
Application Security Engineer
Truist Financial Corporation1 day ago
Atlanta, GA, USA +2 moreSenior
Responsibilities
- Design, configure, test, and improve advanced DAST solutions and technical patterns for complex web applications and APIs.
- Perform and validate authenticated assessments, including login success, session state, crawl coverage, attack surface coverage, vulnerability results, and assessment validity.
- Engineer DAST scan policies, authentication workflows, login sequences, session handling, API definitions, custom scripts, integrations, and automation.
- Investigate difficult assessment problems involving multifactor authentication, incomplete crawling, blocked requests, dynamic application behavior, tool limitations, false positives, false negatives, and inconsistent results.
- Use browser, proxy, HTTP, API, logging, and diagnostic techniques to identify root causes and develop reusable technical solutions.
- Analyze and document DAST evidence, distinguish validated vulnerabilities from false positives and coverage limitations, and support remediation verification.
- Partner with application and engineering teams to resolve testability constraints and establish technically appropriate DAST configurations.
- Serve as a technical escalation point, review complex configurations and evidence, and share specialized knowledge through peer reviews, troubleshooting, and documentation.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- At least 5 years of experience in security engineering or related cybersecurity roles.
- Advanced knowledge of cybersecurity principles, theories, and concepts.
- Proven experience with software development lifecycle security practices.
- Advanced knowledge of threat modeling, security testing, and penetration testing.
- Experience implementing and managing complex information security technologies.
- Preferred: advanced cybersecurity certification such as CISSP, CSSLP, GIAC, GWAPT, OSWE, or an equivalent application security credential.
- Preferred: deep hands-on experience with enterprise DAST technologies and methodologies for complex web applications and APIs.
- Preferred: experience with authenticated testing, modern authentication protocols, session management, multifactor authentication, scripted login workflows, and credential handling.
- Preferred: working knowledge of HTTP, browser behavior, web and API architectures, authentication and authorization patterns, API specifications, and common application frameworks.
- Preferred: experience with security automation, APIs, scripting, data transformation, orchestration, CI/CD integrations, or workflow technologies.
- Preferred: familiarity with emerging cybersecurity technologies, industry trends, and strategic risk management.
Benefits
- Regular employees working at least 20 hours per week may be eligible for medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan.
- Benefits may include at least 10 days of vacation during the first year, 10 sick days, and paid holidays, prorated as applicable.
- Depending on position and division, employees may be eligible for a defined benefit pension plan, restricted stock units, and/or deferred compensation.
- Regular, non-temporary position; work shift is first shift in the United States.
About Truist Financial Corporation
Truist Financial Corporation provides consumer, small‑business, and commercial banking, plus capital markets, payments, mortgage, and wealth management services across the U.S. It earns interest and fee income from deposits, lending, investment banking, and advisory services delivered through Truist Bank and affiliates. The company was formed in 2019 by the merger of BB&T and SunTrust Banks and is headquartered in Charlotte, North Carolina; it is publicly traded on the NYSE (ticker: TFC).