Mediabistro logo
job logo

VP SIEM Content Architect — Splunk ES Expert

Citi, New York, NY, USA

Pay: $125,760-$188,640/yr

Job type: Full Time


SIEM Content Developer, VP

Apply

(opens in new window)

Job Req Id:

26953263
Location(s):

Irving, Texas, United States
Job Type:

Hybrid
Posted:

Apr. 21, 2026
Discover your future at Citi

Working at Citi is far more than just a job. A career with us means joining a team of more than 230,000 dedicated people from around the globe. At Citi, you’ll have the opportunity to grow your career, give back to your community and make a real impact.
Job Overview

Overview of the Role
Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.
As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients’ best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first-class customer experience. We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services.
Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We’ll enable growth and progress together.
Role Overview
The

SIEM Content Developer

is a senior-level cybersecurity professional responsible for designing, implementing, and maintaining high-fidelity SIEM detection and monitoring content. This role translates security requirements, threat intelligence, and incident response playbooks into effective detective controls that enable accurate, timely detection and response to cyber threats.
The position plays a critical role in executing Information Security directives by delivering scalable, reliable, and risk-aligned detection capabilities in accordance with Citi’s Data Security Policy.
Key Responsibilities

SIEM Detection Engineering

Lead the

design, development, testing, deployment, tuning, and optimization

of advanced SIEM content within

Splunk Enterprise Security .

Develop and maintain

correlation rules, alerts, dashboards, and reports

that proactively identify and prioritize security threats for SOC investigation and response.

Translate

threat intelligence, incident response playbooks, and common attack techniques

into robust Splunk ES use cases aligned to frameworks such as

MITRE ATT&CK and NIST .

Content Quality & Optimization

Identify and remediate

false positives, false negatives, logic gaps, data dependencies, and other quality issues

in SIEM content.

Analyze and enhance

SPL queries, detection logic, enrichment logic, macros, lookups, and supporting artifacts

to improve accuracy, reliability, and maintainability.

Perform root-cause analysis of

detection gaps and alert fidelity issues , assess risk, and implement corrective actions.

Data & Platform Enablement

Optimize

data onboarding, parsing, normalization, event processing, data models, and data quality

to ensure effective security monitoring.

Support Splunk administration activities (e.g., app configuration, performance tuning) as needed to enable detection engineering objectives.

Automation & Process Improvement

Identify opportunities to

automate and standardize detection engineering workflows , content lifecycle management, and security controls.

Review and validate automated testing results, prioritizing remediation based on

risk, detection coverage, and operational impact .

Collaboration, Risk & Governance

Partner with security operations, engineering, and business stakeholders to deliver

secure, scalable detection solutions .

Assess and manage risk in alignment with regulatory expectations, Citi policies, and ethical standards.

Escalate and report control issues transparently while safeguarding Citi, its clients, and assets.

Qualifications

Experience & Technical Skills

6–10 years

of progressive experience in information security, with deep focus on

SIEM and detection engineering .

Expert-level experience with

Splunk Enterprise and Splunk Enterprise Security , including:
Advanced SPL development

Correlation searches and alert tuning

Dashboards, reports, and data models

Detection performance and content optimization

Proven experience building

advanced threat detection use cases , including insider threat, malware, APTs, and cloud security.

Strong understanding of

security frameworks , adversary tactics, and detection mapping (MITRE ATT&CK, NIST).

Additional Qualifications

Hands-on experience supporting

Splunk administration

and data onboarding in a security context.

Strong analytical, problem‑solving, and communication skills.

Demonstrated ability to influence stakeholders and manage cross‑functional relationships.

Scripting experience (e.g., Python)

for automation, enrichment, or API integrations is a strong plus.

Splunk certifications

(Enterprise Admin, ES Certified Admin) preferred but not required.

Proficiency with

Microsoft Office

tools.

------------------------------------------------------
Job Family Group:
Technology

------------------------------------------------------
Job Family:
Information Security

------------------------------------------------------
Time Type:
Full time

------------------------------------------------------
Primary Location:
Irving Texas United States

------------------------------------------------------
Primary Location Full Time Salary Range:
$125,760.00 - $188,640.00
In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.
------------------------------------------------------
Most Relevant Skills
Please see the requirements listed above. ------------------------------------------------------
Other Relevant Skills
For complementary skills, please see above and/or contact the recruiter. ------------------------------------------------------
Anticipated Posting Close Date:
Apr 28, 2026

------------------------------------------------------
Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.
If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review

Accessibility at Citi

(opens in new window)

.

View Citi’s

EEO Policy Statement

(opens in new window)

and the

Know Your Rights

(opens in new window)

poster.
Apply

(opens in new window)
#J-18808-Ljbffr