Cyber Incident Management Engineer
The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.
Need Help?
If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).
Regular or Temporary:
Regular
Language Fluency: English (Required)
Work Shift:
1st shift (United States of America)
Please review the following job description:
Leads enterprise cyber incident and high-risk vulnerability response efforts, coordinating cross-functional teams to assess, contain, and remediate threats. Designs and delivers automation solutions that improve Cyber Incident Management and cybersecurity program execution. Partners across security, technology, and business teams to enhance operational efficiency, accountability, reporting, and response outcomes.
Essential Duties And Responsibilities
Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
Required Qualifications
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.
EEO is the Law E-Verify IER Right to Work
Need Help?
If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).
Regular or Temporary:
Regular
Language Fluency: English (Required)
Work Shift:
1st shift (United States of America)
Please review the following job description:
Leads enterprise cyber incident and high-risk vulnerability response efforts, coordinating cross-functional teams to assess, contain, and remediate threats. Designs and delivers automation solutions that improve Cyber Incident Management and cybersecurity program execution. Partners across security, technology, and business teams to enhance operational efficiency, accountability, reporting, and response outcomes.
Essential Duties And Responsibilities
Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
- Act as Incident Manager / Incident Coordinator for information security incidents, investigations, events, zero-days, and high-risk vulnerabilities. Drive end-to-end response from intake through containment, remediation, and closure.
- Coordinate cross-functional stakeholders during incidents and operational initiatives to drive alignment, accountability, and execution.
- Design and implement automation solutions that improve Cyber Incident Management processes and operational efficiency.
- Develop workflows that support incident intake, triage, escalation, stakeholder communications, action tracking, and closure.
- Leverage scripting, APIs, AI-enabled technologies, orchestration tools, and Microsoft 365 platforms to reduce manual effort and improve consistency.
- Partner with technical and business stakeholders to translate operational requirements into scalable automation and process improvements.
- Manage cybersecurity automation projects and process improvement initiatives from planning through implementation.
- Maintain project plans, milestones, risks, issues, dependencies, action items, and executive updates.
- Develop and maintain operational dashboards, metrics, scorecards, and leadership reporting to measure performance and identify improvement opportunities.
- Analyze incidents, project, and operational data to support governance, decision making, and continuous improvement.
Required Qualifications
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Bachelor’s degree or equivalent education, training, and work-related experience.
- Minimum of 3 years of experience in security engineering or related cybersecurity roles.
- Developing knowledge in cybersecurity principles, theories, and concepts.
- Experience in software development lifecycle security practices.
- Proficiency in implementing and managing information security technologies.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Business, or a related field, or equivalent education and experience.
- Experience supporting cybersecurity operations, cyber incident management, major incident management, or related technology operations.
- Experience designing or supporting automation using scripting, APIs, workflow orchestration, artificial intelligence, or Microsoft 365 platforms.
- Experience coordinating cross-functional projects, operational initiatives, or process-improvement efforts.
- Experience gathering requirements, analyzing workflows, and translating business needs into technical or operational solutions.
- Strong organizational, analytical, facilitation, communication, and problem-solving skills.
- Ability to communicate effectively with technical and non-technical stakeholders at multiple organizational levels.
- Experience supporting a Cyber Incident Response Coordinator, Cyber Incident Management, Incident Command, or Major Incident Management function.
- Experience with Power Automate, Power Apps, SOAR platforms, Copilot, AI-enabled automation, or comparable workflow technologies.
- Experience integrating security technologies such as SIEM, SOAR, EDR, ticketing platforms, and APIs.
- Experience leading cybersecurity automation, process-improvement, or operational transformation initiatives.
- Experience developing dashboards, key performance indicators, operational metrics, and executive reporting.
- Knowledge of cybersecurity incident response, security operations, risk management, and governance practices.
- Relevant certifications such as CISSP, CISM, GCIH, PMP, CAPM, Scrum, Agile, ITIL, or equivalent.
Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.
EEO is the Law E-Verify IER Right to Work
Recommended Jobs
Senior Cybersecurity Analyst - Attack Surface Management (Hybrid - Seattle)
Posted 11 hours ago
Security Engineer - SIEM (Splunk) Platform & Operations
Posted 11 hours ago
Security Engineer
Posted 11 hours ago
Network Security Engineer - SASE
Posted 12 hours ago
IT & Security Specialist
Posted 12 hours ago

