Jobs · Information Technology · North Carolina

Lead Vulnerability Remediation Engineer - Infrastructure Engineer

TalentAlly · Greensboro, NC · Today
Information TechnologyFull-time

Regular, full-time position. Fluency in English required. Office-centric role requiring 5 days a week in Truist hubs. Truist will not sponsor work visas or provide immigration support for this position.

About the role

The Lead Infrastructure Engineer within Truist's Digital Workplace organization is accountable for enterprise governance, risk reduction, and lifecycle oversight of endpoint vulnerabilities and configuration compliance across physical and virtual (VDI) environments. This role partners across engineering, operations, and security stakeholders to identify, prioritize, remediate, and prevent endpoint security exposures while producing defensible, repeatable, and scalable solutions aligned to Truist standards. This position supports a proactive operating model emphasizing automation, prevention, and measurable outcomes.

Responsibilities

  • Build and design enterprise infrastructure technology platforms and systems across cloud, network, database, storage, platform, computing, and middleware domains.
  • Apply automation, monitoring, and optimization techniques to ensure high availability and performance of infrastructure.
  • Collaborate with cross-functional teams to integrate new technologies and continuously improve infrastructure standards and processes.
  • Troubleshoot and resolve moderately complex technical issues impacting infrastructure performance and reliability.
  • Support compliance with technology strategies, standards, and governance to mitigate risks and ensure regulatory adherence.
  • Deploy infrastructure designs, configurations, and procedures to support operational consistency and knowledge sharing.
  • Proactively contribute to technical innovation efforts and advancement of infrastructure capabilities.
  • Work with technical project teams to support infrastructure deliverables and solutions.
  • Make adjustments or recommend enhancements in technical systems and processes to improve effectiveness.

Endpoint Vulnerability Management (Enterprise Scale)

  • Operate and mature the endpoint vulnerability lifecycle: discovery, prioritization, remediation, validation, and reporting.
  • Perform vulnerability identification and prioritization using Qualys and/or other security agents, including Microsoft Security Updates and major third-party applications (e.g., Chrome, Edge, legacy dependencies).
  • Drive risk-based remediation workflows aligned to business impact, exploitability, and fleet exposure.
  • Validate remediation efficacy and ensure vulnerability closure is auditable and reproducible.

Secure Baseline Configuration (SBC) & Compliance (Windows 11 + VDI)

  • Own Secure Baseline Configuration compliance outcomes for Windows 11 across physical devices and VDI.
  • Detect and correct compliance drift; build governance routines to prevent recurring deviation.
  • Translate policy intent into enforceable configuration standards and operational guardrails.

Problem Management (Root Cause + Corrective Actions)

  • Lead or co-lead root cause analysis for recurring endpoint issues and systemic remediation failures.
  • Develop long-term corrective actions, workarounds, and knowledge artifacts that reduce repeat incidents.
  • Align problem practices to Digital Workplace Problem Management goals, templates/artifacts, tooling/automation, and metrics.

Configuration Management & Deployment Enablement (SCCM / MECM)

  • Leverage Microsoft Endpoint Configuration Manager (SCCM/MECM) to support remediation delivery at scale (packages, deployments, compliance baselines, reporting).
  • Troubleshoot deployment failures and endpoint state issues impacting remediation timelines.
  • Partner with endpoint engineering and operations teams to harden delivery pipelines and reduce rework.

Automation & Engineering Enablement (PowerShell + Workflows)

  • Create and maintain PowerShell automation to reduce manual effort, accelerate remediation, and improve consistency.
  • Build automation patterns for detection, enforcement, validation, and reporting (including safe failure handling and rollback considerations).
  • Integrate automation into operational workflows (e.g., Service Management processes) to increase throughput and reduce friction.

Data, Reporting, and Decision Support (Databases)

  • Use SQL and relational database concepts to support remediation tracking, compliance analytics, trend analysis, and operational reporting.
  • Define data-quality expectations (integrity, lineage, reproducibility) and produce metrics that support governance and executive visibility.
  • Translate raw findings into actionable insights for stakeholders.

Documentation, Communication, and Governance

  • Produce clear, structured documentation (standards, runbooks, decision records, remediation guides) suitable for audit and cross-team reuse.
  • Communicate tradeoffs, constraints, edge cases, and operational impacts with precision and transparency.
  • Maintain a forward-looking view of risk exposure, compliance drift, and control sustainability.

Requirements

  • Bachelor's degree in Computer Science, Engineering, Information Systems, or related field.
  • Minimum of 3 years of professional experience in infrastructure engineering.
  • Understanding of enterprise infrastructure technologies including cloud, network, database, storage, platform, computing, and middleware.

Preferred Qualifications

  • Bachelor's degree and six years of experience or an equivalent combination of education and work experience.
  • Banking or financial services experience.
  • Experience in VDI environments and their unique compliance/remediation constraints.
  • Familiarity with endpoint configuration governance methods (e.g., baselines, policy-as-code concepts, drift monitoring).
  • Experience integrating security remediation with service management tooling and workflows.
  • ITIL / Problem Management background and comfort operating within structured ITSM practices.
  • Security or endpoint-focused certifications (e.g., Security+, vendor tooling certs, or equivalent experience).
  • Security-first mindset with strong attention to data integrity and reproducibility.
  • Structured communication: crisp problem statements, explicit decision logic, and documented tradeoffs.
  • Anticipates edge cases, failure modes, and operational constraints (bandwidth, maintenance windows, change risk).
  • Designs solutions for scale and sustainability, not one-off fixes.
  • Automation and prevention focused, aligned to the Digital Workplace direction.

Benefits

All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may vary. Truist offers:

  • Medical, dental, and vision insurance.
  • Life insurance, disability, and accidental death and dismemberment coverage.
  • Tax-preferred savings accounts and a 401k plan.
  • No less than 10 days of vacation (prorated based on date of hire and full-time/part-time status) during the first year of employment, along with 10 sick days and paid holidays.
  • Depending on the position and division, eligibility for a defined benefit pension plan, restricted stock units, and/or a deferred compensation plan.

Similar jobs

Lead Security Engineer

SunoBoston, MA· 2 days ago
Information Technology$275k–$395k/yrapply on jobs.ashbyhq.com