A Software Engineer at Suntrust Investment Services (now operating under the unified Truist brand) plays a critical role in building, securing, and scaling the technology infrastructure that powers wealth management, investment portfolios, and enterprise risk systems. In this position, you are not just writing code; you are architecting highly complex solutions that handle high-volume financial transactions, real-time data integration, and critical compliance frameworks. The software you deliver directly impacts millions of clients, financial advisors, and risk officers who rely on stable, secure, and performant platforms to manage capital and mitigate enterprise risk. At Suntrust Investment Services, engineering is tightly integrated with the business. You will work on modernizing legacy financial applications, migrating services to cloud environments, and implementing cutting-edge enterprise Governance, Risk, and Compliance (eGRC) solutions like Archer. The engineering culture places a premium on robustness, security, and continuous delivery. Because of the highly regulated nature of the financial services industry, your code must be backed by rigorous testing, automated pipelines, and sound architectural patterns. This role is ideal for engineers who thrive at the intersection of complex backend engineering, modern frontend interfaces, and business-critical domain logic.
HR Screening Call
reportedInitial call to assess your background, career goals, and alignment with the role's requirements.
What to demonstrate
- Initial call to assess your background, career goals, and alignment with the role's requirements
- Depth in Java
How to prepare
- Be able to walk your CV end to end in two minutes, and say why this company specifically.
- Have your salary expectations, notice period and location constraints ready, and ask for the rest of the loop in writing.
Technical Screening
reportedIncludes a live coding session or a deep-dive technical discussion with a manager.
What to demonstrate
- Includes a live coding session or a deep-dive technical discussion with a manager
- Depth in Java
How to prepare
- Answer aloud and timed: How do you handle transaction management in a Spring-based application? Explain the propagation behaviors available in
@Transactional. - Answer aloud and timed: Describe how memory management works in the Java Virtual Machine (JVM). How would you diagnose and resolve a memory leak in a production Spring Boot application?
Final Panel Interview
reportedInterview with engineering managers, technical leads, and business stakeholders.
What to demonstrate
- Interview with engineering managers, technical leads, and business stakeholders
- Depth in Java
How to prepare
- Answer aloud and timed: Explain the lifecycle hooks in Angular. In what specific scenarios would you use
ngOnInitversusngAfterViewInit? - Answer aloud and timed: How does change detection work in Angular? How can you optimize performance using the
OnPushchange detection strategy?
PracHub editorial advice for the preparation topics above.
Set Up Your IDE in Advance
If you are scheduled for a coding interview, ensure your local development environment is fully configured, including your compiler, test runners (like JUnit), and mocking libraries. Do not waste valuable interview time troubleshooting your IDE setup.
During live coding, talk through your thought process out loud
The interviewer wants to see how you approach problem-solving, structure your logic, and handle edge cases, not just whether you arrive at the perfect syntax immediately.
Brush Up on Financial and Risk Concepts
Even if you are applying for a general engineering role, having a basic understanding of financial systems, transaction security, and enterprise risk management will help you connect with your business-facing interviewers.
Choose a category, try a prompt, then open its approach, worked solution or follow-up when you need it.
Describe how memory management works in the Java Virtual Machine (JVM). How would you diagnose and resolve a m
Describe how memory management works in the Java Virtual Machine (JVM). How would you diagnose and resolve a memory leak in a production Spring Boot application?
Approach
- Say what the runtime actually does before reasoning about the code.
- Name what is shared across threads and what owns each piece of state.
- Identify the window where an invariant is briefly untrue.
- Distinguish a value from a reference to it, and say which one you handed out.
Follow-up
- What happens if two callers reach this at the same time?
- Where could this allocate more than you expect?
What is the event loop in JavaScript, and how does it handle asynchronous execution?
What is the event loop in JavaScript, and how does it handle asynchronous execution?
Approach
- Say what the runtime actually does before reasoning about the code.
- Name what is shared across threads and what owns each piece of state.
- Identify the window where an invariant is briefly untrue.
- Distinguish a value from a reference to it, and say which one you handed out.
Follow-up
- What happens if two callers reach this at the same time?
- Where could this allocate more than you expect?
