Skip to content

Open nowPosted yesterday

VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2)

Citi3,636 open roles

Where
Irving Texas United States
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowVP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2)Citi · Irving Texas United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Citi's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Citi postings stay open a median of 23 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted yesterday

Citi median: 23 days open

The posting

The SOC Analyst (L2) performs continuous monitoring, initial triage, and in-depth analysis of security events across endpoint, network, email, big data, and web telemetry and behavior anomaly detection tools. This role provides high-quality documentation and escalation to Incident Response, while also performing Level 2 peer review analysis to ensure accuracy, thoroughness, and adherence to established procedures across the L1 team.

The L2 analyst leads education and training efforts for L1 analysts, serving as a formal mentor and technical lead. They are responsible for identifying and triaging service outages and log discrepancies, proactively addressing potential data visibility issues. The L2 analyst plays a critical role in designing and implementing new security use cases, conducting content reviews, drafting required Business Requirements Documents (BRDs), and monitoring use case performance to identify over-alerting or underperforming content.

Furthermore, the L2 analyst attends, leads, and organizes cross-organizational communications and conference calls, acting as a key liaison between the SOC and other business units. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with enterprise data security policy, while also driving strategic improvements, automation enablement, and mentorship within the SOC team.

Primary Framework Alignment

  • NICE Workforce Framework: Defensive Cybersecurity - Level 2 (PD-WRL-001), Incident Response - Level 2 (PD-WRL-003)
  • NIST CSF 2.0 Functions: Detect, Respond, Identify
  • NIST Incident Response Lifecycle: Detect, Respond, Mitigate, Recover

Key Responsibilities

  • Perform hands-on 24x7 monitoring and triage of alerts from SIEM, EDR, IDS/IPS, and enterprise fraud tools, serving as both an active analyst and the primary escalation point for complex incidents.
  • Perform Level 2 peer review of L1 analysis to ensure accuracy, thoroughness, and strict adherence to established investigative procedures, stepping in to re-analyze alerts when necessary.
  • Directly execute and coordinate rapid response and containment activities for active fraud incidents, including locking compromised accounts, blocking fraudulent transactions, and mitigating attacker access at the application and network layers.
  • Document all response actions, analytical findings, and decisions in the case management system to create a comprehensive, escalation-ready record for reporting and future analysis.
  • Design, author, and implement advanced SOC playbooks and standard operating procedures (SOPs) specifically for complex cyber-fraud incident scenarios.
  • Lead the identification and implementation of new use cases for AI/LLM tools to enhance advanced analysis, threat hunting, and incident response.
  • Support and enhance SOC governance activities including documentation standards, escalation paths, and operational readiness.
  • Lead education and training efforts for L1 analysts, fostering a culture of continuous improvement and operational excellence within the team.
  • Act as a formal mentor and technical lead, providing expert, hands-on guidance on cyber-fraud analysis, data interrogation, and incident triage.
  • Perform ongoing trend analysis and identification of recurring threat/cyber fraud patterns.
  • Identify potential malware-related activity through alert, log, telemetry, and artifact review and escalate suspected malicious artifacts in accordance with established procedures.

Required Knowledge, Skills & Experience

  • Advanced knowledge of cyber-enabled fraud TTPs, including account takeover, payment fraud, identity theft, and social engineering schemes.
  • Extensive hands-on experience investigating and managing complex fraud incidents within an enterprise SOC environment.
  • Deep expertise with data analytics and query languages/tools such as SQL, Python, SAS, or R for interrogating large datasets.
  • Strong grasp of web application defense principles, including deep knowledge of HTTP/S, DNS, and network traffic analysis within multi-layer enterprise systems.
  • Experience with big data technologies (e.g., Hadoop, Spark), RDBMS, ETL tools, data warehouses, and business intelligence platforms.
  • Solid understanding of application security standards (e.g., OWASP Top 10, API security) and risk assessment procedures.
  • Proficiency in correlating security logs (network, endpoint, WAF) with application and transactional logs to build a complete picture of a fraud event.
  • Demonstrated ability to lead fraud incident response efforts, document complex analytical findings, and mentor junior analysts.
  • Typically, 6-10 years of experience in a cyber-fraud analysis, incident response, or data analytics role within a security context.
  • Ability to work in a 24x7 shift environment.

Preferred Qualifications

  • Experience with Web Application Firewalls (WAF) and Bot Defense solutions.
  • Professional certifications such as Certified Fraud Examiner (CFE), GIAC Certified Incident Handler (GCIH), or certifications in data analytics or machine learning.
  • Experience with data visualization tools (e.g., Tableau, Power BI) for creating fraud trend dashboards and reports.
  • Experience in developing or tuning rules and models for fraud detection systems.
  • Experience with scripting and automation (e.g., Python, PowerShell) to automate response tasks.

Education

  • Bachelor’s degree/University degree in Data Science, Computer Science, Information Systems, or a related field, or equivalent experience.

------------------------------------------------------

Job Family Group:

Technology

------------------------------------------------------

Job Family:

Information Security

------------------------------------------------------

Time Type:

Full time

------------------------------------------------------

Primary Location:

Irving Texas United States

------------------------------------------------------

Primary Location Full Time Salary Range:

$125,760.00 - $188,640.00

In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.

------------------------------------------------------

Most Relevant Skills

Please see the requirements listed above.

------------------------------------------------------

Other Relevant Skills

For complementary skills, please see above and/or contact the recruiter.

------------------------------------------------------

Anticipated Posting Close Date:

Oct 12, 2026

------------------------------------------------------

Automated Processing and AI

We use automated processing, including artificial intelligence, for our legitimate business interests (or our reasonable and appropriate business purposes) to identify and align the candidate's skills and abilities with a specific job opening. Additionally, if you so choose, or consent, we can match your skills and abilities to other suitable roles at Citi.

Importantly, all our hiring processes and decisions, including determining your suitability for a role, are conducted, checked, and decided by individuals. Our automated processing and AI do not involve relying on automatic or autonomous decision-making. Please refer to any Jurisdictional Considerations, with specific provisions for your country (where relevant) for further details.

Illinois residents – AI Notice and Right

------------------------------------------------------

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi.

View Citi’s EEO Policy Statement and the Know Your Rights poster.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Citi's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Citi's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Citi's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.