VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2)

Citibank (Switzerland) AG

Irving (TX)

Hybrid

USD 126,000 - 189,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Citibank (Switzerland) AG in Irving, TX is seeking a VP SOC Cyber Fraud Analyst – Level 2 (L2) to monitor, triage, and analyze security events across endpoints, networks, email, and data. You will lead L1 analysts, mentor junior staff, and drive use-case development and incident response improvements.

The role requires 6–10 years in cyber-fraud analysis or data analytics, strong SQL/Python skills, and experience with big data and WAF/Bot defenses. Hybrid work model.

Qualifications

  • 6–10 years of experience in cyber-fraud analysis, incident response, or data analytics.
  • Advanced knowledge of cyber-enabled fraud TTPs and incident response lifecycle.
  • Experience with data analytics tools and large datasets.

Responsibilities

  • Perform 24x7 monitoring and triage of security alerts across multiple domains.
  • Lead Level 2 review, mentorship, and education for L1 analysts.
  • Coordinate rapid response and containment of active fraud incidents.
  • Document actions and findings for escalation-ready records.
  • Design and implement advanced SOC playbooks and SOPs.

Skills

Data analytics
SQL
Python
SAS/R

Education

Bachelor's degree in Data Science / CS

Tools

Hadoop
Spark
Tableau/Power BI
WAF/Bot Defense Tools

Job description

## VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2)Apply: Hybrid: Irving Texas United States: Full time: Posted Today: 26993495The SOC Analyst (L2) performs continuous monitoring, initial triage, and in-depth analysis of security events across endpoint, network, email, big data, and web telemetry and behavior anomaly detection tools. This role provides high-quality documentation and escalation to Incident Response, while also performing Level 2 peer review analysis to ensure accuracy, thoroughness, and adherence to established procedures across the L1 team. The L2 analyst leads education and training efforts for L1 analysts, serving as a formal mentor and technical lead. They are responsible for identifying and triaging service outages and log discrepancies, proactively addressing potential data visibility issues. The L2 analyst plays a critical role in designing and implementing new security use cases, conducting content reviews, drafting required Business Requirements Documents (BRDs), and monitoring use case performance to identify over-alerting or underperforming content. Furthermore, the L2 analyst attends, leads, and organizes cross-organizational communications and conference calls, acting as a key liaison between the SOC and other business units. The overall objective of this role is to ensure the execution of Information Security directives and activities in alignment with enterprise data security policy, while also driving strategic improvements, automation enablement, and mentorship within the SOC team. ## Primary Framework Alignment* **NICE Workforce Framework:** Defensive Cybersecurity - Level 2 (PD-WRL-001), Incident Response - Level 2 (PD-WRL-003)* **NIST CSF 2.0 Functions:** Detect, Respond, Identify* **NIST Incident Response Lifecycle:** Detect, Respond, Mitigate, Recover## Key Responsibilities* Perform hands-on 24x7 monitoring and triage of alerts from SIEM, EDR, IDS/IPS, and enterprise fraud tools, serving as both an active analyst and the primary escalation point for complex incidents.* Perform Level 2 peer review of L1 analysis to ensure accuracy, thoroughness, and strict adherence to established investigative procedures, stepping in to re-analyze alerts when necessary.* Directly execute and coordinate rapid response and containment activities for active fraud incidents, including locking compromised accounts, blocking fraudulent transactions, and mitigating attacker access at the application and network layers.* Document all response actions, analytical findings, and decisions in the case management system to create a comprehensive, escalation-ready record for reporting and future analysis.* Design, author, and implement advanced SOC playbooks and standard operating procedures (SOPs) specifically for complex cyber-fraud incident scenarios.* Lead the identification and implementation of new use cases for AI/LLM tools to enhance advanced analysis, threat hunting, and incident response.* Support and enhance SOC governance activities including documentation standards, escalation paths, and operational readiness.* Lead education and training efforts for L1 analysts, fostering a culture of continuous improvement and operational excellence within the team.* Act as a formal mentor and technical lead, providing expert, hands-on guidance on cyber-fraud analysis, data interrogation, and incident triage.* Perform ongoing trend analysis and identification of recurring threat/cyber fraud patterns.* Identify potential malware-related activity through alert, log, telemetry, and artifact review and escalate suspected malicious artifacts in accordance with established procedures.## Required Knowledge, Skills & Experience* Advanced knowledge of cyber-enabled fraud TTPs, including account takeover, payment fraud, identity theft, and social engineering schemes.* Extensive hands-on experience investigating and managing complex fraud incidents within an enterprise SOC environment.* Deep expertise with data analytics and query languages/tools such as SQL, Python, SAS, or R for interrogating large datasets.* Strong grasp of web application defense principles, including deep knowledge of HTTP/S, DNS, and network traffic analysis within multi-layer enterprise systems.* Experience with big data technologies (e.g., Hadoop, Spark), RDBMS, ETL tools, data warehouses, and business intelligence platforms.* Solid understanding of application security standards (e.g., OWASP Top 10, API security) and risk assessment procedures.* Proficiency in correlating security logs (network, endpoint, WAF) with application and transactional logs to build a complete picture of a fraud event.* Demonstrated ability to lead fraud incident response efforts, document complex analytical findings, and mentor junior analysts.* Typically, 6-10 years of experience in a cyber-fraud analysis, incident response, or data analytics role within a security context.* Ability to work in a 24x7 shift environment. ## Preferred Qualifications* Experience with Web Application Firewalls (WAF) and Bot Defense solutions.* Professional certifications such as Certified Fraud Examiner (CFE), GIAC Certified Incident Handler (GCIH), or certifications in data analytics or machine learning.* Experience with data visualization tools (e.g., Tableau, Power BI) for creating fraud trend dashboards and reports.* Experience in developing or tuning rules and models for fraud detection systems.* Experience with scripting and automation (e.g., Python, PowerShell) to automate response tasks. ## Education* Bachelor’s degree/University degree in Data Science, Computer Science, Information Systems, or a related field, or equivalent experience.------------------------------------------------------## **Job Family Group:**Technology------------------------------------------------------## **Job Family:**Information Security------------------------------------------------------## **Time Type:**Full time------------------------------------------------------## **Primary Location:**Irving Texas United States------------------------------------------------------## **Primary Location Full Time Salary Range:**$125,760.00 - $188,640.00In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2) Citi · Irving, TX Full-time · On-site $125,760–188,640 4 hours ago
VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2) Citi · Irving, TX Full-time · On-site $125,760–188,640 4 hours ago