Canonicalise a request body into a stable idempotency fingerprint
idempotency_key.request_fingerprint is a SHA-256 over the method, path and canonicalised body, and a retry whose fingerprint differs must be rejected with 422 rather than served the stored response. Write the canonicaliser. Bodies are JSON up to 256 KB nested at most 32 levels; clients vary key order, whitespace and unicode escaping, and some send 64-bit ids as JSON numbers. Produce a deterministic byte string such that semantically identical bodies match and any semantic difference does not. State your complexity and name two normalisations you refuse to perform.
Approach
- Parse once into a tree, then re-serialise under fixed rules: object keys sorted, array order preserved, one escaping convention, no insignificant whitespace. Parsing is O(n) and sorting keys is O(k log k) per object, so O(n log n) overall with O(depth) stack, and the 32-level cap is enforced during parsing because hostile nesting is how a canonicaliser becomes a stack overflow.
- Sort keys by their UTF-8 bytes and say why the obvious implementation is wrong in some runtimes: a default string comparison that orders by UTF-16 code units places surrogate pairs, meaning code points from U+10000 up, below U+E000 to U+FFFF, which is not UTF-8 byte order, so two services written in different languages disagree on the same document.
- Do not re-encode numbers through a double. IEEE-754 binary64 represents integers exactly only up to 2^53, so normalising a 19-digit id through a float changes it, and 1 against 1.0 cannot be reconciled without deciding whether they are the same value. Preserve the literal token, and require ids as strings at the API boundary if you want them comparable.
- Reject duplicate keys rather than picking one. JSON permits them and parsers disagree, most keeping the last, so any choice you make ties the fingerprint to a parser detail that the code handling the request does not necessarily share.
Follow-up
- A client sends the same logical request with an extra field your API ignores. Same key, different fingerprint, so you return 422. Is that the right answer?
- Where does the fingerprint get computed relative to request decompression and the body-size limit?
How do you design a relational database schema for a complex data model while ensuring optimal query performan
How do you design a relational database schema for a complex data model while ensuring optimal query performance and data normalization?
Approach
- Name the grain you start from and join outward from it.
- Check whether any join is one-to-many before aggregating, or the sums inflate.
- Say which index the query would use, and what makes it unusable.
- Handle the rows that do not match: that is usually the actual question.
Follow-up
- How does the query change if that join becomes one-to-many?
- What happens to this when the table is ten times larger?
Stop tag and share joins from fanning out a page
resource_tag is (resource_id, tag_id) with PK (resource_id, tag_id); resource_share is (resource_id, shared_with_user_id, permission). The tagged-and-shared listing inner-joins resource to both, filters tenant_id, tag_id = ANY($2) and shared_with_user_id = $3, orders by updated_at DESC and takes 50. Pages come back with fewer than 50 distinct resources and the total in the header is far too high. Explain the row multiplication, rewrite both the page query and the count query so each is correct, and name the index each one needs. PostgreSQL 16.
Approach
- Do the arithmetic against the predicates that are actually there. An inner join emits one row per matching child row, and both joins are filtered: tag_id = ANY($2) admits only the requested tags, shared_with_user_id = $3 admits one user's share rows. So a resource holding three of the requested tags and shared with $3 once yields three rows, not one — the multiplier is its count of matching tags times its share rows for that single user, and that second factor is 1 unless the table admits duplicate (resource_id, shared_with_user_id) pairs. LIMIT 50 then limits rows rather than resources, and COUNT(*) counts pairs — the header is the product, not the population.
- Reject DISTINCT as the fix. It deduplicates after the product has been built, so the planner must materialise and sort the fanned-out set before the LIMIT can apply, and it leaves any SUM or AVG in the same select list wrong.
- Rewrite both filters as semi-joins, keeping resource as the only row source: AND EXISTS (SELECT 1 FROM resource_tag rt WHERE rt.resource_id = r.resource_id AND rt.tag_id = ANY($2)) and the same shape against resource_share. A semi-join stops at the first match per resource and preserves the driving index order, so ORDER BY updated_at DESC, resource_id DESC LIMIT 50 still stops after 50 rows.
- Count with the same predicates and no join at all: SELECT count(*) FROM resource r WHERE r.tenant_id = $1 AND r.status = 'active' AND EXISTS (...) AND EXISTS (...). Nothing multiplies a resource, so the number is the population.
Follow-up
- The filter changes from 'any of these tags' to 'all of these tags'. Rewrite it and state what it costs relative to the ANY form.
- A resource can be shared with the same user twice under different permissions. Does your count change, and should it?
