VP Security Operations Center (SOC) Cyber Fraud Analyst, Level 2

Citi

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Irving, TX
Salary
$125,760–$188,640 / yr
Employment
Full-time
Posted
6 days ago
Freshness
Confirmed live today

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $157k
This role $157k
$105k $205k
below market most similar roles pay here above market

This role pays more than 50% of similar roles. Most pay $124,905–$190,000 — the blue band above. At the midpoint, this role pays about $157k versus about $157k for comparable roles.

Based on 240 similar postings.

Employer

About Citi

Citi is one of the world’s most trusted financial institutions, proudly serving millions of customers across the United States.

Citi currently has 273 open roles on FindRole.

Listed pay typically runs $125,760–$188,640 across 256 roles with salary data.

Most-posted roles

View all roles at Citi

At a glance

TL;DR · VP Security Operations Center (SOC) Cyber Fraud Analyst, Level 2

JOB TITLE: VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2) The VP Security Operations Center (SOC) Cyber Fraud Analyst – Level 2 (L2) joins the Information Security team to perform continuous monitoring, initial triage, and in-depth analysis of security events across endpoint, network, email, and big data telemetry. This role involves performing Level 2 peer reviews, mentoring L1 analysts, and leading education efforts. Responsibilities include designing security use cases, drafting Business Requirements Documents, and executing rapid response for active fraud incidents like account takeovers or identity theft. The position requires expertise in SQL, Python, SAS, R, and big data technologies like Hadoop and Spark. Candidates must navigate complex cyber-fraud TTPs, web application defense principles, and SIEM, EDR, and IDS/IPS tools to ensure alignment with enterprise data security policies and drive automation.

What you'll do

  • Perform 24x7 monitoring and triage of alerts from SIEM, EDR, IDS/IPS, and enterprise fraud tools.
  • Conduct Level 2 peer reviews of L1 analysis to ensure accuracy and adherence to investigative procedures.
  • Execute rapid response and containment activities for active fraud incidents, including locking accounts and blocking transactions.
  • Design, author, and implement advanced SOC playbooks and standard operating procedures for complex cyber-fraud scenarios.
  • Lead education, training, and formal mentorship for L1 analysts to foster operational excellence.
  • Identify and implement new use cases for AI/LLM tools to enhance threat hunting and incident response.
  • Perform ongoing trend analysis to identify recurring threat patterns and malware-related activity.
  • Draft Business Requirements Documents (BRDs) and monitor use case performance to identify over-alerting or underperforming content.

What we're looking for

  • Typically, 6-10 years of experience in a cyber-fraud analysis, incident response, or data analytics role within a security context.
  • Advanced knowledge of cyber-enabled fraud TTPs, including account takeover, payment fraud, identity theft, and social engineering.
  • Extensive hands-on experience investigating and managing complex fraud incidents within an enterprise SOC environment.
  • Deep expertise with data analytics and query languages/tools such as SQL, Python, SAS, or R for interrogating large datasets.
  • Strong grasp of web application defense principles, including HTTP/S, DNS, and network traffic analysis within multi-layer enterprise systems.
  • Experience with big data technologies, RDBMS, ETL tools, data warehouses, and business intelligence platforms.
  • Solid understanding of application security standards, such as OWASP Top 10 and API security, and risk assessment procedures.
  • Bachelor’s degree in Data Science, Computer Science, Information Systems, or a related field, or equivalent experience.
  • Experience with Web Application Firewalls (WAF) and Bot Defense solutions (preferred).
  • Professional certifications such as CFE, GCIH, or certifications in data analytics or machine learning (preferred).
  • Experience with data visualization tools like Tableau or Power BI (preferred).
  • Experience in developing or tuning rules and models for fraud detection systems (preferred).
  • Experience with scripting and automation using Python or PowerShell (preferred).

More like this

Similar roles

Security Operations Center (SOC) Analyst

Leidos

Alexandria, VA 2 days ago $69,550–$125,725
SIEM SOC Operations Incident Response Cybersecurity Event Analysis Risk Management Framework eMASS Endpoint Security network-security Security Telemetry digital-evidence preservation Cybersecurity Monitoring Security Testing Compliance Checking
2+ yrs exp

Security Operations Center (SOC) Analyst

Leidos

Shiloh, IL 4 days ago $69,550–$125,725
SIEM SOAR Python PowerShell IDS IPS NetFlow Packet Analysis MITRE ATT&CK Cyber Kill Chain AWS Azure OSI Model Defense-in-Depth Threat Intelligence IOCs TTPs
2+ yrs exp

SOC Security Analyst 2

University of Miami

Miami, FL 158 days ago
Splunk CrowdStrike Proofpoint MS Defender SIEM IPS NAC Vulnerability Scanners Network Scanners Log Aggregation Cybersecurity Incident Response Data Recovery Electronic Discovery Networking Protocols Security Protocols Risk Assessment CompTIA Security+
3+ yrs exp

Security Operations Center (SOC) Analyst II

Leidos

Shiloh, IL 4 days ago $87,100–$157,450
SIEM SOAR Python PowerShell IDS/IPS NetFlow Packet Analysis MITRE ATT&CK Cyber Kill Chain AWS Azure OSI Model Security+ CySA+ CEH GCIA Threat Intelligence IOCs TTPs
4+ yrs exp

Senior Cyber Threat Detection and Response Analyst

McKesson Corporation

Richmond, VA 3 days ago $122,500–$204,100
SIEM EDR XDR SOAR Python PowerShell Bash KQL SPL AWS Azure GCP MITRE ATT&CK IDS/IPS Firewalls Windows Linux NIST CIS Benchmarks Incident Response
4+ yrs exp Hybrid