The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status. Need Help? If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response). Regular or Temporary: Regular Language Fluency: English (Required)
Work Shift
1st shift (United States of America) Please review the following job description: ***This role is 5 days a week in the Atlanta or Charlotte Office*** The Artificial Intelligence Security Posture Management (AiSPM) function supports two core areas: Shadow Artificial Intelligence (Shadow AI) risk reduction and AI Security Review/Governance for enterprise AI use cases. This Senior AI Security Engineer will help identify, evaluate, document, and reduce AI-related security risk across approved, emerging, and unapproved AI usage patterns. The role uses security and governance tooling such as CrowdStrike, Wiz, Zscaler, and supporting enterprise workflows to analyze AI exposure, validate ownership, support remediation, and maintain repeatable review evidence. Strong candidates will understand cloud security, software security, data protection, security governance, and enterprise risk management, with the ability to translate technical AI risks into clear actions for engineering, security, and . ESSENTIAL DUTIES AND RESPONSIBILITIES Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time. Supports the Artificial Intelligence Security Posture Management function by identifying, evaluating, documenting, and reducing security risk associated with enterprise AI usage. Investigates Shadow Artificial Intelligence observations from tools such as CrowdStrike, Wiz, and Zscaler, validating usage context, ownership, business purpose, and potential exposure. Performs AI Security Reviews for proposed or existing AI use cases, reviewing intake details, data sensitivity, model or service interactions, control coverage, and residual risk. Partners with application, infrastructure, business, and security teams to confirm AI asset ownership, assess risk, identify required controls, and track remediation or governance outcomes. Documents review evidence, risk gaps, action items, and decision rationale in a clear, repeatable, and audit-ready manner aligned to established security guidance and governance processes. Analyzes telemetry, alerts, inventories, and workflow records to identify trends in AI usage, prioritize risk reduction, and support executive or operational reporting. Contributes to the development and refinement of AI security review procedures, intake checklists, escalation paths, knowledge articles, and operational playbooks. Supports escalation of higher-risk AI observations to appropriate security partners, including Security Operations Center teams, incident response partners, and risk or governance stakeholders when warranted. Communicates technical and governance findings in plain language, helping stakeholders understand AI risk, required controls, remediation expectations, and approval dependencies. Maintains awareness of emerging AI security risks, detection methods, governance practices, and tooling capabilities to improve the effectiveness of the AiSPM program over time. Required
Qualifications
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Bachelor’s degree or equivalent education, training, and work-related experience. Minimum of 7 years of experience in security engineering or related cybersecurity roles. Deep specialized knowledge in cybersecurity principles, theories, and concepts. Proven experience in software development lifecycle security practices. Deep knowledge of threat modeling, security testing, and penetration testing.
Experience
implementing and managing complex information security technologies.
Preferred Qualifications
Working knowledge of AI security, cloud security, data protection, and governance frameworks, including: National Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI RMF) National Institute of Standards and Technology Special Publication 800-53 (NIST SP 800-53) Open Worldwide Application Security Project Machine Learning Top 10 (OWASP ML Top 10) Open Worldwide Application Security Project Large Language Model Top 10 (OWASP LLM Top 10) Federal Financial Institutions Examination Council (FFIEC) guidance applicable to regulated financial services environments Cloud Security Alliance guidance related to AI, cloud, and third-party technology risk
Experience
reviewing AI use cases, machine learning services, large language model applications, or AI-enabled business workflows for security, privacy, governance, or compliance risks.
Experience
using CrowdStrike, Wiz, Zscaler, or similar security tools to investigate endpoint, cloud, network, software, or SaaS-related risk signals.
Experience
with security review, risk assessment, exception management, evidence validation, or control mapping in a regulated enterprise environment. Proficiency or familiarity with Python, PowerShell, Structured Query Language (SQL), or similar scripting and analysis methods used to normalize data, support investigations, and improve repeatable reporting. Relevant security certifications such as Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Security+, or similar credentials.
Experience
in financial services, cybersecurity, regulated enterprise environments, or platforms with high audit and control requirements. Familiarity with secure tool-calling patterns, application programming interface (API) protections, model or prompt change validation, and runtime traceability for AI systems. Working knowledge of cloud-native security patterns, telemetry analysis, governance workflows, and deployment gating for modern engineering teams. General Description of Available
Benefits
for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our
Benefits
site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work. Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace. EEO is the Law E-Verify IER Right to Work About Truist Truist is a purpose-driven financial services company, formed by the historic merger of equals of BB&T and SunTrust. We serve clients in a number of high-growth markets in the country, offering a wide range of financial services. At Truist, our purpose is to inspire and build better lives and communities. That happens through real care to make things better. To meet client needs, to empower teammates, and to lift up communities. Learn more about Truist on truist.com.