How does dependency injection work in Spring Boot, and what are the benefits of using constructor injection ov
How does dependency injection work in Spring Boot, and what are the benefits of using constructor injection over field injection?
Approach
- Clarify what is being asked and what a complete answer contains.
- State your assumptions explicitly before working the problem.
- Say what you would check first and why it is the highest-information step.
- Work from the requirement backwards to the design.
Follow-up
- What assumption would you test first?
- How would you know your answer was wrong?
Explain the difference between Spring MVC and Spring Boot. When would you choose one over the other for a new
Explain the difference between Spring MVC and Spring Boot. When would you choose one over the other for a new microservice?
Approach
- Fix the scope first: who calls this, how often, and what they do when it fails.
- Name the read and write paths separately; they rarely have the same bottleneck.
- Choose a partition key and say what query it makes expensive.
- State the consistency you need, and where you are willing to be stale.
Follow-up
- What breaks first when traffic grows ten times?
- How does this behave when that dependency is down for an hour?
Explain the lifecycle hooks in Angular. In what specific scenarios would you use `ngOnInit` versus `ngAfterVie
Explain the lifecycle hooks in Angular. In what specific scenarios would you use ngOnInit versus ngAfterViewInit?
Approach
- Clarify what is being asked and what a complete answer contains.
- State your assumptions explicitly before working the problem.
- Say what you would check first and why it is the highest-information step.
- Work from the requirement backwards to the design.
Follow-up
- What assumption would you test first?
- How would you know your answer was wrong?
How does change detection work in Angular? How can you optimize performance using the `OnPush` change detectio
How does change detection work in Angular? How can you optimize performance using the OnPush change detection strategy?
Approach
- Clarify what is being asked and what a complete answer contains.
- State your assumptions explicitly before working the problem.
- Say what you would check first and why it is the highest-information step.
- Work from the requirement backwards to the design.
Follow-up
- What assumption would you test first?
- How would you know your answer was wrong?
Walk me through how you would write a unit test for a service class that depends on an external database repos
Walk me through how you would write a unit test for a service class that depends on an external database repository. How do you mock the repository layer?
Approach
- Clarify what is being asked and what a complete answer contains.
- State your assumptions explicitly before working the problem.
- Say what you would check first and why it is the highest-information step.
- Work from the requirement backwards to the design.
Follow-up
- What assumption would you test first?
- How would you know your answer was wrong?
Explain the difference between unit testing, integration testing, and functional testing. How do these fit int
Explain the difference between unit testing, integration testing, and functional testing. How do these fit into a continuous integration (CI) pipeline?
Approach
- Say who the caller is and what they do when the call fails halfway.
- Define the identity of a request so a retry cannot double-apply it.
- Separate accepted, pending, failed and confirmed; they are different facts.
- Design the error taxonomy before the success shape; callers branch on it.
Follow-up
- What happens if the caller retries after a timeout?
- How does a client discover it is on an old version of this contract?
What is your approach to test-driven development (TDD)? Describe a scenario where TDD helped you avoid introdu
What is your approach to test-driven development (TDD)? Describe a scenario where TDD helped you avoid introducing a critical bug into production.
Approach
- Clarify what is being asked and what a complete answer contains.
- State your assumptions explicitly before working the problem.
- Say what you would check first and why it is the highest-information step.
- Work from the requirement backwards to the design.
Follow-up
- What assumption would you test first?
- How would you know your answer was wrong?
How would you design a secure REST API that integrates Suntrust Investment Services internal systems with an e
How would you design a secure REST API that integrates Suntrust Investment Services internal systems with an external third-party vendor?
Approach
- Say who the caller is and what they do when the call fails halfway.
- Define the identity of a request so a retry cannot double-apply it.
- Separate accepted, pending, failed and confirmed; they are different facts.
- Design the error taxonomy before the success shape; callers branch on it.
Follow-up
- What happens if the caller retries after a timeout?
- How does a client discover it is on an old version of this contract?
Explain the differences between REST and SOAP web services. In what scenarios would you still choose SOAP over
Explain the differences between REST and SOAP web services. In what scenarios would you still choose SOAP over REST in a banking environment?
Approach
- Say who the caller is and what they do when the call fails halfway.
- Define the identity of a request so a retry cannot double-apply it.
- Separate accepted, pending, failed and confirmed; they are different facts.
- Design the error taxonomy before the success shape; callers branch on it.
Follow-up
- What happens if the caller retries after a timeout?
