Senior Associate Security Engineer (Cloud Security)

Truist

Charlotte (NC)

On-site

USD 110,000 - 140,000

Full time

27 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical benefits
Dental benefits
Vision benefits
401k
Vacation days
Sick days
Paid holidays

Job summary

Truist is seeking an experienced Cloud Security Engineer to implement advanced security across Azure, AWS, and on‑prem environments. You will contribute to cloud design, perform threat modeling, and drive security testing, with strong emphasis on IAM, encryption, logging, and governance.

Role requires collaboration with product, platform, and DevOps teams to enforce secure-by-design practices and policy-as-code, while maturing incident response and remediation efforts in a fast-paced environment.

Qualifications

  • Bachelor's degree or equivalent education, training, and work-related experience.
  • Minimum of 3 years of experience in security engineering or related cybersecurity roles.
  • Developing knowledge in cybersecurity principles, theories, and concepts.
  • Experience in software development lifecycle security practices.
  • Proficiency in implementing and managing information security technologies.

Responsibilities

  • Implements cybersecurity solutions protecting assets across Azure, AWS, and on-premises environments.
  • Supports cloud security architecture reviews and performs security configuration assessments and threat modeling.
  • Integrates security technologies in Azure and AWS test/production environments with automation.
  • Maintains cloud security controls including IAM, least-privilege, encryption, logging, and monitoring.
  • Uses native security services and tools to assess posture, validate remediation, and improve controls.
  • Analyzes findings, defines risk actions, and collaborates with engineering teams to resolve issues.
  • Investigates escalated security issues and performs root-cause analysis to prevent recurrence.
  • Reviews cloud threats and governance options, supporting technical plans and priorities.
  • Collaborates with product/platform/devops teams to apply security controls in development.
  • Maintains Azure/AWS security baselines and governance controls, including guardrails.
  • Supports incident response and forensic analysis using cloud logging and monitoring capabilities.
  • Shares cloud security knowledge and provides guidance during reviews and design discussions.
  • Plans and manages work to meet objectives and pursue self-development.

Skills

Security engineering
Cloud security
Threat modeling
Vulnerability management

Education

Bachelor's degree or equivalent

Tools

Azure
AWS
Infrastructure as Code
CI/CD pipelines

Job description

Need Help? If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary: Regular

Language Fluency: English (Required)

Work Shift: 1st shift (United States of America)

Please review the following job description: Implements advanced technical, cybersecurity, and Azure/AWS cloud security engineering capabilities across the software development lifecycle. Supports cloud security architecture reviews and applies defined approaches for configuration assessments, threat modeling, security testing, penetration testing, identity and access management, and vulnerability remediation for assigned systems and cloud services. Executes and enhances cybersecurity technologies by baselining cloud and on-premises systems, monitoring results, and adjusting configurations, automation, and processes to deliver reliable, scalable, compliant, and secure solutions with direct impact on the job area, while continuously building technical skills and knowledge.

Essential Duties And Responsibilities

Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.

  • Implements cybersecurity solutions that protect critical assets across Azure, AWS, and on-premises environments, contributing to cloud design and configuration decisions while following established security strategies, patterns, and guidance.
  • Supports cloud security architecture reviews and performs security configuration assessments, threat modeling, and security testing for assigned platforms and services, using defined methods to identify and remediate vulnerabilities and misconfigurations.
  • Integrates and configures information security technologies in Azure and AWS test and production environments, applying and adjusting approved configuration patterns, infrastructure-as-code, automation, and handoff steps for assigned systems.
  • Implements and maintains cloud security controls, including identity and access management, least-privilege access, network security, encryption, logging and monitoring, vulnerability management, and secure configuration baselines.
  • Uses Azure and AWS native security services and approved enterprise cloud security tools to assess security posture, investigate findings, validate remediation, and improve preventive and detective controls.
  • Analyzes cloud security findings, determines applicable risk and remediation actions, collaborates with responsible engineering teams, and validates that identified security issues are appropriately resolved.
  • Investigates security issues escalated within the team for services in scope, performing root-cause analysis and implementing practical fixes that prevent recurrence.
  • Reviews relevant cloud threats, tools, architecture options, and shared-responsibility considerations, and provides input that supports technical plans and priorities for the job area.
  • Collaborates with product, platform, application, DevOps, and engineering teammates to apply security guidelines, secure-by-design practices, cloud governance requirements, and policy-as-code controls in day-to-day development and delivery activities.
  • Implements and maintains approved Azure and AWS security baselines, guardrails, and governance controls for assigned cloud services and environments, including AWS organizational guardrails and Azure policy controls within the assigned area of responsibility.
  • Supports incident response and forensic analysis for assigned cloud services by following established playbooks and using approved Azure and AWS logging, monitoring, and security capabilities.
  • Shares cloud security knowledge and best practices with technical teammates, offering informal guidance and support during code reviews, architecture discussions, design reviews, and pairing sessions.
  • Plans and manages own work to meet defined objectives and milestones, seeking feedback, pursuing self-development, and adjusting approaches to improve quality and effectiveness over time.
Required Qualifications

