Cyber Incident Management Engineer

Truist

Raleigh (NC)

On-site

USD 110,000 - 160,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision
401k plan
Vacation days
Paid holidays
Disability insurance

Job summary

Truist is seeking a seasoned cybersecurity Incident Manager to lead enterprise incident response and high‑risk vulnerability remediation. You will coordinate cross‑functional teams, drive end‑to‑end containment and remediation, and design automation solutions to improve incident management processes.

The role emphasizes developing workflows, leveraging scripting, APIs, AI‑enabled tools, and Microsoft 365 to enhance efficiency, reporting, and governance across security operations.

Qualifications

  • Bachelor’s degree or equivalent education, training, and work‑related experience.
  • Minimum of 3 years of experience in security engineering or related cybersecurity roles.
  • Developing knowledge in cybersecurity principles, theories, and concepts.
  • Experience in software development lifecycle security practices.
  • Proficiency in implementing and managing information security technologies.

Responsibilities

  • Act as Incident Manager / Incident Coordinator for information security incidents, investigations, events, zero‑days, and high‑risk vulnerabilities. Drive end‑to‑end response from intake through containment, remediation, and closure.
  • Coordinate cross‑functional stakeholders during incidents and operational initiatives to drive alignment, accountability, and execution.
  • Design and implement automation solutions that improve Cyber Incident Management processes and operational efficiency.
  • Develop workflows that support incident intake, triage, escalation, stakeholder communications, action tracking, and closure.
  • Leverage scripting, APIs, AI‑enabled technologies, orchestration tools, and Microsoft 365 platforms to reduce manual effort and improve consistency.
  • Partner with technical and business stakeholders to translate operational requirements into scalable automation and process improvements.
  • Manage cybersecurity automation projects and process improvement initiatives from planning through implementation.
  • Maintain project plans, milestones, risks, issues, dependencies, action items, and executive updates.
  • Develop and maintain operational dashboards, metrics, scorecards, and leadership reporting to measure performance and identify improvement opportunities.
  • Analyze incidents, project, and operational data to support governance, decision making, and continuous improvement.

Skills

Security engineering
Cybersecurity
Automation
APIs integration

Education

Bachelor’s degree or equivalent education
Cybersecurity/CS/IT degree recommended

Tools

Power Automate
Power Apps
SOAR platforms
Copilot
APIs
Microsoft 365
SIEM

Job description

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary: Regular

Language Fluency: English (Required)

Work Shift: 1st shift (United States of America)

Leads enterprise cyber incident and high-risk vulnerability response efforts, coordinating cross-functional teams to assess, contain, and remediate threats. Designs and delivers automation solutions that improve Cyber Incident Management and cybersecurity program execution. Partners across security, technology, and business teams to enhance operational efficiency, accountability, reporting, and response outcomes.

Essential Duties And Responsibilities
  • Act as Incident Manager / Incident Coordinator for information security incidents, investigations, events, zero‑days, and high‑risk vulnerabilities. Drive end‑to‑end response from intake through containment, remediation, and closure.
  • Coordinate cross‑functional stakeholders during incidents and operational initiatives to drive alignment, accountability, and execution.
  • Design and implement automation solutions that improve Cyber Incident Management processes and operational efficiency.
  • Develop workflows that support incident intake, triage, escalation, stakeholder communications, action tracking, and closure.
  • Leverage scripting, APIs, AI‑enabled technologies, orchestration tools, and Microsoft 365 platforms to reduce manual effort and improve consistency.
  • Partner with technical and business stakeholders to translate operational requirements into scalable automation and process improvements.
  • Manage cybersecurity automation projects and process improvement initiatives from planning through implementation.
  • Maintain project plans, milestones, risks, issues, dependencies, action items, and executive updates.
  • Develop and maintain operational dashboards, metrics, scorecards, and leadership reporting to measure performance and identify improvement opportunities.
  • Analyze incidents, project, and operational data to support governance, decision making, and continuous improvement.
Qualifications
Required Qualifications

The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Bachelor’s degree or equivalent education, training, and work‑related experience.
  • Minimum of 3 years of experience in security engineering or related cybersecurity roles.
  • Developing knowledge in cybersecurity principles, theories, and concepts.
  • Experience in software development lifecycle security practices.
  • Proficiency in implementing and managing information security technologies.
Preferred Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Business, or a related field, or equivalent education and experience.
  • Experience supporting cybersecurity operations, cyber incident management, major incident management, or related technology operations.
  • Experience designing or supporting automation using scripting, APIs, workflow orchestration, artificial intelligence, or Microsoft 365 platforms.
  • Experience coordinating cross‑functional projects, operational initiatives, or process‑improvement efforts.
  • Experience gathering requirements, analyzing workflows, and translating business needs into technical or operational solutions.
  • Strong organizational, analytical, facilitation, communication, and problem‑solving skills.
  • Ability to communicate effectively with technical and non‑technical stakeholders at multiple organizational levels.
  • Experience supporting a Cyber Incident Response Coordinator, Cyber Incident Management, Incident Command, or Major Incident Management function.
  • Experience with Power Automate, Power Apps, SOAR platforms, Copilot, AI‑enabled automation, or comparable workflow technologies.
  • Experience integrating security technologies such as SIEM, SOAR, EDR, ticketing platforms, and APIs.
  • Experience leading cybersecurity automation, process‑improvement, or operational transformation initiatives.
  • Experience developing dashboards, key performance indicators, operational metrics, and executive reporting.
  • Knowledge of cybersecurity incident response, security operations, risk management, and governance practices.
  • Relevant certifications such as CISSP, CISM, GCIH, PMP, CAPM, Scrum, Agile, ITIL, or equivalent.
General Description of Available Benefits for Eligible Employees of Truist Financial Corporation:

All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax‑preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full‑time or part‑time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non‑temporary position for which you apply, based on full‑time or part‑time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace. EEO is the Law E‑Verify IER Right to Work

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Incident Management Engineer
Cyber Incident Management Engineer

Truist • Atlanta (GA)

On-site
USD 120,000 - 170,000
Medical
Dental
Vision
+5
Cyber Incident Management Engineer
Cyber Incident Management Engineer

Truist • Greensboro (NC)

On-site
USD 110,000 - 140,000
Medical insurance
Dental insurance
Vision insurance
+11
Cyber Incident Management Engineer
Cyber Incident Management Engineer

Crump Life Insurance Svcs Inc • Greensboro (NC)

On-site
USD 120,000 - 165,000
Medical benefits
401(k) plan
Paid time off
Security Engineer
Security Engineer

Truist • Atlanta (GA)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Technology Operations Consultant - Vulnerability Remediation Engineer
Technology Operations Consultant - Vulnerability Remediation Engineer

Truist • Raleigh (NC)

On-site
USD 110,000 - 140,000
Medical insurance
Dental insurance
Vision insurance
+6
Senior Information Security Consultant
Senior Information Security Consultant

Habitat For Humanity Of Durham • Raleigh (NC)

On-site
USD 120,000 - 180,000
Medical
Dental
Vision
+11
Chief Cybersecurity Risk Officer
Chief Cybersecurity Risk Officer

Truist • Atlanta (GA)

On-site
USD 300,000 - 400,000
Medical, dental, vision benefits
401k plan and retirement benefits
Paid time off and holidays
Senior Information Security Consultant
Senior Information Security Consultant

Fayette Chamber of Commerce • Atlanta (GA)

On-site
USD 120,000 - 180,000
Medical
Dental
Vision
+11
Senior Information Security Consultant
Senior Information Security Consultant

Truist • Raleigh (NC)

On-site
USD 115,000 - 170,000
Medical, dental, vision
401k plan
Paid vacation and holidays
+2
Senior Information Security Consultant
Senior Information Security Consultant

Truist • Atlanta (GA)

On-site
USD 140,000 - 190,000
Medical benefits
Dental benefits
Vision benefits
+4