
Senior Security Engineer - Proxy & Cloud Security Platform
Truist Financial Corporation21 days ago
Richmond, VA, USA +3 moreSenior
Base Salary
$120k - $150k/yr
Responsibilities
- Lead the design, implementation, governance, and continuous improvement of the enterprise secure access platform.
- Design proxy, bypass, direct-to-cloud, traffic steering, tunneling, and secure forwarding strategies for Microsoft 365, real-time, encrypted, non-HTTP, and other traffic.
- Evaluate and integrate emerging security capabilities through proof-of-concept and proof-of-value initiatives.
- Build automation and policy-as-code solutions using scripting, APIs, and orchestration tools to improve deployment, validation, compliance, and operational efficiency.
- Perform threat modeling and security design reviews for cloud, SaaS, AI-enabled, application, and network architectures.
- Evaluate TLS inspection, encrypted traffic, HTTP/3, QUIC, and other modern protocol impacts on security controls and user experience.
- Provide expert operational support and troubleshooting for secure web gateway and cloud-delivered security platforms.
- Lead medium-complexity initiatives, coordinate with cross-functional partners, mentor junior engineers, and provide technical leadership.
- Support documentation, approvals, attestations, audits, and complex multidisciplinary troubleshooting efforts.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- At least 7 years of experience in security engineering or related cybersecurity roles.
- Deep knowledge of cybersecurity principles, threat modeling, security testing, penetration testing, and software development lifecycle security practices.
- Experience implementing and managing complex information security technologies.
- Expertise in proxy, firewall, network security, advanced traffic routing, tunneling, secure forwarding architectures, DLP, GRE, IPSec, and PAC.
- Hands-on experience with cloud-delivered security platforms, including Zscaler, and Zero Trust SSE/ZTNA architectures.
- Experience with enterprise troubleshooting, log analysis, monitoring tools, identity integrations, automation, platform engineering, security platform integrations, and Microsoft 365 traffic optimization.
- Proficiency with Python, PowerShell, APIs, orchestration frameworks, GitLab SaaS, and CI/CD or Infrastructure-as-Code practices.
- Experience with Entra ID (Azure AD), SAML, SSO, SCIM, CrowdStrike, ServiceNow, certificate management, security policy governance, compliance, or NSPM tools.
- Familiarity with HTTP/2, HTTP/3, QUIC, WebSockets, AI/ML security, and data inspection use cases.
- CISSP or equivalent certification and experience working in Agile delivery models are preferred.
Benefits
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401(k) plan for eligible regular employees working at least 20 hours per week.
- At least 10 days of first-year vacation, 10 sick days, and paid holidays, prorated as applicable.
- The position may be eligible for a defined benefit pension plan, restricted stock units, and/or deferred compensation plan.
- The role is regular and onsite five days per week in Charlotte or Raleigh, North Carolina, or Atlanta, Georgia.
- Minimal travel is expected, up to 10%, and after-hours support may be required based on business needs.