
Senior API Developer/ Security Engineer (Vulnerability / Remediation)
Truist Financial Corporation2 hours ago
Tokyo, JapanSenior
Responsibilities
- Lead the enterprise vulnerability management program for automated API testing.
- Identify, assess, prioritize, track, and drive remediation of security vulnerabilities across applications and APIs.
- Perform security testing and penetration testing for assigned platforms and services.
- Develop risk-based remediation strategies with application and technology teams.
- Triage and validate security findings to reduce false positives and improve remediation effectiveness.
- Design, implement, and maintain automated API security testing within CI/CD pipelines.
- Implement and update security baselines, guardrails, and control configurations.
- Provide technical guidance during code reviews, design discussions, and pairing sessions.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- At least 7 years of experience in security engineering or related cybersecurity roles.
- Deep knowledge of cybersecurity principles, threat modeling, security testing, and penetration testing.
- Experience with software development lifecycle security practices and complex information security technologies.
- Experience with API security testing tools such as Akamai, Salt Security, Traceable, Data Theorem, OWASP ZAP, SoapUI, ReadyAPI, or Burp Suite.
- Working knowledge of NIST SP 800-228, FFIEC guidelines, OWASP API Security Top 10, and FAPI.
- Strong understanding of OAuth 2.0, OpenID Connect, mutual TLS, and JSON Web Tokens.
- Python scripting proficiency or familiarity.
- Relevant certifications such as CISSP, OSCP, CEH, or Security+.
- Experience with AWS or Microsoft Azure and with banking, financial services, regulated enterprise, or high-audit environments.
- Familiarity with secure tool-calling patterns, API protections, model or prompt change validation, runtime traceability for AI systems, cloud-native security patterns, telemetry analysis, and deployment gating.
Benefits
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401(k) plan for eligible employees.
- At least 10 days of vacation, 10 sick days, and paid holidays during the first year, prorated as applicable.
- The position may be eligible for a defined benefit pension plan, restricted stock units, and/or deferred compensation plan depending on the division.
- Regular, non-temporary work; five days per week in the Atlanta, Raleigh, or Charlotte office; first shift; English fluency required.