
Senior Security Engineer - Proxy & Cloud Security Platform
Truist Financial Corporation27 days ago
Richmond, VA, USA +3 moreSenior
Base Salary
$120k - $150k/yr
Responsibilities
- Lead the design, implementation, governance, and continuous improvement of the enterprise secure access platform.
- Design traffic steering strategies for proxy, bypass, direct-to-cloud, Microsoft 365, real-time, encrypted, and non-HTTP traffic.
- Evaluate and integrate emerging security capabilities through proof-of-concept and proof-of-value initiatives.
- Architect automation and policy-as-code using scripting, APIs, and orchestration tools.
- Conduct threat modeling and security design reviews across cloud, SaaS, AI-enabled, and network architectures.
- Evaluate TLS inspection, encrypted traffic, HTTP/3, QUIC, and other modern protocol impacts on security controls and user experience.
- Provide expert operational support and troubleshooting for secure web gateway and cloud-delivered security platforms.
- Lead medium-complexity initiatives, coordinate cross-functional delivery, mentor junior engineers, and provide technical leadership.
- Support documentation, approvals, attestations, audits, and complex troubleshooting meetings.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- Minimum of 7 years of experience in security engineering or related cybersecurity roles.
- Deep knowledge of cybersecurity principles, threat modeling, security testing, penetration testing, and software development lifecycle security practices.
- Experience implementing and managing complex information security technologies.
- Preferred expertise in proxy, firewall, network security, advanced traffic routing, tunneling, secure forwarding, DLP, GRE, IPSec, and PAC.
- Hands-on experience with cloud-delivered security platforms such as Zscaler and Zero Trust SSE/ZTNA architectures.
- Expert troubleshooting experience in complex enterprise environments, including log analysis and monitoring with tools such as Splunk.
- Experience with Entra ID/Azure AD, SAML, SSO, and SCIM identity integrations.
- Proficiency with Python, PowerShell, APIs, orchestration frameworks, GitLab SaaS, CI/CD, and Infrastructure-as-Code practices.
- Experience integrating security platforms such as CrowdStrike and enterprise systems such as ServiceNow.
- Knowledge of Microsoft 365 network optimization, TLS inspection, certificate management, and encrypted traffic visibility.
- Familiarity with HTTP/2, HTTP/3, QUIC, and WebSockets.
- Experience with security policy governance, compliance, or Network Security Policy Management tools.
- Exposure to AI/ML security or data inspection use cases.
- CISSP or equivalent certification and experience working in Agile delivery models.
Benefits
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401(k) plan for eligible employees.
- At least 10 days of vacation, 10 sick days, and paid holidays during the first year, prorated as applicable.
- Depending on position and division, eligibility may include a defined benefit pension plan, restricted stock units, and/or deferred compensation plan.
- Regular, office-centric position requiring five days per week onsite in Charlotte or Raleigh, North Carolina, or Atlanta, Georgia.
- Minimal travel of up to 10%; after-hours support may be required based on business needs.