- How does a client discover it is on an old version of this contract?
Describe the difference between observables and promises in JavaScript and RxJS. How do you prevent memory lea
Describe the difference between observables and promises in JavaScript and RxJS. How do you prevent memory leaks when subscribing to observables in Angular components?
Approach
- Establish what changed and when, before forming any theory.
- Pick a bisection that eliminates candidates whichever way it turns out.
- Check the instrumentation before believing the symptom.
- Separate the trigger from the cause; the deploy is rarely the bug.
Follow-up
- What would you look at first, and what would it rule out?
- How would you tell a cause from a coincidence here?
Built from the rounds and topics Suntrust Investment Services candidates report.
Prepare, practise & reflect
One practical outcome each day. Spend longer where you need it.
0 / 7 done01Map the Suntrust Investment Services loop
- Write out the reported sequence: HR Screening Call, Technical Screening, Final Panel Interview.
- For each round, write one sentence on what it is judging, from the description above, and mark the one you are least ready for.
Deliverable: A one-page map of the 3 reported rounds, with the weakest marked.
02Work Java
- Spend the session on Java, which Suntrust Investment Services candidates report being tested on.
- Write one worked example in Java and time yourself on it.
Deliverable: One timed worked example in Java.
03Work eGRC (Governance, Risk, and Compliance) Domain
- Spend the session on eGRC (Governance, Risk, and Compliance) Domain, which Suntrust Investment Services candidates report being tested on.
- Write one worked example in eGRC (Governance, Risk, and Compliance) Domain and time yourself on it.
Deliverable: One timed worked example in eGRC (Governance, Risk, and Compliance) Domain.
04Work Archer Solution Engineering
- Spend the session on Archer Solution Engineering, which Suntrust Investment Services candidates report being tested on.
- Write one worked example in Archer Solution Engineering and time yourself on it.
Deliverable: One timed worked example in Archer Solution Engineering.
05Answer out loud: Core Java & Backend Frameworks
- Answer aloud, timed: How does dependency injection work in Spring Boot, and what are the benefits of using constructor injection over field injection?
- Answer aloud, timed: Explain the difference between Spring MVC and Spring Boot. When would you choose one over the other for a new microservice?
Deliverable: Spoken answers to 2 reported Core Java & Backend Frameworks question(s), under time.
06Answer out loud: Frontend Engineering (Angular & JavaScript)
- Answer aloud, timed: Explain the lifecycle hooks in Angular. In what specific scenarios would you use `ngOnInit` versus `ngAfterViewInit`?
- Answer aloud, timed: How does change detection work in Angular? How can you optimize performance using the `OnPush` change detection strategy?
Deliverable: Spoken answers to 2 reported Frontend Engineering (Angular & JavaScript) question(s), under time.
07Answer out loud: Testing & Engineering Practices
- Answer aloud, timed: Walk me through how you would write a unit test for a service class that depends on an external database repository. How do you mock the repository layer?
- Answer aloud, timed: Explain the difference between unit testing, integration testing, and functional testing. How do these fit into a continuous integration (CI) pipeline?
Deliverable: Spoken answers to 2 reported Testing & Engineering Practices question(s), under time.
Expand any day for tasks and deliverables. Your progress is saved on this device.
Behavioural rounds judge the decision you made and what it cost.
How do you handle transaction management in a Spring-based application? Explain the propagation behaviors avai
How do you handle transaction management in a Spring-based application? Explain the propagation behaviors available in @Transactional.
Approach
- Pick a story where you made the decision, not one where you watched it.
- State the situation in two sentences and spend the rest on the reasoning.
- Give the blast radius: what could have broken, and what you measured.
- Name the disagreement and how you resolved it with evidence.
Follow-up
- What would you do differently if you ran that again?
- How did you know your change caused the improvement?
How do you handle asynchronous messaging in an enterprise application? Explain how you would use MQ or JMS to
How do you handle asynchronous messaging in an enterprise application? Explain how you would use MQ or JMS to decouple system components.
Approach
- Pick a story where you made the decision, not one where you watched it.
- State the situation in two sentences and spend the rest on the reasoning.
- Give the blast radius: what could have broken, and what you measured.
- Name the disagreement and how you resolved it with evidence.
Follow-up
- What would you do differently if you ran that again?
- How did you know your change caused the improvement?
