Container Security Lead
Truist
**The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.**
Need Help? (https://www.brainshark.com/bbandt/careers-site-faq)
_If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (careers@truist.com?subject=Accommodation%20request)_
_(accommodation requests only; other inquiries won't receive a response)._
**Regular or Temporary:**
Regular
**Language Fluency:** English (Required)
**Work Shift:**
1st shift (United States of America)
**Please review the following job description:**
The CSMT Technical Lead serves as the primary technical person for enterprise container security and management initiatives. This role is essential to addressing critical findings from the Management Report of Internal Audit (MRIA) and establishing a comprehensive, automated approach to container image lifecycle management across the organization's containerized infrastructure.
The Technical Lead will design, implement, and maintain integrated security solutions that span multiple platforms including CrowdStrike, Artifactory, GitLab, OpenShift, and AWS ECS, while providing strategic leadership to ensure the long-term sustainability and scalability of container security operations.
This role requires both strong technical and collaboration skills as well as the ability to handle multiple assignments at once. Engineers at this level could be assigned a specific focus of work, for example Quality Assurance or Coaching, which would not materially change essential duties.
**ESSENTIAL DUTIES AND RESPONSIBILITIES**
Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
1.Guide, educate, and provide thought leadership to our delivery teams as related to their optimum adoption of DevSecOps practices and framework.
2. Champion the use of DevSecOps as a strategic asset of culture change to enhance the flow of business value to our clients.
3. Make informed decisions and determine which tool best fits any given situation based on proficiencies with multiple vendor products based on each of the above capabilities.
4. Develop and recommend DevSecOps best practices.
5. Use sophisticated, analytical thought to exercise judgment and design innovative solutions for the most complex components of the DevSecOps lifecycle.
6. Works independently, with guidance in only the most complex situations.
7. Provide technical and process guidance to junior team members.
8. Build and maintain the automation and streamlining of software delivery and operations for new or existing software applications through advanced proficiency and subject matter expertise in vendor tools in the DevOps lifecycle including:
a. Infrastructure as Code; Agile and Development Lifecycle Management; Source Code Management; Build Orchestration; Build Management; Artifact Repository Management; Behavior Driven Development; Test Driven Development; Automated Testing including Unit Testing, Integration Testing, Functional Testing, Smoke Testing, Regression Testing, Stress Testing, and Performance Testing; Static Code Analysis; Load and Performance Testing; Artifact Scanning; Database Schema Management, Orchestration and Recovery; Compliance Automation and Audit Trails; Configuration Management; Containers; Application Release Automation; Deployment Strategies and Patterns including Blue/Green Deployment, Canary Releases, and Rolling Releases; Logging and Log Analytics; and Performance Monitoring and Management.
9. Liaise with DevSecOps Center for Enablement (C4E) to ensure that Enterprise tools or practices are followed, and to share information about any team specific tools or practices that may benefit other teams.
10. Active participant with the Truist Agile Guild and Agile DevOps Communities of Practice.
**QUALIFICATIONS**
**Required Qualifications**
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
1. Bachelor degree or equivalent education and related training or experience
2. Seven+ years of experience in software engineering or IT including at least Four years of experience in a role in which the primary responsibility is DevOps Engineering or the development, maintenance, and support of CI/CD pipelines.
3. Must demonstrate ability to write code
4. Foundational cloud architecture knowledge
5. Must demonstrate ability to construct basic application build pipeline
**Preferred Qualifications:**
1. Primary Vulnerability Coordinator: Serve as the organization's lead for assessing, prioritizing, and orchestrating remediation of security vulnerabilities across the entire container environment
2. Risk Assessment: Conduct technical risk assessments for container vulnerabilities, considering deployment context (OpenShift vs. AWS ECS) and platform-specific mitigations
3. Design and maintain automated workflows that leverage vulnerability scanning tool results to trigger appropriate remediation actions across the container lifecycle.
4. Lead the implementation of automated integrations between CrowdStrike, Artifactory, GitLab CI/CD, OpenShift, and AWS ECS to create seamless container security workflows
5. Design, Configure, maintain, and expand Renovate automation for container image updates, ensuring continuous compliance with security standards and automated merge requests into downstream repositories
6. CI/CD Security Integration: Design and implement GitLab CI/CD pipeline integrations that enforce container security policies and automate compliance verification
7. Custom Tooling Development: Develop custom scripts, tools, and applications to fill automation gaps and enhance the container security ecosystem
8. Entry level development experience and a willingness to solve business objectives with custom code when vendor or internal applications fall short.
9. Introduction level knowledge of AI and AI agents of any kind. We will be implementing them in the near future as part of this process.
**OTHER JOB REQUIREMENTS / WORKING CONDITIONS**
**Sitting**
Constantly (More than 50% of the time)
**Standing**
Occasionally (Less than 25% of the time)
**Walking**
Occasionally (Less than 25% of the time)
**Visual / Audio / Speaking**
Able to access and interpret client information received from the computer and able to hear and speak with individuals in person and on the phone.
**Manual Dexterity / Keyboarding**
Able to work standard office equipment, including PC keyboard and mouse, copy/fax machines, and printers.
**Availability**
Able to work all hours scheduled, including overtime as directed by manager/supervisor and required by business need.
**Travel**
Minimal and up to 10%
**General Description of Available Benefits for Eligible Employees of Truist Financial Corporation:** All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site (https://benefits.truist.com/)
. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.
**_Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace._**
EEO is the Law (https://www.eeoc.gov/sites/default/files/2022-10/EEOC\_KnowYourRights\_screen\_reader\_10\_20.pdf)
Pay Transparency Nondiscrimination Provision (https://www.dol.gov/sites/dolgov/files/OFCCP/pdf/pay-transp\_%20English\_formattedESQA508c.pdf)
E-Verify (https://e-verify.uscis.gov/web/media/resourcesContents/E-Verify\_Participation\_Poster\_ES.pdf)
Por favor confirme su dirección de correo electrónico: Send Email