Senior Cyber Threat Intelligence (CTI) Engineer
Company: Truist Bank
Location: Atlanta
Posted on: April 1, 2026
|
|
|
Job Description:
The position is described below. If you want to apply, click the
Apply Now button at the top or bottom of this page. After you click
Apply Now and complete your application, you'll be invited to
create a profile, which will let you see your application status
and any communications. If you already have a profile with us, you
can log in to check status. Need Help? If you have a disability and
need assistance with the application, you can request a reasonable
accommodation. Send an email to Accessibility (accommodation
requests only; other inquiries won't receive a response). Regular
or Temporary: Regular Language Fluency: English (Required) Work
Shift: 1st shift (United States of America) Please review the
following job description: The Senior Cyber Threat Intelligence
(CTI) Engineer is a senior individual contributor responsible for
designing, engineering, and advancing CTI capabilities that enable
cyber defense, incident response, and threat informed risk
decisions. This role blends deep technical expertise with hands on
operational intelligence analysis. The engineer builds intelligence
workflows, integrates threat data across security operations, and
delivers timely, actionable intelligence across the full
intelligence lifecycle in support of enterprise cybersecurity
objectives within a large financial services environment. Job
Description Essential Duties and Responsibilities Following is a
summary of the essential functions for this job. Other duties may
be performed, both major and minor, which are not mentioned below.
Specific activities may change from time to time. Threat
Intelligence Engineering & Platform Ownership Design, implement,
and innovate enterprise threat intelligence capabilities, including
threat intelligence platforms (TIP), data pipelines, and
integrations with security tooling (e.g., SIEM, SOAR, EDR/NDR/XDR).
Engineer automated pipelines for ingesting, enriching, correlating,
and distributing threat intelligence across stakeholders and
system. Develop and maintain integrations and automation that
enable intelligence enrichment and orchestration. Establish data
quality standards and evolve lifecycle management for intelligence
artifacts. Continuously assess and improve intelligence workflows,
tooling, analytic methods, and dissemination practices. Operational
CTI Analysis Perform analysis of cyber threats, adversaries,
campaigns, techniques, and threat models to identify risks relevant
to the organization’s attack surface. Apply structured analytic
techniques to raw intelligence to assess relevance, confidence, and
potential impact. Monitor emerging threats, vulnerabilities, and
breach/attack trends to drive proactive defensive actions. Support
threat hunting and incident response with intelligence?driven
context, hypotheses, during active investigations.
Intelligence?Driven Defense Enablement Translate intelligence
products into operational outputs such as detection requirements,
prioritized response actions, defensive recommendations, and
control improvements. Partner with key stakeholders to embed
intelligence into day?to?day security workflows. Support
intelligence?led prioritization of threats, vulnerabilities, and
control/capability gaps based on threat modeling. Collaboration and
Influence Serve as a subject?matter expert for cyber threat
intelligence, advising technical teams and stakeholders on threat
landscape and intelligence?informed decisions. Participate/lead in
industry-facing intelligence and knowledge sharing. Mentor and
guide junior analysts and engineers, promoting consistent analytic
standards and engineering best practices. Qualifications Required
Qualifications: The requirements listed below are representative of
the knowledge, skill and/or ability required. Reasonable
accommodations may be made to enable individuals with disabilities
to perform the essential functions. Bachelor’s degree and eight
years of experience in systems engineering or administration or an
equivalent combination of education and work experience Deep
specialized and/or broad functional knowledge in applied enterprise
information security technologies including but not limited to
firewalls, intrusion detection/prevention systems, network
operating systems, identity management, database activity
monitoring, encryption, content filtering, and Mainframe security
Previous experience in leading complex IT projects Strongly
Preferred Qualifications: Bachelor’s degree in Cybersecurity,
Computer Science, Information Systems, or a related technical
field, or equivalent practical experience. Advanced scripting
and/or programming experience used to automate intelligence
processing and integration. Significant experience in cybersecurity
with demonstrated progression into advanced threat intelligence
engineering and operational analysis responsibilities. Proven
ability to design and operate threat intelligence platforms,
automation workflows, and intelligence data pipelines in complex
enterprise environments. Engineering and automation in cloud
environments (Azure/AWS), TIP (e.g. OpenCTI), tuning commercial
threat intelligence tools and feeds. Strong background in
adversarial capability?focused analysis, including mapping observed
activity to techniques, tactics. Demonstrated experience
integrating intelligence into security operations, incident
response, and detection processes. Experience operating in
financial services sector/highly regulated environments where
intelligence capabilities support risk management and regulatory
expectations. Professional certifications (AWS DevOps, Azure
Engineer) or equivalent experience demonstrating engineering
expertise. Professional certifications (GCIH, GMON, GCTI, GSEC) or
equivalent experience demonstrating cybersecurity and intelligence
expertise. General Description of Available Benefits for Eligible
Employees of Truist Financial Corporation: All regular teammates
(not temporary or contingent workers) working 20 hours or more per
week are eligible for benefits, though eligibility for specific
benefits may be determined by the division of Truist offering the
position. Truist offers medical, dental, vision, life insurance,
disability, accidental death and dismemberment, tax-preferred
savings accounts, and a 401k plan to teammates. Teammates also
receive no less than 10 days of vacation (prorated based on date of
hire and by full-time or part-time status) during their first year
of employment, along with 10 sick days (also prorated), and paid
holidays. For more details on Truist’s generous benefit plans,
please visit our Benefits site . Depending on the position and
division, this job may also be eligible for Truist’s defined
benefit pension plan, restricted stock units, and/or a deferred
compensation plan. As you advance through the hiring process, you
will also learn more about the specific benefits available for any
non-temporary position for which you apply, based on full-time or
part-time status, position, and division of work. Truist is an
Equal Opportunity Employer that does not discriminate on the basis
of race, gender, color, religion, citizenship or national origin,
age, sexual orientation, gender identity, disability, veteran
status, or other classification protected by law. Truist is a Drug
Free Workplace. EEO is the Law E-Verify IER Right to Work
Keywords: Truist Bank, Macon , Senior Cyber Threat Intelligence (CTI) Engineer, IT / Software / Systems , Atlanta, Georgia