AppSec Jobs
← Back to all jobs

Citizens

Principal Security Engineer

Johnston, RIWebsite

Full details on LinkedIn

The complete job description, requirements, and application details are available on the original posting.


About Citizens

Citizens Financial Group, Inc. is one of the oldest and largest financial institutions in the U.S., based in Providence, Rhode Island. With $218.3 billion in assets as of mid-2025, it serves a diverse clientele, including individuals, small businesses, middle-market companies, large corporations, and institutions. The company offers a wide range of retail and commercial banking products, such as checking and savings accounts, credit cards, home and student loans, wealth management, and various lending and treasury management services. It operates approximately 1,000 branches and 3,000 ATMs across 14 states and the District of Columbia. Citizens Inc is an insurance holding company headquartered in Austin, Texas, and has been operating since 1969. It specializes in life insurance and related products, catering to niche markets both domestically and internationally.

Industry

banking

Employees

18,000

1152 engineers

Revenue

$NaNK

Website

Visit →

Security at Citizens

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Public Citizens Bank materials present Application Security as an enterprise-aligned, risk- and compliance-aware function embedded into technology delivery.
  • Security strategy is tied to business and regulatory requirements, with emphasis on embedding security into development initiatives and CI/CD pipelines and operationalizing secure software development lifecycle practices and application security testing.

Security Team

  • Public postings indicate the Head of Infrastructure & Application Security reports to the CISO and is accountable for building and leading a team of cloud, network, endpoint, and application security professionals.
  • Job listings reveal roles focused on vulnerability management and operations (e.g., Senior Vulnerability Specialist.
  • Manager, Vulnerability Management), implying a functionally segmented program covering discovery, triage, metrics, remediation tracking, and executive reporting.
  • The Recorded Future case study references a Threat Intelligence team that produces regular reports for stakeholders, indicating a dedicated threat-intel function that collaborates with red-team and hunting activities.

Key Initiatives

  • Secure SDLC adoption and automation (SAST, DAST, IAST, code review) and integration into DevOps/CI-CD pipelines.
  • An enterprise vulnerability management program across infrastructure and applications with prioritization, remediation tracking, metrics, and executive reporting.
  • Cloud security posture management and secure cloud design.
  • Threat intelligence integration, threat hunting, and red-team collaboration with recurring reporting for stakeholders.
  • A public responsible-disclosure program managed by a third party for application-security vulnerability reporting and validation.
  • Customer-facing security for initiatives such as the Open Banking API emphasizing a seamless and secure user experience.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.