Truist

Cybersecurity RACF Senior Engineer

Truist

full-time

Posted on:

Origin:  • 🇺🇸 United States • North Carolina

Visit company website
AI Apply
Manual Apply

Job Level

Senior

Tech Stack

Cyber SecurityFirewallsSDLC

About the role

  • Open to a Remote Talent
  • Responsible for developing and maintaining the technical IT / cyber security capabilities necessary for safeguarding the firm's information systems and applications (software development lifecycle), including every phase of the SDLC and software stack.
  • Design, plan, test and implement phases of cybersecurity technology projects.
  • This role seeks an experienced RACF engineer in the Mainframe Security team to ensure secure access control, across our mainframes including identity management, certificate administration, encryption controls.
  • This role is critical in ensuring secure and compliant access requiring the successful candidate to understand the complete user access lifecycle, privileged access administration, and risk management.
  • A role that is responsible for implementing and supporting capabilities described by industry best practices such as NIST and CRI.
  • This includes administering and maintaining RACF policies and profiles, ensuring proper RBAC, segregation of duties, controls and auditing mechanisms.
  • The team member will collaborate across IAM, other cybersecurity, infrastructure, application development, risk and audit teams.
  • This position may lead related projects in this space.
  • Additionally, this team member will build and maintain automation scripts and custom tools to streamline provisioning, monitoring and reporting of access controls.
  • Further, this senior position will mentor junior security engineers and server as a technical SME.
  • Develop and maintain the technical IT/cyber capabilities including all phases of the software development lifecycle and software stack which includes threat modeling of application designs, static application security testing (SAST), software composition analysis (SCA), dynamic application security testing (DAST), and penetration testing.
  • Lead efforts related to designing, planning, enhancing, and testing all cybersecurity technologies used throughout the enterprise including base-lining current systems, trend analysis, and capacity planning as required for future systems requirements and new technologies.
  • Analyze information to determine, recommend, and plan the use of new information security technologies, or modifications to existing equipment and systems that will provide capability for proposed project or work load, efficient operation and effective use of allotted resources
  • Lead the implementation of new information security technologies or integration of existing technologies including initial configuration, installation, change management, and operational handoff
  • Use sophisticated analytical thought through models, testing, and experience to exercise judgment and identify innovative solutions.
  • Responsible for technical support of information security technologies providing expert problem analysis and resolution in a timely manner
  • Leads teams or projects with moderate resource requirements, risk, and complexity.

Requirements

  • Bachelor’s degree and eight years of experience in systems engineering or administration or an equivalent combination of education and work experience
  • Deep specialized and/or broad functional knowledge in applied enterprise information security technologies including but not limited to firewalls, intrusion detection/prevention systems, network operating systems, identity management, database activity monitoring, encryption, content filtering, and Mainframe security
  • Previous experience in leading complex IT projects
  • Preferred Qualifications: Bachelor’s degree and ten years of experience or an equivalent combination of education and work experience. Banking or financial services experience. Other security certifications (e.g. CCNA Security, GSEC, GCED, GPPA, etc.) Other technical Certifications (e.g. CCNA, RHCE, MCSE, etc.) Certification in Information Security Management (e.g. CISSP, CRISC or CISM), or related security certification(s), Understanding of regulatory frameworks for financial institutions, Ability to collaborate across teams and influence people, Excellent communications skills, Experience in waterfall and agile project management methodologies