The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Bachelor's degree or equivalent education, training, and work-related experience.
  • Minimum of 3 years of experience in security engineering or related cybersecurity roles.
  • Developing knowledge in cybersecurity principles, theories, and concepts.
  • Experience in software development lifecycle security practices.
  • Proficiency in implementing and managing information security technologies.
Preferred Qualifications
  • Minimum of 3 years of experience in security engineering, cloud security engineering, or related cybersecurity roles.
  • Developing knowledge of cybersecurity principles, theories, concepts, and cloud shared-responsibility models.
  • Hands-on experience implementing or assessing security controls for workloads, services, or platforms in Microsoft Azure and/or Amazon Web Services (AWS).
  • Experience with cloud identity and access management, network security, encryption, logging and monitoring, vulnerability management, and secure configuration practices.
  • Experience using scripting, APIs, infrastructure-as-code, CI/CD pipelines, or automation to implement, assess, and maintain cloud security controls.
  • Proficiency in implementing and managing information security technologies and analyzing cloud security findings through native or enterprise security tools.

General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist's generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist's defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.

EEO is the Law E-Verify IER Right to Work

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer (Application Security Testing)
Security Engineer (Application Security Testing)

Truist • Atlanta (GA)

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+2
Security Engineer
Security Engineer

Truist • Atlanta (GA)

On-site
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Cyber Incident Management Engineer
Cyber Incident Management Engineer

Truist • Charlotte (NC)

On-site
USD 140,000 - 190,000
Medical benefits
401k plan
Paid time off
Cyber Incident Management Engineer
Cyber Incident Management Engineer

Truist • Atlanta (GA)

On-site
USD 110,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+2
Senior Information Security Consultant
Senior Information Security Consultant

Habitat For Humanity Of Durham • Raleigh (NC)

On-site
USD 120,000 - 180,000
Medical
Dental
Vision
+11
Senior Information Security Consultant
Senior Information Security Consultant

Fayette Chamber of Commerce • Atlanta (GA)

On-site
USD 120,000 - 180,000
Medical
Dental
Vision
+11
Senior Security Engineer - Proxy & Cloud Security Platform
Senior Security Engineer - Proxy & Cloud Security Platform

Truist Financial • Atlanta (GA)

On-site
USD 120,000 - 150,000
Medical insurance
401k plan
Paid time off
Technology Operations Consultant - Sn. DevSecOps Engineer
Technology Operations Consultant - Sn. DevSecOps Engineer

Truist • Town of Charlotte (NY)

On-site
USD 120,000 - 170,000
Cyber Incident Management Engineer
Cyber Incident Management Engineer

Truist • Greensboro (NC)

On-site
USD 110,000 - 140,000
Medical insurance
Dental insurance
Vision insurance
+11
Java/Full-stack Engineer - Security Engineer - ON-SITE REQUIRED IN LISTED HUBS
Java/Full-stack Engineer - Security Engineer - ON-SITE REQUIRED IN LISTED HUBS

Truist • Raleigh (NC)

On-site
USD 125,000 - 150,000
Medical benefits
Vacation days
401k plan