develop and document an effective architecture that aligns with Citi's architecture principles and overall Enterprise Architecture.
-
Lead a product mgmt. function that engages stakeholders toprioritize features and capabilities in the Cybersecurity Technology roadmap, delivering value anduser experience.
-
Build an AI capability thatmaintainsan "agent first" mindset to solve security problems
-
Manage the budget, resource planning, and delivery of end results through executing the functional strategy
-
Leverage the team to rapidly respond to emerging threats, securityincidentsand critical business activities
-
Lead and securely enable significant business change in complex global environments, managing complex multiple risk dimensions
-
Partner with peer leadership to drive cyber strategy and unify global processes and functions
-
Implement an effective problem management process toidentifyrecurring issues or potential upcoming issues toassurethe long-term effectiveness of the environment.
-
Maintain a responsiblecompliance program
Requirements
-
Deep, demonstrable experience leading security engineering and operations at scale - not just policy and governance.
-
A track recordof building and mentoring high-performing, diverse security teams.
-
Hands-on fluency across cloud-native architectures (Kubernetes, Terraform, service mesh), modern CI/CD, and infrastructure-as-code.
-
A sharp understanding of the AI threat landscape, including risks specific to generative AI and large language models.
-
Experienceoperatingor transforming a SOC - with a bias toward automation, detection engineering, and measurable outcomes.
-
Strong DFIR fundamentals and the ability to lead under pressure during major incidents.
-
Active engagement with the open-source security community - whether as a contributor, maintainer, or power user of projects like Sigma, Velociraptor, Falco, MISP,Semgrep, or similar.
-
The ability to communicate risk to boards and business leaders withoutreliance onjargon or frameworks., * 15+ years of relevant experience in an Engineering rolein the cybersecurity, digital or AI fields
-
Experience working in Financial Servicesor Technologyor a large complex and/or global environment
-
Comprehensive knowledge of design metrics, analytics tools, benchmarkingactivitiesand related reporting toidentifybest practices
-
Proventrack recordofbuilding and running resilient service driven technology capabilities
-
Demonstrated use of driving AI delivery and engineering to transform capabilities and services to deliver value tocustomers and stakeholders
-
Proven ability to engage and influence senior stakeholders across business, risk, technology, and governance functions in a banking context.
-
Demonstrated success in building, leading, and scaling global cybersecurity teams