Security Engineer (Application Security)

Socket.dev

Atlanta (GA)

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical benefits
Dental benefits
401(k) plan

Job summary

Truist Financial Corporation is seeking an experienced Application Security Engineer to design and implement security across the software development lifecycle. This role partners with developers, DevOps, and security teams to embed secure coding practices and remediation workflows.

The ideal candidate has 5+ years in security engineering, strong knowledge of SAST/SCA, IaC security, and cloud-native security.

Qualifications

  • Strong experience with application security testing methodologies and tools, including SAST, SCA, Secrets Detection, and IaC Security.
  • Solid understanding of vulnerability management, risk assessment, and remediation practices.
  • Proficiency in one or more programming or scripting languages, such as Python, Java, .NET, or similar technologies.
  • Experience with Git-based development workflows, source control management, and CI/CD pipeline integration.
  • Hands-on experience with application security and vulnerability scanning platforms such as GitLab Advanced SAST, JFrog Xray, or equivalent solutions.
  • Experience with cloud platforms and cloud-native application security practices is preferred.
  • Ability to collaborate effectively with developers, DevOps engineers, and security teams to integrate security throughout the software development lifecycle.

Responsibilities

  • Designs and implements application security solutions to protect assets and support secure software development.
  • Analyzes, prioritizes, and tracks remediation of vulnerabilities identified through security scanning tools.
  • Partners with development and DevOps teams to promote secure coding practices and integrate security controls into CI/CD pipelines.
  • Supports security testing, control validation, audits, compliance activities, and evidence collection.
  • Develops and maintains security standards, baselines, procedures, metrics, reports, and documentation.
  • Serves as a technical escalation point for complex security issues, providing root cause analysis and remediation guidance.
  • Evaluates emerging threats, security tools, and architecture options to improve security posture.
  • Provides technical leadership, mentoring, and knowledge sharing across engineering and security teams.
  • Leads application security initiatives and coordinates security engineering efforts to ensure quality, consistency, and compliance.

Skills

SAST
SCA
Secrets Detection
IaC Security
Vulnerability Mgmt
Python
Java
.NET
CI/CD
Git-based workflows
Cloud security

Education

Bachelor’s degree

Tools

GitLab Advanced SAST
JFrog Xray

Job description

Need Help?

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary:

Regular

Language Fluency: English (Required)

Work Shift:

1st shift (United States of America)

Please review the following job description:

Designs and implements application security capabilities across the software development lifecycle, including secure development, security scanning, testing, and vulnerability management.

Builds and enhances scalable, reliable, and secure technology solutions by analyzing trends, establishing security baselines, and preparing for future requirements.

Collaborates closely with developers, DevOps engineers, and security teams to identify, assess, and remediate security vulnerabilities across diverse technologies and platforms.

ESSENTIAL DUTIES AND RESPONSIBILITIES Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.

  • Designs and implements application security solutions to protect critical assets and support secure software development.

  • Analyzes, prioritizes, and tracks remediation of vulnerabilities identified through security scanning tools.

  • Partners with development and DevOps teams to promote secure coding practices and integrate security controls into CI/CD pipelines.

  • Supports security testing, control validation, audits, compliance activities, and evidence collection.

  • Develops and maintains security standards, baselines, procedures, metrics, reports, and documentation.

  • Serves as a technical escalation point for complex security issues, providing root cause analysis and remediation guidance.

  • Evaluates emerging threats, security tools, and architecture options to improve security posture.

  • Provides technical leadership, mentoring, and knowledge sharing across engineering and security teams.

  • Leads application security initiatives and coordinates security engineering efforts to ensure quality, consistency, and compliance.

Technical Skills Qualifications

  • Strong experience with application security testing methodologies and tools, including SAST, SCA, Secrets Detection, and Infrastructure as Code (IaC) Security.

  • Solid understanding of vulnerability management, risk assessment, and remediation practices.

  • Proficiency in one or more programming or scripting languages, such as Python, Java, .NET, or similar technologies.

  • Experience with Git-based development workflows, source control management, and CI/CD pipeline integration.

  • Hands-on experience with application security and vulnerability scanning platforms such as GitLab Advanced SAST, JFrog Xray, or equivalent solutions.

  • Experience with cloud platforms and cloud-native application security practices is preferred.

  • Ability to collaborate effectively with developers, DevOps engineers, and security teams to integrate security throughout the software development lifecycle.

Required Qualifications The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Bachelor’s degree or equivalent education, training, and work-related experience.

  • Minimum of 5 years of experience in security engineering or related cybersecurity roles.

  • Advanced knowledge in cybersecurity principles, theories, and concepts.

  • Proven experience in software development lifecycle security practices.

  • Advanced knowledge of threat modeling, security testing, and penetration testing.

  • Experience implementing and managing complex information security technologies.

Preferred Qualifications

  • Understanding of security controls, risk management, and compliance requirements.

  • Strong analytical, communication, documentation, and problem-solving skills.

  • Industry certifications such as CISSP, CEH, or similar certifications are a plus.

  • Experience working in an Agile development environment is preferred.

  • Demonstrated eagerness to learn new technologies and grow within the application security field.

General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position.Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.

EEO is the Law E-Verify IER Right to Work

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer (Application Security Testing)
Security Engineer (Application Security Testing)

Truist • Atlanta (GA)

On-site
USD 120,000 - 160,000
Medical, dental, vision
401k plan and pension options
Vacation & holidays
Security Engineering Director
Security Engineering Director

Truist • Atlanta (GA)

On-site
USD 150,000 - 210,000
Security Engineer
Security Engineer

Truist • Atlanta (GA)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Senior Security Engineer
Senior Security Engineer

Truist • Raleigh (NC)

On-site
USD 120,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+7
Senior Security Engineer
Senior Security Engineer

Truist • Charlotte (NC)

On-site
USD 140,000 - 195,000
Medical benefits
Dental benefits
Vision benefits
+5
Senior Security Engineer
Senior Security Engineer

Truist • Atlanta (GA)

On-site
USD 150,000 - 210,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Security Data Engineer
Senior Security Data Engineer

Habitat For Humanity Of Durham • Raleigh (NC)

On-site
USD 130,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+2
Senior Information Security Consultant
Senior Information Security Consultant

Fayette Chamber of Commerce • Atlanta (GA)

On-site
USD 120,000 - 180,000
Medical
Dental
Vision
+11
Cyber Incident Management Engineer
Cyber Incident Management Engineer

Crump Life Insurance Svcs Inc • Greensboro (NC)

On-site
USD 120,000 - 165,000
Medical benefits
401(k) plan
Paid time off
Cyber Incident Management Engineer
Cyber Incident Management Engineer

Truist • Raleigh (NC)

On-site
USD 110,000 - 160,000
Medical, dental, vision
401k plan
Vacation days
+2