Describe a time when you had to deliver a complex technical solution under a tight deadline. How did you prior
Describe a time when you had to deliver a complex technical solution under a tight deadline. How did you prioritize your tasks and manage stakeholder expectations?
Approach
- Pick a story where you made the decision, not one where you watched it.
- State the situation in two sentences and spend the rest on the reasoning.
- Give the blast radius: what could have broken, and what you measured.
- Name the disagreement and how you resolved it with evidence.
Follow-up
- What would you do differently if you ran that again?
- How did you know your change caused the improvement?
How do you handle a situation where a Product Owner introduces a user story with ambiguous acceptance criteria
How do you handle a situation where a Product Owner introduces a user story with ambiguous acceptance criteria?
Approach
- Pick a story where you made the decision, not one where you watched it.
- State the situation in two sentences and spend the rest on the reasoning.
- Give the blast radius: what could have broken, and what you measured.
- Name the disagreement and how you resolved it with evidence.
Follow-up
- What would you do differently if you ran that again?
- How did you know your change caused the improvement?
Give an example of a time when you mentored a junior engineer. How did you help them build their technical exp
Give an example of a time when you mentored a junior engineer. How did you help them build their technical expertise while ensuring project deadlines were met?
Approach
- Pick a story where you made the decision, not one where you watched it.
- State the situation in two sentences and spend the rest on the reasoning.
- Give the blast radius: what could have broken, and what you measured.
- Name the disagreement and how you resolved it with evidence.
Follow-up
- What would you do differently if you ran that again?
- How did you know your change caused the improvement?
Tell me about a time you had to influence senior leadership to adopt a new technical tool or architectural dir
Tell me about a time you had to influence senior leadership to adopt a new technical tool or architectural direction. What was your approach?
Approach
- Pick a story where you made the decision, not one where you watched it.
- State the situation in two sentences and spend the rest on the reasoning.
- Give the blast radius: what could have broken, and what you measured.
- Name the disagreement and how you resolved it with evidence.
Follow-up
- What would you do differently if you ran that again?
- How did you know your change caused the improvement?
- 01
How do you handle transaction management in a Spring-based application? Explain the propagation behaviors available in `@Transactional`.
- 02
How do you handle asynchronous messaging in an enterprise application? Explain how you would use MQ or JMS to decouple system components.
- 03
Describe a time when you had to deliver a complex technical solution under a tight deadline. How did you prioritize your tasks and manage stakeholder expectations?
- 04
How do you handle a situation where a Product Owner introduces a user story with ambiguous acceptance criteria?
How technical is the interview process for Software Engineers?
The process is highly technical and thorough. You should expect detailed questions covering your primary language, system architecture, and database design. Additionally, you must be prepared for a live coding session where writing clean, testable code is mandatory.
Suntrust Investment Services Software Engineer candidate reports ↗What is the company's stance on unit testing during the interview?
Unit testing is heavily prioritized. Candidates have struggled in the past because they could not set up or write a basic unit test during the live coding session. Ensure you are fully prepared to write and execute unit tests on the fly.
Suntrust Investment Services Software Engineer candidate reports ↗What is the work culture like within the engineering teams?
The culture is highly collaborative, professional, and supportive. Teams operate in mature Agile environments where developers work closely with business partners and product owners. There is a strong emphasis on mentorship, continuous learning, and technical excellence.
Suntrust Investment Services Software Engineer candidate reports ↗How long does the hiring process typically take from start to finish?
The typical timeline spans two to four weeks. This includes the initial HR screen, technical assessments, and the final panel interview. The HR team is generally communicative, but the multi-phased approach means you should plan for a structured, multi-week process.
Suntrust Investment Services Software Engineer candidate reports ↗What topics does Suntrust Investment Services test in interviews?
Suntrust Investment Services interviews most often cover Problem Solving, SQL, Stakeholder Management, Forecasting, and Business Case Development. The exact emphasis depends on the specific role you apply for.
Suntrust Investment Services Software Engineer candidate reports ↗Sources & methodology 3 sources ↗
Official role evidence, timestamped platform data and clearly labeled preparation advice.
- 01Suntrust Investment Services Software Engineer candidate reports ↗
Company-reported rounds, questions and FAQ.
candidate · Accessed 2026-09-22 - 02PracHub Software Engineer practice ↗
PracHub practice material, not company-reported.
platform · Accessed 2026-09-22 - 03PracHub preparation framework ↗
PracHub preparation guidance.
platform · Accessed 2026-09-22