Full-Time

Cybersecurity Senior Engineer

Threat Engineering Detection Team

Posted on 9/19/2025

Truist Bank

Truist Bank

10,001+ employees

Offers integrated banking, lending, wealth management

No salary listed

Raleigh, NC, USA + 2 more

More locations: Charlotte, NC, USA | Atlanta, GA, USA

In Person

Category
IT & Security (2)
,
Requirements
  • Bachelor’s degree and eight years of experience in systems engineering or administration or an equivalent combination of education and work experience
  • Deep specialized and/or broad functional knowledge in applied enterprise information security technologies including but not limited to firewalls, intrusion detection/prevention systems, network operating systems, identity management, database activity monitoring, encryption, content filtering, and Mainframe security
  • Previous experience in leading complex IT projects
  • Language: English (Required)
  • Work Shift: 1st shift (United States of America)
  • Regular employment status
Responsibilities
  • Detection Engineering: Design, develop, and maintain high-fidelity detections across Splunk, Snowflake, and related platforms
  • Content Development: Author SPL-based detections (Splunk) and SQL-based queries (Snowflake, MySQL, PostgreSQL, SQL Server)
  • Snowflake Engineering: Design and optimize queries within Snowflake for detection logic and threat hunting
  • Snowflake Engineering: Configure and maintain Snowpipe pipelines for real-time and batch ingestion of security-relevant data
  • Snowflake Engineering: Partner with data engineering to ensure schema design and ingestion pipelines support scalable detection use cases
  • Pipeline Engineering (Future State): Design and maintain integrations with Cribl/Databahn (or similar platforms) for log routing, transformation, and observability pipeline efficiency, telemetry enrichment, normalization, and cost-optimized data movement
  • Platform Administration: Provide administrative expertise for Splunk and Snowflake environments, ensuring resilience, scalability, and performance
  • Threat Modeling & Framework Alignment: Map detections to the MITRE ATT&CK framework to ensure comprehensive threat coverage
  • Anvilogic-Driven Detection Engineering: Use detection-as-code workflows for structured creation, testing, and deployment of detections
  • Anvilogic-Driven Detection Engineering: Leverage Anvilogic content packs and extend/customize them for organization-specific threats
  • Anvilogic-Driven Detection Engineering: Orchestrate multi-platform detection deployment across Splunk, Snowflake, and other SIEM/data lake platforms
  • Anvilogic-Driven Detection Engineering: Apply coverage analytics within Anvilogic to identify detection gaps and validate against MITRE ATT&CK
  • Anvilogic-Driven Detection Engineering: Manage the full lifecycle of detections including creation, validation, deployment, tuning, and retirement within Anvilogic
  • Anvilogic-Driven Detection Engineering: Collaborate with SOC and IR teams to streamline workflows and reduce false positives using Anvilogic-driven integration
  • Regulatory Alignment: Engineer detection solutions with compliance in mind (e.g., PCI-DSS, HIPAA, SOX, GLBA)
  • Collaboration: Partner with SOC, IR, Threat Intel, Red/Purple, Continuous Security Validation, and Data Engineering teams to validate detections, minimize false positives, and strengthen visibility
Desired Qualifications
  • 5+ years of experience in detection engineering, threat engineering, or a related security role
  • Strong expertise in Splunk SPL and detection development
  • Proficiency with SQL (MySQL, PostgreSQL, SQL Server)
  • Hands-on experience with Snowflake, including: Authoring SQL-based detections and threat hunts; Designing and managing Snowpipe pipelines for security data ingestion
  • Proven Splunk and Snowflake administration experience
  • Demonstrated ability to align detections to the MITRE ATT&CK framework
  • Experience operating in highly regulated industries
  • Hands-on experience with Anvilogic (detection-as-code, orchestration, coverage analytics, lifecycle management)
  • Hands-on experience with Cribl/Databahn or similar for log routing, enrichment, and observability pipelines cost-optimized telemetry and data engineering integration
  • Relevant certifications: Splunk Certified Architect, SnowPro Core/Advanced, GIAC (GCDA, GCED, etc.)
  • Experience with No-Code/Low-Code Security Detection Engineering tools
  • Python development experience
  • Docker, Kubernetes, containerization pipeline, and deployment experience
  • Banking or financial services experience
  • Other security certifications (e.g. GSEC, GCED, GPPA, etc.)
  • Experience operationalizing Cyber use cases with Large Language Models (LLMs)

Truist provides banking, lending, and wealth management services to individuals, small businesses, and large corporations across the United States. It operates through integrated relationship management, offering personal and commercial banking, loan products, and advisory wealth services. Customers access deposits, loans, payment services, and investment advice, with revenue coming from interest on loans, banking fees, and advisory fees. The firm differentiates itself by delivering coordinated financial solutions across different client segments and by pursuing strategic partnerships and community initiatives to support local development. Its goal is to inspire and build better lives and communities by helping clients manage money, grow assets, and strengthen relationships with their bank.

Company Size

10,001+

Company Stage

IPO

Headquarters

Washington DC, District of Columbia

Founded

2018

Simplify Jobs

Simplify's Take

What believers are saying

  • Q1 2026 earnings beat with $5.20B revenue and $1.09 adjusted EPS exceeding estimates.
  • $500M+ Infosys GCC contract extends two-decade partnership and reduces operational costs.
  • $260M Credibly securitization positions Truist as lead structuring agent for SMB lending.

