CybersecurityJobs.io
← Back to all jobs

Job Description

As a Senior Security Engineer focused on penetration testing at Truist Bank, you will help identify vulnerabilities across enterprise and emerging technologies, then support validation and remediation to reduce risk. The role emphasizes AI and Mainframe security testing alongside broader offensive security work.

Role Responsibilities

  • Conduct penetration tests across enterprise applications, infrastructure, cloud platforms, AI systems, APIs, mobile applications, Active Directory environments, and other technology assets.
  • Simulate real-world attack techniques to uncover vulnerabilities, attack paths, misconfigurations, and security weaknesses.
  • Perform validation and retesting to confirm remediation effectiveness and demonstrate risk reduction.
  • Document technical findings with reproduction steps, supporting evidence, business impact, and remediation recommendations.
  • Maintain testing artifacts and evidence aligned to regulatory, audit, and compliance needs.
  • Present and defend findings with application teams, technology leaders, and other stakeholders.
  • Join escalation calls for disputed findings, risk discussions, and remediation planning.
  • Apply sound judgment when assessing vulnerability severity and exploitability.
  • Collaborate with internal and external testing teams to improve testing coverage and effectiveness.
  • Keep pace with emerging attack techniques, technologies, and industry trends.
  • Contribute to AI security testing initiatives and emerging offensive security capabilities, including AI model evaluation, testing, training, and security validation efforts.
  • Provide feedback to improve testing methodologies, automation, tooling, and operational processes.
  • Identify opportunities to increase testing efficiency, effectiveness, and scalability.
  • Complete peer reviews of penetration testing reports and related deliverables.
  • Provide technical guidance and mentorship to junior security professionals.
  • Collaborate across security, engineering, development, infrastructure, and app teams, working with multiple levels of management.
  • Assist with standards, procedures, playbooks, and testing documentation.
  • Support special projects and security initiatives based on individual expertise.

Required Qualifications

  • Bachelor’s degree (or equivalent education, training, and work-related experience).
  • Minimum 7 years of experience in security engineering or related cybersecurity roles.
  • Deep specialized knowledge of cybersecurity principles, theories, and concepts.
  • Proven experience applying security practices across the software development lifecycle.
  • Deep knowledge of threat modeling, security testing, and penetration testing.
  • Experience implementing and managing complex information security technologies.

Preferred Qualifications

  • 5+ years of penetration testing, red teaming, offensive security, vulnerability research, or related cybersecurity experience.
  • Strong technical writing and communication skills.
  • Ability to clearly communicate technical risks to both technical and non-technical audiences.
  • Ability to independently manage multiple engagements in a dynamic environment.
  • Experience defending technical findings and participating in challenging stakeholder discussions.
  • Strong analytical and problem-solving skills.
  • Ability to adapt quickly to changing priorities, technologies, and business needs.
  • Experience with AI Security Testing and/or Mainframe Security Testing.
  • Experience conducting assessments across environments and technologies, including Active Directory, APIs, web applications, infrastructure, cloud platforms, mobile applications, thick/client-server applications, IoT devices, wireless networks, network security, social engineering, and physical security controls.
  • Banking, financial services, or highly regulated industry experience.
  • Experience supporting red team, purple team, or adversary emulation activities.
  • Experience with scripting, automation, and offensive security tool development.

Technologies and Platforms

  • AI systems
  • Mainframe
  • Active Directory
  • APIs
  • Web Applications
  • Infrastructure
  • Mobile
  • IoT
  • Cloud Platforms
  • Thick Client Applications
  • Physical Security
  • Wireless networks

Relevant Certifications

  • Offensive Security (OffSec): OSCP+, OSEP, OSED, OSEE, OSWE, OSWA, OSAI
  • GIAC: GPEN, GWAPT, GXPN, GRTP, GCFA
  • ISC2: CISSP, CRIS
  • Hack The Box: CPTS, Active Directory Penetration Tester, Web Exploitation Specialist, Web Exploitation Expert, Offensive AI Expert
  • Equivalent certifications in offensive security, penetration testing, red team activities, exploit development, web application security, or digital forensics will also be considered.

Benefits

  • Medical, Dental, Vision
  • Life insurance
  • Disability
  • Accidental death and dismemberment
  • Tax-preferred savings accounts
  • 401k plan
  • No less than 10 days of vacation during the first year of employment (prorated based on date of hire and by full-time or part-time status)
  • 10 sick days (also prorated)
  • Paid holidays
  • Defined benefit pension plan depending on position and division
  • Restricted stock units depending on position and division
  • Deferred compensation plan depending on position and division

General Eligibility Notes for Benefits

  • All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though specific benefits may vary by the division offering the position.
  • Exact benefits availability for non-temporary positions may be confirmed as you progress through the hiring process, based on full-time or part-time status, position, and division of work.

Role Details

  • Location: Raleigh, NC (onsite)
  • Salary: USD 120,000 - 170,000 per year
  • Experience: Minimum 7 years
  • Education: Bachelor’s degree or equivalent

Similar Jobs