Senior Security Engineer- Threat Engineering Detection Team

Truist Financial
Atlanta, Raleigh, Charlotte
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 7+ yearsEducation: bachelorsSkills: ["Strategic mindset","Collaboration","Accuracy","Attention to detail"]

Design, develop, and optimize enterprise threat detections across Splunk and Snowflake, including real-time/batch ingestion with Snowpipe. Build and extend detection-as-code workflows using Anvilogic for multi-platform orchestration, coverage analytics, and full lifecycle management of detections. Author SPL and SQL queries, align detections to MITRE ATT&CK, and partner with SOC, IR, threat intel, and data engineering to reduce false positives and improve visibility in highly regulated environments.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Truist Financial
Truist Financial
15 hours ago

Senior Security Engineer- Threat Engineering Detection Team

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 15 hours agoStatus: Live

Job Summary

Design, develop, and optimize enterprise threat detections across Splunk and Snowflake, including real-time/batch ingestion with Snowpipe. Build and extend detection-as-code workflows using Anvilogic for multi-platform orchestration, coverage analytics, and full lifecycle management of detections. Author SPL and SQL queries, align detections to MITRE ATT&CK, and partner with SOC, IR, threat intel, and data engineering to reduce false positives and improve visibility in highly regulated environments.
Location: Atlanta, Raleigh, Charlotte
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Design, develop, and maintain high-fidelity detections across Splunk, Snowflake, and related platforms.
  • •Author SPL-based detections and SQL-based queries for detection development and threat hunting.
  • •Optimize Snowflake detection logic and configure/maintain Snowpipe pipelines for security data ingestion.
  • •Use Anvilogic detection-as-code workflows to create, test, deploy, tune, and retire detections and manage coverage analytics.
  • •Align detections to MITRE ATT&CK and partner with SOC, IR, threat intel, and data engineering to minimize false positives and strengthen visibility.

Pay and Benefits

Perks:Health InsuranceDentalVisionLife Insurance401kPaid Leave

Key Requirements

  • •Bachelor’s degree or equivalent education, training, and work-related experience.
  • •Minimum of 7 years of experience in security engineering or related cybersecurity roles.
  • •Deep specialized knowledge of cybersecurity principles, theories, and concepts.
  • •Proven experience applying security practices across the software development lifecycle.
  • •Deep knowledge of threat modeling, security testing, and penetration testing.
Experience:7+ yearsCybersecurityDetection engineeringThreat engineeringHighly regulated industriesSOC/IR collaborationFinancial services
Education:Bachelor's
Skills:Strategic mindsetCollaborationAccuracyAttention to detail
Certifications:Splunk Certified ArchitectSnowPro CoreSnowPro AdvancedGIAC (GCDA)GIAC (GCED)GIAC (etc.)GSECGCEDGPPAGCDA
Languages:English
Tech Stack:AnvilogicSplunkSplunk SPLSnowflakeSnowpipeCriblDatabahnSQLMySQLPostgreSQLSQL ServerMITRE ATT&CKPCI-DSSHIPAASOXGLBADetection-as-codeData pipelinesThreat huntingCyber use cases

Company Brief

Truist Financial
Provides consumer and commercial banking, wealth management, insurance, lending, and payments services through a large U.S. financial services platform formed by the merger of BB&T and SunTrust.
Industry: Banking
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Charlotte, United States
Founded: 2019
WebsiteLinkedIn