Citi is a global financial institution operating across more than 180 countries and jurisdictions, with a history spanning over 200 years. Its cybersecurity teams defend a massive attack surface that spans banking, financial services, wealth management, markets, and consumer cards. The threat model here isn't theoretical - think nation-state actors targeting cross-border payment rails, credential-stuffing campaigns against consumer accounts, and supply-chain risks embedded in the fintech ecosystem.
The security organization operates across a sprawling geographic and business footprint, requiring teams that can navigate incident response across time zones, secure cloud and on-prem hybrid infrastructure, and enforce consistent policy in a heavily regulated environment. Citi's five core business lines - Services, Markets, Banking and International, Wealth, and U.S. Consumer Cards - each present distinct risk profiles and regulatory obligations that shape how security engineering, threat detection, and governance functions are structured.
The company emphasizes diverse perspectives within its workforce and supports career mobility across local and international offices. For cybersecurity professionals, the scale translates into exposure to real-world threat intelligence, fraud analytics, identity and access management at massive scale, and the complexity of defending critical financial infrastructure that connects millions of clients globally.





