Truist Bank-posted 9 days ago
Full-time • Principal
Onsite • Charlotte, NC
5,001-10,000 employees

In Office 5v day a week Support cyber security Identity Access Management (IAM) capabilities necessary for safeguarding the firm's information systems and applications for Microsoft Azure/M365/AWS programs while working in a multiple-team environment. Essential Duties and Responsibilities Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time. Identity & Access Management: Design and implement enterprise Azure AD solutions including Conditional Access, MFA, Privileged Identity Management (PIM), and passwordless authentication while ensuring zero-trust security principles Configure and manage Azure RBAC, custom role definitions, and Azure AD roles to enforce least-privilege access across cloud resources and applications Implement identity governance frameworks including access reviews, lifecycle management, and automated provisioning/deprovisioning workflows Cloud Security Architecture: Architect and deploy defense-in-depth security controls using Azure Security Center, Microsoft Defender for Cloud, and Azure Sentinel for threat detection and response Design and implement network security solutions including Azure Firewall, NSGs, Application Gateway WAF, and private endpoints to secure cloud workloads Configure Azure Policy, Blueprints, and management groups to enforce security compliance and governance standards across subscriptions Security Operations & Compliance: Monitor and respond to security incidents using Azure Sentinel SIEM/SOAR, implementing automated playbooks and investigation workflows Implement data protection strategies using Azure Key Vault for secrets management, encryption at rest/in transit, and Azure Information Protection Ensure compliance with regulatory requirements (SOC2, HIPAA, GDPR) through Azure Compliance Manager and continuous security assessments DevSecOps & Automation: Integrate security into CI/CD pipelines using Azure DevOps, implementing infrastructure as code (Terraform/Bicep) with built-in security controls Develop PowerShell and Azure CLI scripts to automate security tasks, compliance reporting, and identity management operations Implement container security for AKS environments including pod security policies, Azure AD integration, and container image scanning Required Qualifications: The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Design and implement enterprise Azure AD solutions including Conditional Access, MFA, Privileged Identity Management (PIM), and passwordless authentication while ensuring zero-trust security principles
  • Configure and manage Azure RBAC, custom role definitions, and Azure AD roles to enforce least-privilege access across cloud resources and applications
  • Implement identity governance frameworks including access reviews, lifecycle management, and automated provisioning/deprovisioning workflows
  • Architect and deploy defense-in-depth security controls using Azure Security Center, Microsoft Defender for Cloud, and Azure Sentinel for threat detection and response
  • Design and implement network security solutions including Azure Firewall, NSGs, Application Gateway WAF, and private endpoints to secure cloud workloads
  • Configure Azure Policy, Blueprints, and management groups to enforce security compliance and governance standards across subscriptions
  • Monitor and respond to security incidents using Azure Sentinel SIEM/SOAR, implementing automated playbooks and investigation workflows
  • Implement data protection strategies using Azure Key Vault for secrets management, encryption at rest/in transit, and Azure Information Protection
  • Ensure compliance with regulatory requirements (SOC2, HIPAA, GDPR) through Azure Compliance Manager and continuous security assessments
  • Integrate security into CI/CD pipelines using Azure DevOps, implementing infrastructure as code (Terraform/Bicep) with built-in security controls
  • Develop PowerShell and Azure CLI scripts to automate security tasks, compliance reporting, and identity management operations
  • Implement container security for AKS environments including pod security policies, Azure AD integration, and container image scanning
  • Bachelor’s degree in Computer Science or related field or equivalent education and related training
  • Eight years of experience in Cybersecurity or related work
  • Broad knowledge of general IT with mastery of one or more of the following areas: operating systems, networking, computer programing, web development or database administration
  • Demonstrated advanced knowledge of cyber security operations with mastery of one or more of the following: attack surface management, Security Operations Center (SOC) operations, Intrusion Detection/Intrusion Prevention Systems (IDS/IPS), Security Information and Event Management (SIEM) use, threats (including Advanced Persistent Threat (APT), insider), vulnerabilities, and exploits; incident response, investigations and remediation
  • Experience with systems for automated threat intelligence sharing using industry standard protocols, such as Structured Threat Information Expression (STIX) and Trusted Automated Exchange of Indication Information (TAXII)
  • Advanced knowledge of processes, procedures and methods to research, analyze and disseminate threat intelligence information
  • Ability to lead and persuade individuals and large teams on ideas, concepts and opportunities
  • Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates.
  • Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays.
  • Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service