Join to apply for the Cybersecurity RACF Senior Engineer role at Truist .
Get AI-powered advice on this job and more exclusive features.
The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.
Need Help?
If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).
Regular or Temporary: Regular
Language Fluency: English (Required)
Work Shift: 1st shift (United States of America)
Please review the following job description:
Responsible for developing and maintaining the technical IT / cyber security capabilities necessary for safeguarding the firm's information systems and applications (software development lifecycle), including every phase of the SDLC and software stack. Design, plan, test and implement phases of cybersecurity technology projects.
This role seeks an experienced RACF engineer in the Mainframe Security team to ensure secure access control, across our mainframes including identity management, certificate administration, encryption controls. This role is critical in ensuring secure and compliant access requiring the successful candidate to understand the complete user access lifecycle, privileged access administration, and risk management. A role that is responsible for implementing and supporting capabilities described by industry best practices such as NIST and CRI. This includes administering and maintaining RACF policies and profiles, ensuring proper role-based access control (RBAC), segregation of duties, controls and auditing mechanisms. The team member will collaborate across IAM, other cybersecurity, infrastructure, application development, risk and audit teams. This position may lead related projects in this space. Additionally, this team member will build and maintain automation scripts and custom tools to streamline provisioning, monitoring and reporting of access controls. Further, this senior position will mentor junior security engineers and serve as a technical SME.
Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
Develop and maintain the technical IT/cyber capabilities including all phases of the software development lifecycle and software stack which includes threat modeling of application designs, static application security testing (SAST), software composition analysis (SCA), dynamic application security testing (DAST), and penetration testing.
Lead efforts related to designing, planning, enhancing, and testing all cybersecurity technologies used throughout the enterprise including base-lining current systems, trend analysis, and capacity planning as required for future systems requirements and new technologies.
Analyze information to determine, recommend, and plan the use of new information security technologies, or modifications to existing equipment and systems that will provide capability for proposed project or workload, efficient operation and effective use of allotted resources.
Lead the implementation of new information security technologies or integration of existing technologies including initial configuration, installation, change management, and operational handoff.
Use sophisticated analytical thought through models, testing, and experience to exercise judgment and identify innovative solutions.
Responsible for technical support of information security technologies providing expert problem analysis and resolution in a timely manner.
Lead teams or projects with moderate resource requirements, risk, and complexity.
Qualifications
Required Qualifications:
Bachelors degree and eight years of experience in systems engineering or administration or an equivalent combination of education and work experience.
Deep specialized and/or broad functional knowledge in applied enterprise information security technologies including but not limited to firewalls, intrusion detection/prevention systems, network operating systems, identity management, database activity monitoring, encryption, content filtering, and Mainframe security.
Previous experience in leading complex IT projects.
Preferred Qualifications:
Bachelors degree and ten years of experience or an equivalent combination of education and work experience.
Banking or financial services experience.
Other security certifications (e.g., CCNA Security, GSEC, GCED, GPPA).
Other technical Certifications (e.g., CCNA, RHCE, MCSE).
Certification in Information Security Management (e.g., CISSP, CRISC, CISM), or related security certifications.
Understanding of regulatory frameworks for financial institutions.
Ability to collaborate across teams and influence people.
Excellent communication skills.
Experience in waterfall and agile project management methodologies.
Benefits: All regular teammates working 20 hours or more per week are eligible for benefits, including medical, dental, vision, life insurance, disability, 401k, paid vacation, sick days, and holidays. More details are available on our Benefits site. Depending on the position, this job may also be eligible for additional plans such as pension, stock units, and deferred compensation.
Truist is an Equal Opportunity Employer and a Drug-Free Workplace. We do not discriminate based on race, gender, age, religion, or other protected classes.
#J-18808-Ljbffr