Senior Security Engineer – Cyber Hunting & Incident Response at Truist
Atlanta, GA
—
Jul 30, 2026
Atlanta, GA
Sep 24, 2026
What this job asks for AI summary
A senior cybersecurity engineer embedded in a 24x7 Cyber Fusion Center, responsible for proactive threat hunting, digital forensics, and end-to-end incident response (investigation, containment, eradication, recovery). The role also involves developing detection methodologies, mentoring peers, and collaborating with security and business teams to improve enterprise threat visibility. On-call rotation is required.
Senior level · 7+ years · Atlanta-Sandy Springs-Alpharetta, GA · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 200 people in the Atlanta-Sandy Springs-Alpharetta, GA area plausibly meet what this posting asks for (information security analysts). range 60–300
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $134,382 (middle half $104,315–$168,301).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 1, 2026. It is a model, not a headcount.
Why we read it this way (6)
The posting lists two work locations — Atlanta, GA and Zebulon, NC — with no indication that one is primary. Atlanta (CBSA 12060) is used here as the larger metro; the Zebulon, NC location falls within the Raleigh-Cary, NC CBSA (39580).
The degree requirement states 'Bachelor's degree or equivalent education, training, and work-related experience,' so no formal degree is hard-gated.
Threat hunting, incident response, digital forensics, and penetration testing appear under the Required Qualifications section and are treated as hard gates. All other named technologies (Wireshark, tcpdump, Azure, AWS, scripting, ML/AI, IAM, OS knowledge) appear exclusively under Preferred Qualifications.
Certifications (Security+, CySA+, GCIH, GCFA, GCFE, GNFA, GREM, Azure, AWS) are listed as preferred examples only; no specific certification is hard-required.
The posting explicitly states Truist will not sponsor work visas or provide immigration-related support for this position.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): network traffic analysis.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.