Sponsored
Verified Job Hardware / Network Engineer

Lead Vulnerability Remediation Engineer - Infrastructure Engineer

Grantsboro, North Carolina
0 views
Hardware / Network Engineer
#785209
Remote / WFH
Truist

Job Description

Qualifications
Language Fluency: English (Required)
The requirements listed below are representative of the knowledge, skill and/or ability required
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions
Bachelor’s degree in Computer Science, Engineering, Information Systems, or related field
Minimum of 3 years of professional experience in infrastructure engineering
Understanding of enterprise infrastructure technologies including cloud, network, database, storage, platform, computing, and middleware
Benefits
General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position
Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates
Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays
For more details on Truist’s generous benefit plans, please visit our Benefits site
Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan
Responsibilities
The Lead Infrastructure Engineer within Truist’s Digital Workplace organization is accountable for enterprise governance, risk reduction, and lifecycle oversight of endpoint vulnerabilities and configuration compliance across physical and virtual (VDI) environments
This role partners across engineering, operations, and security stakeholders to identify, prioritize, remediate, and prevent endpoint security exposures while producing defensible, repeatable, and scalable solutions aligned to Truist standards
This position supports a proactive operating model emphasizing automation, prevention, and measurable outcomes
Builds and designs enterprise infrastructure technology platforms and systems across various environments, such as cloud, network, database, storage, platform, computing, and/or middleware domains
Applies automation, monitoring, and optimization techniques to ensure high availability and performance of infrastructure
Collaborates with cross-functional teams to integrate new technologies and continuously improve infrastructure standards and processes
Troubleshoots and resolves moderately complex technical issues impacting infrastructure performance and reliability
Supports compliance with technology strategies, standards, and governance to mitigate risks and ensure regulatory adherence
Deploys infrastructure designs, configurations, and procedures to support operational consistency and knowledge sharing
Proactively contributes to technical innovation efforts and advancement of infrastructure capabilities
Works with technical project teams to support infrastructure deliverables and solutions
Makes adjustments or recommends enhancements in technical systems and processes to improve effectiveness of area of responsibility
Endpoint Vulnerability Management (Enterprise Scale)
Operate and mature the endpoint vulnerability lifecycle: discovery → prioritization → remediation → validation → reporting
Perform vulnerability identification and prioritization using Qualys and or other security agents, including (but not limited to) Microsoft Security Updates and major 3rd‑party applications (e.g., Chrome, Edge, legacy dependencies where applicable)
Drive risk-based remediation workflows aligned to business impact, exploitability, and fleet exposure
Validate remediation efficacy and ensure vulnerability closure is auditable and reproducible
Secure Baseline Configuration (SBC) & Compliance (Windows 11 + VDI)
Own Secure Baseline Configuration compliance outcomes for Windows 11 across physical devices and VDI
Detect and correct compliance drift; build governance routines to prevent recurring deviation
Translate policy intent into enforceable configuration standards and operational guardrails
Problem Management (Root Cause + Corrective Actions)
Lead or co-lead root cause analysis for recurring endpoint issues and systemic remediation failures
Develop long-term corrective actions, workarounds, and knowledge artifacts that reduce repeat incidents
Align problem practices to Digital Workplace Problem Management goals, templates/artifacts, tooling/automation, and metrics
Configuration Management & Deployment Enablement (SCCM / MECM)
Leverage Microsoft Endpoint Configuration Manager (SCCM/MECM) to support remediation delivery at scale (packages, deployments, compliance baselines, reporting)
Troubleshoot deployment failures and endpoint state issues impacting remediation timelines
Partner with endpoint engineering and operations teams to harden delivery pipelines and reduce rework
Automation & Engineering Enablement (PowerShell + Workflows)
Create and maintain PowerShell automation to reduce manual effort, accelerate remediation, and improve consistency
Build automation patterns for detection, enforcement, validation, and reporting (including safe failure handling and rollback considerations)
Integrate automation into operational workflows (e.g., Service Management processes) to increase throughput and reduce friction
Data, Reporting, and Decision Support (Databases)
Use SQL and relational database concepts to support remediation tracking, compliance analytics, trend analysis, and operational reporting
Define data-quality expectations (integrity, lineage, reproducibility) and produce metrics that support governance and executive visibility
Translate raw findings into actionable insights for stakeholders
Documentation, Communication, and Governance
Produce clear, structured documentation (standards, runbooks, decision records, remediation guides) suitable for audit and cross-team reuse
Communicate tradeoffs, constraints, edge cases, and operational impacts with precision and transparency
Maintain a forward-looking view of risk exposure, compliance drift, and control sustainability
Job description
The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.

Need Help?

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary:

Regular

Language Fluency: English (Required)

Work Shift:

1st shift (United States of America)

Please review the following job description:

The Lead Infrastructure Engineer within Truist’s Digital Workplace organization is accountable for enterprise governance, risk reduction, and lifecycle oversight of endpoint vulnerabilities and configuration compliance across physical and virtual (VDI) environments. This role partners across engineering, operations, and security stakeholders to identify, prioritize, remediate, and prevent endpoint security exposures while producing defensible, repeatable, and scalable solutions aligned to Truist standards.

This position supports a proactive operating model emphasizing automation, prevention, and measurable outcomes.

For this opportunity, Truist will not sponsor an applicant for work visa status or employment authorization, nor will we offer any immigration-related support for this position (including, but not limited to H-1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN-1 or TN-2, E-3, O-1, or future sponsorship for U.S. lawful permanent residence status.)

This position is office-centric 5 days a week in our Truist hubs.

General Essential Duties And Responsibilities

Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
• Builds and designs enterprise infrastructure technology platforms and systems across various environments, such as cloud, network, database, storage, platform, computing, and/or middleware domains.
• Applies automation, monitoring, and optimization techniques to ensure high availability and performance of infrastructure.
• Collaborates with cross-functional teams to integrate new technologies and continuously improve infrastructure standards and processes.
• Troubleshoots and resolves moderately complex technical issues impacting infrastructure performance and reliability.
• Supports compliance with technology strategies, standards, and governance to mitigate risks and ensure regulatory adherence.
• Deploys infrastructure designs, configurations, and procedures to support operational consistency and knowledge sharing.
• Proactively contributes to technical innovation efforts and advancement of infrastructure capabilities.
• Works with technical project teams to support infrastructure deliverables and solutions.
• Makes adjustments or recommends enhancements in technical systems and processes to improve effectiveness of area of responsibility.

Specific job Function:
• Endpoint Vulnerability Management (Enterprise Scale)
• Operate and mature the endpoint vulnerability lifecycle: discovery → prioritization → remediation → validation → reporting.
• Perform vulnerability identification and prioritization using Qualys and or other security agents, including (but not limited to) Microsoft Security Updates and major 3rd‑party applications (e.g., Chrome, Edge, legacy dependencies where applicable).
• Drive risk-based remediation workflows aligned to business impact, exploitability, and fleet exposure.
• Validate remediation efficacy and ensure vulnerability closure is auditable and reproducible.
• Secure Baseline Configuration (SBC) & Compliance (Windows 11 + VDI)
• Own Secure Baseline Configuration compliance outcomes for Windows 11 across physical devices and VDI.
• Detect and correct compliance drift; build governance routines to prevent recurring deviation.
• Translate policy intent into enforceable configuration standards and operational guardrails.
• Problem Management (Root Cause + Corrective Actions)
• Lead or co-lead root cause analysis for recurring endpoint issues and systemic remediation failures.
• Develop long-term corrective actions, workarounds, and knowledge artifacts that reduce repeat incidents.
• Align problem practices to Digital Workplace Problem Management goals, templates/artifacts, tooling/automation, and metrics.
• Configuration Management & Deployment Enablement (SCCM / MECM)
• Leverage Microsoft Endpoint Configuration Manager (SCCM/MECM) to support remediation delivery at scale (packages, deployments, compliance baselines, reporting).
• Troubleshoot deployment failures and endpoint state issues impacting remediation timelines.
• Partner with endpoint engineering and operations teams to harden delivery pipelines and reduce rework.
• Automation & Engineering Enablement (PowerShell + Workflows)
• Create and maintain PowerShell automation to reduce manual effort, accelerate remediation, and improve consistency.
• Build automation patterns for detection, enforcement, validation, and reporting (including safe failure handling and rollback considerations).
• Integrate automation into operational workflows (e.g., Service Management processes) to increase throughput and reduce friction.
• Data, Reporting, and Decision Support (Databases)
• Use SQL and relational database concepts to support remediation tracking, compliance analytics, trend analysis, and operational reporting.
• Define data-quality expectations (integrity, lineage, reproducibility) and produce metrics that support governance and executive visibility.
• Translate raw findings into actionable insights for stakeholders.
• Documentation, Communication, and Governance
• Produce clear, structured documentation (standards, runbooks, decision records, remediation guides) suitable for audit and cross-team reuse.
• Communicate tradeoffs, constraints, edge cases, and operational impacts with precision and transparency.
• Maintain a forward-looking view of risk exposure, compliance drift, and control sustainability.

Qualifications

Required Qualifications

The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
• Bachelor’s degree in Computer Science, Engineering, Information Systems, or related field.
• Minimum of 3 years of professional experience in infrastructure engineering.
• Understanding of enterprise infrastructure technologies including cloud, network, database, storage, platform, computing, and middleware.

Preferred Qualifications
• Bachelor's degree and six years of experience or an equivalent combination of education and work experience.
• Banking or financial services experience.
• Experience in VDI environments and their unique compliance/remediation constraints.
• Familiarity with endpoint configuration governance methods (e.g., baselines, policy-as-code concepts, drift monitoring).
• Experience integrating security remediation with service management tooling and workflows.
• ITIL / Problem Management background and comfort operating within structured ITSM practices.
• Security or endpoint-focused certifications (examples: Security+, vendor tooling certs, or equivalent experience).
• Security-first mindset with strong attention to data integrity and reproducibility.
• Structured communication: crisp problem statements, ******** decision logic, and documented tradeoffs.
• Anticipates edge cases, failure modes, and operational constraints (bandwidth, maintenance windows, change risk).
• Designs solutions for scale and sustainability, not one-off fixes.
• Automation and prevention focused, aligned to the Digital Workplace direction.

General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, ****** orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.

EEO is the Law E-Verify IER Right to Work
View more Lead Jobs in Grantsboro →
Sponsored

Similar Openings in Hardware / Network Engineer

More jobs you might like

Intermediate Support Engineer aryaveer Verified
Bengaluru, Karnataka Hardware / Network Engineer

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve ope...

Posted 2m ago View Details
Bengaluru, Karnataka Hardware / Network Engineer

Req ID: 61619 Job Function: Business Services & Operations Posting Start Date: 09/08/2026 Posting End Date: 10/08/2026 Division: UK Busi...

Posted 5m ago View Details
Chennai, Tamil Nadu Hardware / Network Engineer

Skills Required: Python, Data Science, Big Query,, Data/Analytics, AI/ML, Machine Learning Skills Preferred: Artificial Intelligence & E...

Posted 8m ago View Details
New York City, New York Hardware / Network Engineer

Qualifications ents• Perform advanced Cisco networking tasks including routing configuration (OSPF, BGP basics), ACLs, inter-VLAN routing, a...

Posted 9m ago View Details