- Conduct penetration tests against enterprise applications, infrastructure, cloud platforms, AI systems, APIs, mobile applications, Active Directory environments, and other technology assets
- Simulate real-world attack techniques to identify vulnerabilities, attack paths, misconfigurations, and security weaknesses
- Perform validation and retesting to verify remediation and confirm risk reduction
- Document technical findings with reproduction steps, evidence, business impact, and remediation recommendations
- Maintain testing artifacts and evidence for regulatory, audit, and compliance requirements
- Defend findings with application teams, technology leaders, and stakeholders
- Participate in escalation calls involving disputed findings, risk discussions, and remediation planning
- Collaborate with internal and external testing teams to improve testing coverage and effectiveness
- Contribute to AI security testing initiatives and emerging offensive security capabilities
- Support AI model evaluation, testing, training, and security validation
- Improve testing methodologies, automation, tooling, and operational processes
- Perform peer reviews of penetration testing reports and deliverables
- Provide technical guidance and mentorship to junior security professionals
- Collaborate across security, engineering, development, infrastructure, application teams, and management
- Assist with standards, procedures, playbooks, and testing documentation
- Support special projects and security initiatives
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience
- Minimum of 7 years of experience in security engineering or related cybersecurity roles
- Deep specialized knowledge of cybersecurity principles, theories, and concepts
- Proven experience in software development lifecycle security practices
- Deep knowledge of threat modeling, security testing, and penetration testing
- Experience implementing and managing complex information security technologies
- 5+ years of penetration testing, red teaming, offensive security, vulnerability research, or related cybersecurity experience
- Experience with AI Security Testing and/or Mainframe Security Testing
- Experience conducting penetration testing, red team, and security assessments across diverse environments and technologies
- Experience with scripting, automation, and offensive security tool development
- Strong technical writing and communication skills
- Ability to articulate technical risks to technical and non-technical audiences
- Ability to independently manage multiple engagements
- Experience defending technical findings and participating in stakeholder discussions
- Strong analytical and problem-solving skills
- Banking, financial services, or highly regulated industry experience preferred
- Relevant certifications such as OSCP+, OSEP, OSED, OSEE, OSWE, OSWA, OSAI, GPEN, GWAPT, GXPN, GRTP, GCFA, CISSP, CRIS, CPTS, or equivalent certifications may be held
- English language fluency required
- Applicant must have U.S. work authorization; Truist will not sponsor work visas or employment authorization
Core Competencies
Demonstrates extensive expertise in penetration testing, vulnerability assessment, and security engineering, with a strong focus on AI security testing and compliance within highly regulated industries. Capable of effectively communicating technical risks and collaborating across diverse teams to enhance security practices and methodologies.
Highest-signal resume keywords
- Penetration Testing
- AI Security Testing
- Vulnerability Research
- Technical Writing
- Cybersecurity Principles
ATS Optimization Keywords
Hard Skills
- Penetration Testing
- Vulnerability Assessment
- Threat Modeling
- Security Testing
- Scripting
- Automation
- Offensive Security Tool Development
- Software Development Lifecycle Security
- Risk Assessment
- Compliance Documentation
Soft Skills
- Analytical Skills
- Problem-Solving Skills
- Communication Skills
- Collaboration
- Mentorship
Certifications & Qualifications
- OSCP+
- OSEP
- OSED
- OSEE
- OSWE
- OSWA
- OSAI
- GPEN
- GWAPT
- CISSP
Industry Keywords
- Cybersecurity
- Financial Services
- Regulatory Compliance
- Red Teaming
- Offensive Security