Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Truist

Application Security Engineer

Truist

. Design, configure, test, and improve advanced DAST solutions and technical patterns for complex web applications and APIs .

Posted 10/5/2026full-timeCharlotte • North Carolina • United StatesMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates advanced knowledge in cybersecurity principles and practices, with a focus on DAST solutions for web applications and APIs. Proficient in security testing, vulnerability assessment, and remediation verification, alongside strong collaboration with engineering teams.

Highest-signal resume keywords
DAST Solutions DesignSecurity TestingThreat ModelingPenetration TestingAdvanced Cybersecurity Certification

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Cybersecurity PrinciplesSoftware Development Lifecycle SecurityAuthenticated TestingSession ManagementMultifactor AuthenticationAPI SpecificationsScriptingData TransformationSecurity AutomationCI/CD Integrations
Soft Skills
CollaborationProblem SolvingTechnical Communication
Tools & Technologies
DAST TechnologiesHTTPBrowser BehaviorWeb ArchitecturesAPI Architectures
Certifications & Qualifications
CISSPCSSLPGIACGWAPTOSWE
Industry Keywords
Vulnerability AssessmentApplication SecurityInformation Security TechnologiesSecurity Testing MethodologiesEmerging Cybersecurity Technologies

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Design, configure, test, and improve advanced DAST solutions and technical patterns for complex web applications and APIs
  • Perform and validate complex authenticated assessments, including login success, session state, crawl coverage, attack surface coverage, vulnerability results, and overall assessment validity
  • Engineer DAST scan policies, authentication workflows, login sequences, session handling, API definitions, custom scripts, integrations, and automation
  • Investigate difficult assessment problems, including multifactor authentication constraints, incomplete crawling, blocked requests, dynamic application behavior, tool limitations, false positives, false negatives, and inconsistent results
  • Use browser, proxy, HTTP, API, logging, and diagnostic techniques to identify root causes and develop reusable technical solutions
  • Analyze and document DAST evidence to distinguish validated vulnerabilities, suspected false positives, coverage limitations, and inconclusive results, and support remediation verification
  • Partner with application and engineering teams to understand runtime behavior, resolve testability constraints, and establish appropriate DAST configurations
  • Serve as a technical escalation point, review complex configurations and technical evidence, and share specialized knowledge through peer reviews, troubleshooting sessions, and reusable documentation

Requirements

What you’ll need
  • Bachelor’s degree or equivalent education, training, and work-related experience
  • Minimum of 5 years of experience in security engineering or related cybersecurity roles
  • Advanced knowledge in cybersecurity principles, theories, and concepts
  • Proven experience in software development lifecycle security practices
  • Advanced knowledge of threat modeling, security testing, and penetration testing
  • Experience implementing and managing complex information security technologies
  • English language fluency required
  • Must not require work visa sponsorship or employment authorization sponsorship
  • Preferred: Advanced cybersecurity certification such as CISSP, CSSLP, GIAC, GWAPT, OSWE, or an equivalent application security credential
  • Preferred: Deep hands-on experience with enterprise DAST technologies and methodologies for complex web applications and APIs
  • Preferred: Advanced experience with authenticated testing, modern authentication protocols, session management, multifactor authentication, scripted login workflows, and credential handling
  • Preferred: Deep working knowledge of HTTP, browser behavior, web and API architectures, authentication and authorization patterns, API specifications, and common application frameworks
  • Preferred: Experience with security automation, APIs, scripting, data transformation, orchestration, CI/CD integrations, or workflow technologies
  • Preferred: Familiarity with emerging cybersecurity technologies, industry trends, and strategic risk management

Benefits

Comp & perks
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Disability insurance
  • Accidental death and dismemberment coverage
  • Tax-preferred savings accounts
  • 401(k) plan
  • At least 10 days of vacation during the first year of employment, prorated
  • 10 sick days, prorated
  • Paid holidays
  • Defined benefit pension plan (depending on position and division)
  • Restricted stock units (depending on position and division)
  • Deferred compensation plan (depending on position and division)