What critics are saying

  • Net interest margin compression from deposit competition erodes core profitability versus peers.
  • Infosys GCC dependency creates operational risk if vendor fails or transfer stalls.
  • Credibly's $3B+ SMB portfolio faces credit deterioration if AI underwriting model fails.

What makes Truist Bank unique

  • Leading market share in seven of top ten fastest-growing U.S. markets with $549B assets.
  • Digital channels capture 45% of new-to-bank clients, particularly Gen Z and millennials.
  • Integrated relationship management across consumer, commercial, investment banking, and wealth management.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Health Savings Account/Flexible Spending Account

Unlimited Paid Time Off

Paid Vacation

Paid Sick Leave

Paid Holidays

Hybrid Work Options

401(k) Retirement Plan

401(k) Company Match

Company Equity

Company News

Yahoo Finance
Apr 13th, 2026
Truist cuts Camping World price target to $14 amid weak RV sales

Camping World Holdings, Inc. (NYSE:CWH) received a Buy rating from Truist on 9 April, though the firm reduced its price target to $14 from $15. Analyst Michael Swartz noted North American RV retail revenues declined in the low-20% range in February, following a 10.8% drop in January. The company reported fourth-quarter 2025 adjusted EBITDA of $242.9 million, up over 35%, whilst posting a net loss of $105.6 million due to deferred tax asset changes. CEO Matthew Wagner highlighted 4% growth in same-store vehicle unit revenue and record market share exceeding 13%. Camping World finished 2025 with $215 million in cash and $1.472 billion in long-term debt, representing 5.7x net leverage. The company projects 2026 adjusted EBITDA between $275 million and $325 million.

Yahoo Finance
Apr 13th, 2026
Delek Logistics Partners (DKL) Secures $1.3 Billion Credit Facility

Delek Logistics Partners, LP (NYSE:DKL) is one of the MLP Stocks List: 20 Largest MLPs. On March 26, 2026, Delek Logistics Partners, LP (NYSE:DKL) announced it had secured a new $1.3 billion revolving credit agreement. Led by Truist Bank, the new credit facility allows the company to effectively refinance its existing debt. The facility matures […]

Stock Titan
Mar 27th, 2026
National Fuel Gas (NYSE: NFG) secures $1.3B credit line to 2031

National Fuel Gas Company secured a $1.3B unsecured revolving credit facility maturing in 2031, with rate spreads tied to credit ratings and a 0.65 debt-to-capitalization covenant.

Belmont University
Mar 26th, 2026
Belmont student-athletes host annual Battle of the Bruins presented by Truist.

Belmont student-athletes host annual Battle of the Bruins presented by Truist. Belmont athletes partner with Special Olympians for the event. NASHVILLE, Tenn. - Last night, the Belmont Student-Athlete Advisory Committee (SAAC) hosted its annual Battle of the Bruins presented by Truist on the Belmont campus. The event featured Belmont student-athletes from all 17 teams competing in different types of games along with Special Olympians. "Once again, we had another incredible Battle of the Bruins," said Ryan Neises, Belmont's Director of Spiritual Formation. "It's so great to see the Special Olympians as they join us in competition, fellowship, and fun. They joy and enthusiasm impacts all of our athletes every time we interact with them." All proceeds raised for the event will go to Special Olympics Nashville.

Teknovation.biz
Mar 19th, 2026
Truist marks a century of economic impact in Knoxville.

Truist marks a century of economic impact in Knoxville. "Tennessee has played an important role in Truist's story, and Knoxville is a cornerstone of that legacy," said Johnny Moore, Truist Tennessee Regional President. While the Truist name and branding may be newer to Knoxville, the bank's history in the city dates to 1926, when the Bank of Knoxville first opened its doors downtown. "For a century, this bank has grown alongside Knoxville," said Harry Gross, Truist Market President for East Tennessee. "Even as our name has changed over the years, our commitment to this community has never wavered. We are proud of our history here and energized about continuing to serve Knoxville for the next 100 years." These quick numbers only scrape the surface of the bank's impact on the local community: * 17 branches in the Knoxville area * 30 ATMs * No. 2 in deposit market share * 450+ volunteer hours from Truist teammates in 2025 * $250,000+ in grants over the last two years to support Knoxville communities A night of celebration. Truist celebrated this milestone with an event on Wednesday evening. During the event, the Knoxville Mayor Indya Kincannon proclaimed March 18, 2026, as Truist Centennial Celebration Day. The event was held at the Knoxville Museum of Art and was open to key players who have been part of the bank's history. To further honor the milestone, Truist sponsored one of the museum's rotating exhibits. "Our support of the arts reflects our belief that vibrant communities depend on creativity and dialogue," Gross said. "Partnering with the Knoxville Museum of Art during this milestone year is a purposeful way to celebrate Knoxville's culture while looking forward together." A commitment to workforce development. Guided by the bank's purpose to "inspire and build better lives and communities," Truist invested a recent $125,000 grant to the Roane State Community College Foundation in support of its Simulation Center at the Knox Regional Health Science Educator Center. The 130,000-square-foot facility is designed to address Tennessee's growing healthcare workforce shortages by advancing high-quality healthcare education. "Tennessee has played an important role in Truist's story, and Knoxville is a cornerstone of that legacy," said Johnny Moore, Truist Tennessee Regional President. "This milestone is not just about honoring our past, but about reaffirming our commitment to listen, to lead and to invest in the people and places we serve." Like what you've read?

INACTIVE