Logo
Truist Financial

Head of Cloud Security Automation

Truist Financial, Charlotte, North Carolina, United States, 28245

Save Job

Company:

Truist Financial Location:

Charlotte, NC Employment Type:

Full Time Date Posted:

12/11/2025 Job Categories:

Banking, Computers, Software, Finance/Economics, Financial Services, Information Technology Head of Cloud Security Automation

The Head of Cloud Security Automation leads the enterprise strategy, engineering, and execution of automated cloud security controls across AWS, Azure, and SaaS platforms. This leader drives the shift from manual, ticket-based security operations to an Agentic AI-powered, self‑healing cloud security model, leveraging large‑scale automation, IaC guardrails, MCP agents, and continuous compliance pipelines. The role owns the roadmap for security automation across CSPM, CIEM, SSPM, CNAPP, IaC, digital workforce agents, and evidence automation to meet NIST 800-53 Rev5, and internal regulatory requirements. ESSENTIAL DUTIES AND RESPONSIBILITIES

Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time. Strategic Leadership

Define and own the enterprise Cloud Security Automation Strategy & Roadmap(2026+), aligned to CISO, CCoE, and Enterprise Architecture goals. Lead the design of a self‑healing cloud using automation‑first architecture and Agentic AI digital workforce. Govern the automation maturity model and drive adoption across engineering and application teams. Automation Engineering & Architecture

Build and lead teams developing:

Automated risk detection & prioritization pipelines (Wiz, CrowdStrike, CNAPP). IaC guardrails (Terraform/Wiz IaC/SNYK) and policy‑as‑code frameworks. Agentic AI remediation flows for misconfigurations, permissions, containers, and vulnerabilities. Cross‑account remediation orchestration using MCP agents and ServiceNow VR/Risk workflows. Automated evidence and compliance pipelines for NIST, FedRAMP, SOC2, PCI.

Operational Excellence

Replace manual reviews with automated workflows for:

Misconfiguration remediation Privilege analysis & JIT provisioning SSPM controls (SaaS misconfigurations) Vulnerability closure across containers, VMs, serverless

Partner with Platform Engineering, DevOps, and AppSec to embed security into CI/CD and digital factory delivery pipelines. Governance & Risk

Establish automation KPIs, SLAs, and dashboards for remediation velocity, exposure reduction, and FTE savings. Drive measurable reduction in Mean Time to Detect/Remediate (MTTD/MTTR). Enforce secure‑by‑default patterns using guardrails and MCP agents. QUALIFICATIONS

Required Qualifications: 1. Bachelor's degree and ten to twelve years of experience in systems engineering or an equivalent combination of education and work experience. 2. Strong functional and technical knowledge of information/cyber security capabilities with deep expertise in one or more of the following areas: Encryption, Data Security, Application Security, End Point Security, Identity and Access Management, Windows/Unix/Linux Systems Security, Mainframe Security, Perimeter Security, Network Security, Mobility Security, Cloud Security, Cyber Security, Cryptography, or Authentication Systems. 3. Strong understanding of service lifecycle management, strategic planning, and the cyber security landscape. Preferred Qualifications: 1015+ years in cloud security, platform engineering, or DevSecOps leadership. Deep knowledge of AWS/Azure security services and CNAPP/CSPM/CIEM/SSPM tooling. Hands‑on expertise with IaC (Terraform), GitOps, automation frameworks, and API‑driven remediation. Proven track record delivering enterprise‑scale automation and security transformation. Strong understanding of NIST 800-53, SOX, and financial‑sector controls. Experience building AI‑driven automation, policy‑as‑code, and agent‑based workflows. Prior leadership in highly regulated environments (Finance, Healthcare, Defense). OTHER JOB REQUIREMENTS / WORKING CONDITIONS

Sitting: Constantly (More than 50% of the time) Visual / Audio / Speaking: Able to access and interpret client information received from the computer and able to hear and speak with individuals in person and on the phone. Manual Dexterity / Keyboarding: Able to work standard office equipment, including PC keyboard and mouse, copy/fax machines, and printers. Availability: Able to work all hours scheduled, including overtime as directed by manager/supervisor and required by business need. Travel: Minimal and up to 10% General Description of Available Benefits for Eligible Employees of Truist Financial Corporation

All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax‑preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full‑time or part‑time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non‑temporary position for which you apply, based on full‑time or part‑time status, position, and division of work. Equal Opportunity Statement

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace. EEO is the Law E-Verify IER Right to Work

#J-18808-Ljbffr