Truist Financial

Associate Application Security Engineer - Bug Bounty & Vulnerability Management

Truist Financial$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent experience in cybersecurity or related field.
  • At least 3 years of experience in security engineering or related roles.
  • Basic understanding of cybersecurity principles and concepts.
  • Knowledge of security practices in software development lifecycle.
  • Experience with information security technologies.

Responsibilities

  • Review and validate vulnerability reports from the Bug Bounty program.
  • Coordinate with internal teams to remediate and verify vulnerabilities.
  • Conduct threat modeling and vulnerability assessments across platforms.
  • Perform root cause analysis on security issues to mitigate risks.
  • Provide guidance on secure coding and security design practices.
  • Analyze trends in emerging threats and vulnerabilities to inform security measures.
  • Support implementation of security technologies and control standards.
  • Assist with incident response and forensics as required.

Benefits

  • Remote work flexibility for qualified candidates outside the Truist footprint.
  • Opportunity to work hours accommodating Eastern Standard Time.
Full Job Description
Manages and triages submissions to the Bug Bounty program, validating reported vulnerabilities, assessing impact and severity, and coordinating remediation efforts with internal teams. Applies cybersecurity expertise to analyze findings, identify trends, improve vulnerability response processes, and help strengthen the organization's overall security posture while continuously expanding technical knowledge of emerging threats and attack techniques.

***Telecommuting/Remote workstyle will be considered for well-qualified individuals located outside of the Truist footprint. Teammate will work hours supporting Eastern Standard Time***

ESSENTIAL DUTIES AND RESPONSIBILITIES
Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
  • Reviews, validates, and triages vulnerability reports submitted through the Bug Bounty program, assessing risk, impact, exploitability, and business relevance.
  • Partners with product, engineering, and security teams to investigate reported findings, coordinate remediation efforts, and verify resolution of identified vulnerabilities.
  • Performs threat modeling, security testing, vulnerability analysis, and penetration testing activities to identify and assess security weaknesses across assigned platforms and services.
  • Investigates security issues escalated within the team, conducts root cause analysis, and drives corrective actions that reduce recurring vulnerabilities and systemic risks.
  • Provides technical guidance on vulnerability remediation, secure coding practices, and security design considerations to support secure-by-design principles.
  • Reviews emerging threats, attack techniques, and vulnerability trends from internal assessments, bug bounty submissions, and external research to improve security controls and defensive capabilities.
  • Supports the implementation and maintenance of security technologies, control frameworks, security baselines, and configuration standards across assigned systems and applications.
  • Works with internal stakeholders to prioritize remediation activities based on severity, exploitability, business impact, and regulatory requirements.
  • Assists with incident response, forensic investigations, and security assessments as needed, leveraging findings to improve detection, prevention, and response capabilities.
  • Tracks and reports on vulnerability remediation progress, recurring security issues, and program metrics to support risk management and continuous improvement efforts.
  • Plans and manages work activities to meet established objectives, continuously developing technical expertise in application security, vulnerability management, and offensive security techniques.


Qualifications
Required Qualifications
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
  • Bachelor's degree or equivalent education, training, and work-related experience.
  • Minimum of 3 years of experience in security engineering or related cybersecurity roles.
  • Developing knowledge in cybersecurity principles, theories, and concepts.
  • Experience in software development lifecycle security practices.
  • Proficiency in implementing and managing information security technologies.


Preferred Qualifications
  • Experience participating in Bug Bounty Programs (BBP) and Vulnerability Disclosure Programs (VDP), including vulnerability triage, validation, and remediation coordination.
  • Active involvement in the bug bounty, security research, or threat hunting community, with a demonstrated passion for discovering, analyzing, and understanding emerging security threats and attack techniques.
  • Strong desire to continuously learn and expand technical expertise in application security, vulnerability research, offensive security methodologies, and security tooling.
  • Familiarity with security automation, threat detection technologies, emerging cybersecurity trends, and risk-based approaches to vulnerability management and remediation.


***Telecommuting/Remote workstyle will be considered for well-qualified individuals located outside of the Truist footprint. Teammate will work hours supporting Eastern Standard Time***

About Truist Financial

Truist Financial Careers

Join the dynamic team at Truist Financial, a leader in the financial services sector, and propel your career to new heights. At Truist Financial, we offer more than just job opportunities; we provide a platform for professional growth and innovation in an environment that values diversity and leadership.

Why Truist Financial?

At Truist Financial, we are committed to building a diverse and inclusive workplace where every team member is empowered to contribute their unique skills and perspectives. We believe that our strength lies in our diversity, and we are dedicated to fostering a culture that embraces the differences that make each of us unique.

Explore a World of Opportunities

Whether you're seeking your first internship or a seasoned professional looking to advance your career, Truist Financial offers a range of employment opportunities across various disciplines. Our team is growing, and we are constantly looking for talented individuals who are eager to make an impact.

Innovate and Lead

Join us and be part of a culture of innovation where your ideas can help shape the future of banking. At Truist Financial, you’ll work alongside industry leaders and have access to cutting-edge resources that foster continuous professional development and innovation.

Develop Your Career

Truist Financial is deeply invested in the career progression of our employees. We offer robust training programs, including leadership development and diversity training, to ensure you have the tools needed to succeed. Our commitment to your growth is reflected in our comprehensive benefits package, designed to support you both professionally and personally.

Networking and Professional Development

Enhance your professional network and connect with like-minded colleagues through our various networking events and community engagement initiatives. At Truist Financial, we believe in the power of connections and the impact they can have on your career.

Join Our Team

Ready to take the next step in your career? Explore the current job openings at Truist Financial. We are hiring across multiple departments, looking for passionate, curious, and innovative individuals to join our team. Check out our available positions and find the one that best matches your skills and interests.

Prepare for Your Interview

Make a great first impression. Visit our Careers page for tips on how to craft a compelling resume and succeed in your interview at Truist Financial. We are excited to see how you can contribute to our team and help us drive the future of banking.

Stay Connected

Don’t miss out on future opportunities or insights into our company culture and industry trends. Subscribe to our job alert emails and stay informed about new positions and career tips directly from our professionals. At Truist Financial, we’re not just offering jobs; we’re building careers. Join us and discover how you can make a difference and fuel your future.

SEARCH TRUIST FINANCIAL JOBS

READ CAREERS BLOG

Learn more about Truist Financial
Size
50,283 employees
Market Cap
$56.6 billion
Industry
5 Year Trend
+14.3%
NASDAQ

Similar Jobs

More Jobs at Truist Financial

More Information Technology Jobs

Find similar Associate Application Security Engineer - Bug Bounty & Vulnerability Management jobs: