The Team:The Chief Information Security Office (CISO) is home to deeply talented colleagues that work to ensure the safety of Citi's clients, our revenue, our employees and our proprietary data. We manage information security as one end-to-end program - one with a clear mandate and accountability. Our mission is a program that is fully anchored to modern control and architectural frameworks, is fully aligned with the enterprise architecture of the firm and is deeply integrated into the sectors and functions. This role is a key leadership position within our Cybersecurity Fusion Center (CSFC).
The Role:Citigroup seeks an experienced, proactive, and innovative
Director of Cybersecurity Insider Threat. This senior leadership position is a critical part of the Cybersecurity Fusion Center (CSFC) within the CISO organization, reporting directly to the Head of the CSFC, a Managing Director.
This role is critical to reducing risk to the firm, with a significant focus on leveraging Artificial Intelligence (AI) to address the new and evolving threat landscape. The Director will be responsible for the strategic refinement and implementation of a new, data-centric process to better protect the firm against insider risk. This position requires strong leadership, strategic vision, and the ability to drive transformative change across the organization. The role will involve collaboration with peers across the firm to co-lead the Insider Threat Coordination Program (ITCP).
Key ResponsibilitiesThe Director of Insider Threat will manage and optimize key insider threat capabilities, including:
- Program Strategy and Leadership: Define and execute the strategic vision for the enterprise Insider Threat program, aligned with organizational risk tolerance and business objectives. Provide strong leadership, strategic direction, and development for the insider threat team.
- AI-Driven Threat Mitigation: Drive the strategy for leveraging AI and advanced data analytics to enhance the detection, analysis, and mitigation of insider threats, with a specific focus on addressing the new risks associated with AI.
- Process Innovation & Refinement: Lead the design, refinement, and implementation of a new, data-centric process to better protect the firm against the risk of insiders, ensuring the program remains adaptive to emerging threats.
- Insider Threat Program Development & Execution: Design, mature, and sustain an enterprise insider threat program, including detection, triage, response, and mitigation capabilities. Integrate behavioral, technical, and contextual indicators to enable a holistic and risk-based approach.
- Stakeholder and Industry Engagement: Serve as a trusted advisor on insider threat to senior leadership, legal, HR, compliance, risk, cyber, and other partners. Engage with industry peers, forums, and intelligence-sharing groups to benchmark programs, identify emerging trends, and adopt leading practices.
- Governance, Risk, and Compliance: Contribute to enterprise governance, risk management, and control frameworks related to insider threat. Ensure appropriate oversight, metrics, and reporting mechanisms are in place to demonstrate program effectiveness and risk reduction.
Qualifications- Experience: 15+ years' experience in cybersecurity, insider threat, or relevant experience as detailed below with significant experience leading investigative, intelligence, or insider threat functions within an enterprise corporate, government, and regulated environment.
- Leadership & Strategy: Proven track record of defining and executing strategic vision for a major security program. 15+ years' experience in people management with multiple direct reports. Demonstrated success in building, leading, and mentoring high-performing, multidisciplinary teams.
- Technical Acumen: Strong understanding of the insider threat landscape, attack vectors, and mitigation strategies. Proven experience designing, implementing, or maturing insider threat detection and mitigation programs. A strong focus on data and familiarity with leveraging AI/ML for security solutions is required.
- Communication & Influence: Strong ability to synthesize complex and sensitive information into actionable mitigation strategies and executive-level communications. Experience engaging senior stakeholders and influencing outcomes through collaboration and credible risk-based insights.
- Work Environment: Ability to work effectively and lead teams in a fast-paced, high-pressure, global environment.
Skills ProfileLeadership & Strategic Vision- Cybersecurity Leadership: Demonstrated ability to lead and motivate cybersecurity teams, manage complex projects, and contribute to the firm's strategic direction under pressure.
- Strategic Thinking: Capacity to develop and implement a comprehensive Insider Threat strategy aligned with business objectives, risk appetite, and industry best practices.
- Transformation & Innovation: Experience leading large-scale cyber and digital transformations, with a focus on data and AI. Fosters a culture of innovation and continuous improvement.
Cybersecurity Operations Expertise- Insider Threat Program Management: Expertise in managing the full lifecycle of an insider threat program, including identification, assessment, prioritization, and remediation.
- Threat Intelligence & Analytics: Strong understanding of cyber threat intelligence principles and practices, including experience with threat intelligence platforms and cyber data analytics to identify and analyze insider threats.
- Incident Response & Crisis Leadership: Experience supporting complex incident response and crisis management activities, demonstrating decisive decision-making and effective communication in high-stakes situations.
Technical Acumen & Innovation- Emerging Technologies: Deep familiarity with emerging security technologies, including ML/AI-driven security solutions, and the ability to evaluate and implement innovative solutions to address the evolving threat landscape.
- Data-Driven Analysis: Expertise in using data analytics to drive security decisions, refine detection models, and measure program effectiveness.
Collaboration & Partnership- Cross-Functional Collaboration: Proven ability to collaborate effectively with diverse stakeholders, including technology teams, business functions, and management across different regions.
- External Partnerships: Experience building and supporting relationships with external partners, including industry peers, vendors, and government agencies.
Education- Bachelor's degree/University degree in Computer Science, Software Engineering, Information Security, related field or equivalent experience
- Master's degree preferred
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
Job Family Group: Technology
Job Family:Information Security
Time Type:Full time
Primary Location:Tampa Florida United States
Primary Location Full Time Salary Range:$170,000.00 - $300,000.00
In addition to salary, Citi's offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.
Most Relevant Skills Please see the requirements listed above.
Other Relevant Skills For complementary skills, please see above and/or contact the recruiter.
Anticipated Posting Close Date:Sep 02, 2026
Automated Processing and AIWe use automated processing, including artificial intelligence, for our legitimate business interests (or our reasonable and appropriate business purposes) to identify and align the candidate's skills and abilities with a specific job opening. Additionally, if you so choose, or consent, we can match your skills and abilities to other suitable roles at Citi.
Importantly, all our hiring processes and decisions, including determining your suitability for a role, are conducted, checked, and decided by individuals. Our automated processing and AI do not involve relying on automatic or autonomous decision-making. Please refer to any Jurisdictional Considerations, with specific provisions for your country (where relevant) for further details.