
Senior API Developer/ Security Engineer (Vulnerability / Remediation)
Truist Financial Corporation2 days ago
Atlanta, GA, USA +2 moreSenior
Responsibilities
- Lead the enterprise vulnerability management program for automated API testing, including identification, assessment, prioritization, tracking, and remediation.
- Perform security testing and penetration testing for assigned platforms and services.
- Develop risk-based remediation strategies and collaborate with application teams to reduce security exposure.
- Triage and validate security findings to reduce false positives and improve remediation effectiveness.
- Design, implement, and maintain automated API security testing capabilities within CI/CD pipelines.
- Implement and update security baselines, guardrails, and control configurations for systems and applications.
- Partner with application development, DevSecOps, and technology teams on vulnerability remediation and security priorities.
- Share security knowledge and provide informal guidance during code reviews, design discussions, and pairing sessions.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- Minimum of 7 years of experience in security engineering or related cybersecurity roles.
- Deep specialized knowledge of cybersecurity principles, theories, and concepts.
- Proven experience with software development lifecycle security practices.
- Deep knowledge of threat modeling, security testing, and penetration testing.
- Experience implementing and managing complex information security technologies.
- Preferred knowledge of NIST SP 800-228, FFIEC guidelines, OWASP API Security Top 10, and FAPI.
- Preferred understanding of OAuth 2.0, OpenID Connect, mutual TLS, and JSON Web Tokens.
- Preferred experience in banking, financial services, cybersecurity, regulated enterprise environments, or high-audit platforms.
- Proficiency or familiarity with Python scripting is preferred.
- Relevant security certifications such as CISSP, OSCP, CEH, or Security+ are preferred.
- Preferred experience with AWS or Microsoft Azure, cloud-native security patterns, telemetry analysis, deployment gating, and AI-system security controls.
Benefits
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan for eligible employees.
- At least 10 days of vacation, 10 sick days, and paid holidays during the first year, prorated as applicable.
- Depending on position and division, eligibility may include a defined benefit pension plan, restricted stock units, and deferred compensation plan.
- Regular employees working 20 or more hours per week are eligible for benefits, subject to specific plan and division eligibility.
About Truist Financial Corporation
Truist Financial Corporation provides consumer, small‑business, and commercial banking, plus capital markets, payments, mortgage, and wealth management services across the U.S. It earns interest and fee income from deposits, lending, investment banking, and advisory services delivered through Truist Bank and affiliates. The company was formed in 2019 by the merger of BB&T and SunTrust Banks and is headquartered in Charlotte, North Carolina; it is publicly traded on the NYSE (ticker: TFC).