Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Truist

Senior API Developer – Security Engineer, Vulnerability, Remediation

Truist

. Lead the enterprise vulnerability management program for automated API testing, including identification, assessment, prioritization, tracking, and remediation of security vulnerabilities .

Posted 9/18/2026full-timeAtlanta • North Carolina • United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in leading enterprise vulnerability management programs, implementing automated API security testing within CI/CD pipelines, and ensuring compliance with regulatory standards. Proficient in security testing, risk-based remediation strategies, and collaboration with application teams to enhance security posture.

Highest-signal resume keywords
Vulnerability ManagementSecurity TestingPenetration TestingAPI SecurityCybersecurity Principles

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security EngineeringThreat ModelingPython ScriptingAPI DevelopmentCloud Security
Soft Skills
CollaborationKnowledge SharingPlanning
Tools & Technologies
AWSMicrosoft AzureCI/CD PipelinesAPI Security Testing Tools
Certifications & Qualifications
CISSPOSCPCEHSecurity+
Industry Keywords
NIST SP 800-228FFIEC GuidelinesOWASP API Security Top 10BankingFinancial Services

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityPython

About the role

Key responsibilities & impact
  • Lead the enterprise vulnerability management program for automated API testing, including identification, assessment, prioritization, tracking, and remediation of security vulnerabilities
  • Perform security testing and penetration testing for assigned platforms and services
  • Develop risk-based remediation strategies and collaborate with application teams to reduce organizational security exposure
  • Review security threats, tools, and design options and provide input supporting technical plans and priorities
  • Perform triage and validation of security findings to reduce false positives and improve remediation effectiveness
  • Design, implement, and maintain automated API security testing capabilities within CI/CD pipelines
  • Implement and update security baselines, guardrails, and control configurations for systems and applications
  • Help maintain regulatory and policy compliance
  • Share knowledge and best practices with technical teammates during code reviews, design discussions, and pairing sessions
  • Plan and manage work to meet defined objectives and milestones

Requirements

What you’ll need
  • Bachelor’s degree or equivalent education, training, and work-related experience
  • Minimum of 7 years of experience in security engineering or related cybersecurity roles
  • Deep specialized knowledge in cybersecurity principles, theories, and concepts
  • Proven experience in software development lifecycle security practices
  • Deep knowledge of threat modeling, security testing, and penetration testing
  • Experience implementing and managing complex information security technologies
  • Working knowledge of NIST SP 800-228, FFIEC guidelines, OWASP API Security Top 10, and FAPI
  • Strong understanding of OAuth 2.0, OpenID Connect (OIDC), Mutual TLS (mTLS), and JSON Web Tokens (JWT)
  • Experience within banking or financial services environments
  • Proficiency or familiarity with Python scripting
  • Experience with API development and/or API security testing tools
  • Experience with cloud platforms such as AWS and/or Microsoft Azure
  • Familiarity with secure tool-calling patterns, API protections, model or prompt change validation, and runtime traceability for AI systems
  • Working knowledge of cloud-native security patterns, telemetry analysis, and deployment gating
  • Relevant security certifications such as CISSP, OSCP, CEH, or Security+ are preferred
  • English language fluency required

Benefits

Comp & perks
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Disability insurance
  • Accidental death and dismemberment coverage
  • Tax-preferred savings accounts
  • 401(k) plan
  • No less than 10 days of vacation during the first year of employment (prorated)
  • 10 sick days (prorated)
  • Paid holidays
  • Defined benefit pension plan (depending on position and division)
  • Restricted stock units (depending on position and division)
  • Deferred compensation plan (depending on position and division)