EngineerJobs.io
← Back to all jobs

Job Description

Truist Bank is hiring a Senior Security Engineer focused on penetration testing across enterprise and emerging technologies, with experience in AI and Mainframe security testing.

Responsibilities

  • Conduct penetration tests across enterprise applications, infrastructure, cloud platforms, AI systems, APIs, and mobile applications
  • Assess Active Directory environments and other technology assets to identify vulnerabilities and security weaknesses
  • Use realistic attack techniques to uncover attack paths, misconfigurations, and exploitable conditions
  • Validate fixes through retesting to confirm risk reduction after remediation
  • Produce clear technical findings including reproduction steps, supporting evidence, business impact, and remediation recommendations
  • Maintain testing artifacts and evidence to support regulatory, audit, and compliance requirements
  • Defend findings with application teams, technology leaders, and other stakeholders
  • Participate in escalation calls for disputed findings, risk discussions, and remediation planning
  • Apply sound judgment when evaluating vulnerability severity and exploitability
  • Partner with internal and external testing teams to improve coverage and effectiveness
  • Track emerging attack techniques, technologies, and industry trends
  • Contribute to AI security testing initiatives and emerging offensive security capabilities
  • Support AI model evaluation, testing, training, and security validation efforts
  • Provide feedback to improve testing methodologies, automation, tooling, and operational processes
  • Identify opportunities to increase testing efficiency, effectiveness, and scalability
  • Perform peer reviews of penetration testing reports and deliverables
  • Provide technical guidance and mentorship to junior security professionals
  • Coordinate effectively across security, engineering, development, infrastructure, app teams, and leadership
  • Assist with standards, procedures, playbooks, and penetration testing documentation
  • Support special projects and security initiatives aligned to individual expertise

Requirements

  • Bachelor’s degree or equivalent education, training, and work-related experience
  • Minimum 7 years of experience in security engineering or related cybersecurity roles
  • Deep specialized knowledge of cybersecurity principles, theories, and concepts
  • Proven experience with software development lifecycle security practices
  • Deep knowledge of threat modeling, security testing, and penetration testing
  • Experience implementing and managing complex information security technologies

Technologies

  • AI systems
  • Mainframe
  • Active Directory
  • APIs
  • Web Applications
  • Infrastructure
  • Mobile
  • IoT
  • Cloud Platforms
  • Thick Client Applications
  • Physical Security
  • Wireless networks

Benefits

  • Medical
  • Dental
  • Vision
  • Life insurance
  • Disability
  • Accidental death and dismemberment
  • Tax-preferred savings accounts
  • 401k plan
  • No less than 10 days of vacation during the first year of employment (prorated by hire date and full-time or part-time status)
  • 10 sick days (prorated)
  • Paid holidays
  • Defined benefit pension plan (depending on position and division)
  • Restricted stock units (depending on position and division)
  • Deferred compensation plan (depending on position and division)

Preferred Qualifications

  • 5+ years in penetration testing, red teaming, offensive security, vulnerability research, or related cybersecurity experience
  • Strong technical writing and communication skills
  • Ability to clearly articulate technical risks to technical and non-technical audiences
  • Ability to independently manage multiple engagements in a dynamic environment
  • Experience defending technical findings and participating in challenging stakeholder discussions
  • Strong analytical and problem-solving skills
  • Ability to adapt quickly to changing priorities, technologies, and business needs
  • Experience with AI Security Testing and/or Mainframe Security Testing
  • Experience conducting penetration testing, red team, and security assessments across a variety of environments and technologies including Active Directory, APIs, web applications, infrastructure, cloud platforms, mobile applications, thick/client-server applications, IoT devices, wireless networks, network security, social engineering, and physical security controls
  • Banking, financial services, or highly regulated industry experience
  • Experience supporting red team, purple team, or adversary emulation activities
  • Experience with scripting, automation, and offensive security tool development

Desired Characteristics

  • Self-starter who requires minimal supervision
  • Takes ownership and drives work to completion
  • Performs well under demanding workloads and changing priorities
  • Maintains professionalism and effectiveness during difficult conversations
  • Comfortable challenging assumptions and presenting evidence-based findings
  • Continuously invests in improving technical and professional skills
  • Shows resilience, accountability, and a strong bias for action
  • Balances individual execution with team success
  • Helps elevate the performance of others

Relevant Certifications

  • Offensive Security (OffSec): OSCP+, OSEP, OSED, OSEE, OSWE, OSWA, OSAI
  • GIAC: GPEN, GWAPT, GXPN, GRTP, GCFA
  • ISC2: CISSP, CRIS
  • Hack The Box: CPTS, Active Directory Penetration Tester, Web Exploitation Specialist, Web Exploitation Expert, Offensive AI Expert
  • Equivalent certifications in offensive security, penetration testing, red team, exploit development, web application security, or digital forensics will also be considered

Location: Raleigh, NC (onsite)

Salary: USD 120,000 - 170,000 per year

Benefit eligibility note: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may vary by division. Specific benefits may differ based on full-time or part-time status, position, and division. Additional details are provided during the hiring process.

Similar Jobs