Artificial Intelligence (AI) Offensive Security Analyst at Citi
Tampa, FL
$87,280–$212,160from the description
Aug 4, 2026
Tampa, FL
Sep 24, 2026
What this job asks for AI summary
An offensive security practitioner role within Citi's CISO organization, focused on running penetration tests, vulnerability assessments, and red team evaluations against AI systems — including GenAI applications, LLM-backed products, and agentic systems. The role also involves building and using AI-powered security testing tooling to improve coverage and efficiency. Multiple seniority levels are available, from AVP through SVP, suited to candidates with 5–10+ years of hands-on security testing experience.
Senior level · 5+ years · Tampa-St. Petersburg-Clearwater, FL · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 15 people in the Tampa-St. Petersburg-Clearwater, FL area plausibly meet what this posting asks for (information security analysts). range 6–25
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
What the occupation pays Median $121,586 (middle half $89,036–$154,361). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 6, 2026. It is a model, not a headcount.
Why we read it this way (7)
The posting covers multiple seniority levels (AVP/C12 at 5-7+ years, VP/C13 at 8-10+ years, SVP/C14 at 10+ years). The advertised title 'AI Offensive Security Analyst' carries no explicit level, but the role framing and the lowest qualifying band (AVP, 5-7+ years) anchor the floor at Senior. The wide salary range ($87,280–$212,160) reflects this multi-level structure.
A Bachelor's degree in CS, Information Security, or Engineering is listed, but the posting explicitly accepts 'equivalent practical experience' as a substitute, so no hard degree gate is set.
Burp Suite is the named primary tool; nuclei and nmap are listed alongside it as 'or similar' alternatives and are captured in the alternatives array rather than as separate required skills.
OWASP LLM Top 10 and MITRE ATLAS appear together as 'at least some exposure to' — framed as a single soft requirement rather than a hard gate; listed as preferred.
AI testing frameworks (Garak, PyRIT, PromptBench, Inspect AI) are explicitly called 'a real plus' in the posting, confirming preferred status.
The alt SOC (15-1252 Software Developers) is noted because the role explicitly involves building security tooling and pipelines from scratch, giving it a meaningful engineering dimension alongside the primary security-analysis work.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): OWASP LLM Top 10.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.