Threat & Exposure Management Platform Engineer

CitiIrving, TexasOn-siteFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

We are looking for a highly experienced Threat & Exposure Management Platform Engineer to design, build, and operate the data platform and architecture that unifies threat, vulnerability, and exposure signal across the enterprise. This is a foundational, high-impact platform engineering role at the core of our organization's evolution toward a next-generation, AI-enabled security operations capability.

You will own the architecture connecting security tooling, threat intelligence, vulnerability data, and adversary validation results into a single, continuously updated substrate — enabling faster, more accurate, and increasingly automated risk prioritization and response across the business.

This role calls for someone with deep platform engineering expertise and strong architectural judgment , comfortable owning complex, mission-critical systems end-to-end rather than working on isolated components.

Key Responsibilities

- Data Pipeline Engineering: Design, build, and operate scalable, resilient data pipelines that ingest, normalize, and enrich threat and exposure signals from a wide range of security, IT, and cloud platforms (e.g., vulnerability scanners, EDR/XDR, CSPM, CMDB, threat intelligence feeds, identity systems).
- Platform Integration: Develop and maintain robust API integrations connecting security tooling, data lakes, and correlation/analytics engines to create a single, unified view of the organization's threat and exposure posture.
- Correlation Engine Development: Architect and implement correlation logic and data models that link vulnerabilities, threats, assets, and business context to support automated, evidence-based risk prioritization.
- Data Substrate & Architecture Ownership: Build and evolve the underlying data substrate (schemas, storage layers, streaming infrastructure) that serves as the authoritative source of truth for enterprise risk and exposure data, and own its long-term architectural direction.
- API & Interface Development: Expose clean, well-documented, secure APIs enabling downstream systems, dashboards, and analyst tooling to consume unified threat and exposure data programmatically.
- Continuous Exposure Lifecycle Support: Build and operate the platform capabilities that support an ongoing, iterative approach to discovering, prioritizing, and validating exposures across the environment — from initial scoping through to remediation tracking.
- Adversary-Informed Validation Integration: Integrate outputs from adversary emulation, control validation, and simulation exercises into the correlation engine, enriching risk prioritization with real-world evidence of exploitability and defensive effectiveness.
- Coverage & Gap Analysis: Architect data models and pipelines that continuously assess defensive coverage against real-world attack techniques, surfacing prioritized gaps for remediation.
- Operational Reliability: Own the uptime, performance, scalability, and data quality of production pipelines and integrations; implement monitoring, alerting, and self-healing mechanisms.
- Cross-Platform Normalization: Establish common taxonomies and data standards to reconcile inconsistent data formats, severity scoring, and asset identifiers across heterogeneous security tools.
- Cross-Functional Collaboration: Partner with security operations, threat intelligence, detection engineering, red/purple team, and data science functions to ensure platform outputs meet operational and analytical needs.
- Security & Compliance: Ensure all data handling, storage, and access adhere to enterprise security, privacy, and regulatory requirements, given the sensitivity of threat and exposure data.
- Automation & Scale: Drive automation of data onboarding for new tools and platforms to reduce integration lead time as the environment and tool ecosystem grow.
- Documentation & Knowledge Transfer: Maintain architecture diagrams, runbooks, and integration documentation to support platform sustainability and team scaling.

Required Skills & Experience

- Strong architecture skills — demonstrated ability to design end-to-end platform architectures spanning data ingestion, correlation, validation, and delivery layers, with sound judgment on scalability, extensibility, and long-term maintainability.
- Deep platform engineering expertise — a proven track record owning and operating complex, production-grade security data platforms end-to-end.
- Hands-on experience building large-scale data pipelines (batch and streaming) using tools such as Kafka, Spark, Airflow, Flink, or equivalent.
- Strong expertise in API design and development (REST/GraphQL), including authentication, rate limiting, and versioning for high-throughput data.
- Proven experience integrating heterogeneous security platforms (vulnerability management, EDR/XDR, CSPM, SIEM, CMDB, threat intelligence platforms, simulation/emulation tooling).
- Strong background in data modeling and correlation engine design — able to reconcile asset, vulnerability, threat, and adversary-behavior data into unified risk views.
- Practical understanding of how to operationalize an ongoing exposure discovery, prioritization, and validation process within a technical platform.
- Familiarity with mapping known attacker techniques and behaviors to defensive controls and detection coverage.
- Familiarity with simulation or emulation-based control validation approaches and how their outputs feed into broader risk models.
- Proficiency in at least one major programming language (Python, Go, or Java) for pipeline and integration development.
- Experience with cloud-native data infrastructure (AWS/Azure/GCP), including data lakes, warehouses, and event-driven architectures.
- Solid understanding of core cybersecurity concepts: vulnerability management, threat intelligence, exposure management, attack surface management, and risk scoring frameworks (e.g., CVSS, EPSS).
- Experience with database technologies spanning relational, NoSQL, graph, and time-series stores for correlation and attack-path use cases.
- Strong software engineering fundamentals: CI/CD, infrastructure-as-code, version control, testing, and observability practices.
- Excellent cross-functional collaboration skills, able to work with security operations, detection engineering, and platform architecture teams in a fast-paced, mission-critical environment.

Preferred Qualifications

- 10+ yrs of experience leading a continuous exposure management program or initiative end-to-end, from architecture through operational rollout.
- Familiarity with graph-based attack path analysis or asset/risk graphs.
- Hands-on experience with adversary simulation or emulation frameworks and purple-team tooling.
- Experience supporting AI/ML-driven security operations or automation-first security initiatives.
- Relevant certifications (e.g., GIAC, cloud security or data certifications) are a plus but not required in lieu of hands-on expertise.

##

What We're Looking For

A builder who thrives on architecting and operating complex, high-stakes data platforms — someone equally comfortable in deep technical design discussions and hands-on implementation, who wants to shape the data foundation behind the next generation of automated, intelligence-driven security operations.

Education:

- Bachelor’s degree/University degree or equivalent experience
- Master’s degree preferred

This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.

------------------------------------------------------

## Job Family Group:
Technology
------------------------------------------------------

## Job Family:
Information Security
------------------------------------------------------

## Time Type:
Full time
------------------------------------------------------

## Primary Location:
Irving Texas United States
------------------------------------------------------

## Primary Location Full Time Salary Range:
$156,160.00 - $234,240.00
In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.

------------------------------------------------------

## Most Relevant Skills
Please see the requirements listed above.
------------------------------------------------------

## Other Relevant Skills
For complementary skills, please see above and/or contact the recruiter.
------------------------------------------------------

## Anticipated Posting Close Date:
Oct 25, 2026
------------------------------------------------------

Automated Processing and AI

We use automated processing, including artificial intelligence, for our legitimate business interests (or our reasonable and appropriate business purposes) to identify and align the candidate's skills and abilities with a specific job opening. Additionally, if you so choose, or consent, we can match your skills and abilities to other suitable roles at Citi.

Importantly, all our hiring processes and decisions, including determining your suitability for a role, are conducted, checked, and decided by individuals. Our automated processing and AI do not involve relying on automatic or autonomous decision-making. Please refer to any Jurisdictional Considerations, with specific provisions for your country (where relevant) for further details.

Illinois residents – AI Notice and Right

------------------------------------------------------

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi .

View Citi’s EEO Policy Statement and the Know Your Rights poster.