Emploive • Irving (TX)

On-site
USD 126,000 - 189,000
VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2)
VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2)

Citigroup Inc. • Irving (TX)

On-site
USD 126,000 - 189,000
VP Security Operations Center (SOC) Cyber Fraud Analyst - Level 2 (L2)
VP Security Operations Center (SOC) Cyber Fraud Analyst - Level 2 (L2)

Citigroup • Irving (TX)

On-site
USD 90,000 - 130,000
VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2)
VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2)

Citi • Irving (TX)

On-site
USD 126,000 - 189,000
Intelligence Senior Analyst
Intelligence Senior Analyst

Citibank (Switzerland) AG • Tampa (FL)

On-site
Confidential
Fraud Operation Lead Analyst - Vice President
Fraud Operation Lead Analyst - Vice President

Citibank (Switzerland) AG • Jacksonville (FL)

On-site
USD 93,000 - 140,000
VP SOC Fraud Analytics & Incident Response
VP SOC Fraud Analytics & Incident Response

Citibank (Switzerland) AG • Irving (TX)

Hybrid
USD 126,000 - 189,000
Insider Threat Engineering Support Lead
Insider Threat Engineering Support Lead

Citibank (Switzerland) AG • Irving (TX)

Hybrid
USD 126,000 - 189,000
Fraud Lead Systems Analyst Vice President
Fraud Lead Systems Analyst Vice President

Citibank (Switzerland) AG • Jacksonville (FL), Northern (KY)

Hybrid
USD 114,000 - 171,000
Fraud Red Team Senior Analyst
Fraud Red Team Senior Analyst

Citi • New York (NY)

On-site
USD 87,000 - 131,000