Cybersecurity Engineer - Data Protection Engineer
Truist
Job Description
Job Overview The Data Protection Engineer will serve as a subject matter expert for Protegrity and data tokenization, helping to design, implement, and support enterprise‑level data protection solutions. This role will focus on integrating Protegrity with new and existing business applications, ensuring sensitive data is secured through tokenization, masking, and encryption. The engineer will work closely with application teams, architects, cybersecurity leaders, and compliance stakeholders to apply best‑in‑class data protection controls across the enterprise.
Location: Onsite, office‑centric (5 days a week) in Truist core locations: North Carolina (Charlotte, Raleigh, Wilson, Greensboro); Georgia (Atlanta); Virginia (Richmond). Employment Details Employment Type: Regular. Language Fluency: English (Required).
Work Shift: 1st shift (United States of America). Essential Duties and Responsibilities Lead the design, implementation, and maintenance of enterprise data protection solutions using Protegrity, including tokenization, masking, and encryption controls. Serve as the primary technical expert for integrating Protegrity with new and existing applications, databases, and data pipelines across the organization.
Develop, test, and optimize data protection policies, workflows, and integration patterns to meet security and compliance requirements. Troubleshoot and resolve complex issues related to Protegrity agents, connectors, policy enforcement, and application integration. Partner with application teams, architects, and cybersecurity stakeholders to ensure secure data handling throughout solution lifecycles.
Maintain documentation for architectures, integration guides, runbooks, and operational procedures for data protection platforms. Support ongoing operations and incident response activities for the organization’s Tier 1 data protection platform. Required Qualifications Bachelor’s degree and five years of experience in systems engineering or administration or an equivalent combination of education and work experience.
In‑depth knowledge in applied enterprise information security technologies including but not limited to firewalls, intrusion detection/prevention systems, network operating systems, identity management, database activity monitoring, encryption, content filtering, and Mainframe security. Previous experience in planning and managing IT projects. Preferred Qualifications 6+ years in software engineering, cybersecurity engineering, or data engineering roles.
Experience working in cloud environments (AWS, Azure, GCP). Hands‑on DevSecOps experience with CI/CD pipelines (Gitlab, Terraform, IaC, etc.). Exposure to Protegrity or a similar enterprise data protection platform.
Knowledge of: Tokenization (format‑preserving, reversible, non‑reversible) Data masking (static, dynamic) Encryption (symmetric, asymmetric, key management concepts) Experience with application integration patterns (APIs, SDKs, agents, proxy‑based controls, microservices). Proficiency with at least one modern programming language (Java, Python, .NET, etc.). Understanding of data security, IAM, and compliance frameworks (PCI DSS, GDPR, HIPAA, etc.).
Ability to diagnose and resolve complex production issues in high‑criticality environments. Strong communication and cross‑team collaboration abilities. Availability to provide after‑hours, remote support for production rollout(s), on an occasional/as‑needed basis.
Other Job Requirements / Working Conditions Sitting Constantly (More than 50% of the time). Visual / Audio / Speaking Able to access and interpret client information received from the computer and able to hear and speak with individuals in person and on the phone. Manual Dexterity / Keyboarding Able to work standard office equipment, including PC keyboard and mouse, copy/fax machines, and printers.
Availability Able to work all hours scheduled, including overtime as directed by manager/supervisor and required by business need. Travel Minimal and up to 10%. Benefits All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position.
Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax‑preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full‑time or part‑time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site.
Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non‑temporary position for which you apply, based on full‑time or part‑time status, position, and division of work. Equal Opportunity Employer Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status or other classification protected by law.
Truist is a Drug Free Workplace. EEO is the Law. E-Verify IER Right to Work. #J-18808-Ljbffr