Expert Cybersecurity - Security Control Validation
AT&TAbout the role
Job Description:
This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.
Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it.
This Expert Cybersecurity position is the visionary and architect of our security control validation program. This position is responsible for evolving our breach and attack program to ensure AT&T’s BAS program maximizes the breadth and depth of our security control validation program and stays current with developments in the field. In addition, this position is responsible for finding new Breach and Attack Simulation security control validation use cases across the enterprise and collaborating with security control and application owners to realize these use cases. This position works across detection engineering, analytics platforms, application, and security controls to validate security controls and subsequent event flows and makes recommendations to improve security posture based on findings.
Responsibilities:
- Drive growth of the security control validation program by developing new use cases
- Set architectural vision to expand program beyond pure BAS to include attack path validation and beyond
- Maintain a wholistic view of security at our enterprise and drive overall posture improvement
- Analyze and interpret breach and attack simulation results
- Identify security control shortfalls, validate log/alerting flows, and prioritize vulnerability remediation efforts by exposure and business criticality
- Stay current with emerging threats and work with vendor to ensure simulations exist for emerging threats
- Work with security control owners to guide breach and attack finding remediation and retest after remediation
- Make recommendations for security posture improvements based on analysis of breach and attack simulation trends
- Work with senior analysts and leadership to develop relevant BAS dashboards to represent program value
- Quantify risk reduction due to breach and attack simulation program
- Leverage APIs and automation techniques to integrate BAS with other security tools
- Maintain awareness of threat landscape to drive BAS scenarios and inform defense strategies
- Report to leadership on quantified risk reduction due to BAS program
Qualifications:
- Education:
- Bachelor’s degree in computer science, information systems, cybersecurity or engineering disciplines or equivalent experience preferred
- Experience:
- Minimum of 15 years of experience in information security, with a focus on threat detection and/or breach and attack simulation or other offensive security discipline.
- Experiencing architecting and implementing large enterprise security solutions
- Experience operating security controls like firewalls, IDS/IPS, endpoint detection and response.
- Experience in security operations environment responding to alerts and incidents.
- Experience in managing and working Security Information and Event Management systems.
- Experience in presenting security issues and business impact clearly.
- Skills:
- Ability to architect large enterprise security solutions
- Offensive security skills such as penetration testing or vulnerability assessment
- Advanced cybersecurity knowledge
- Understanding and experience in application of security best practices and fundamentals as well as familiarity and hands on experience with common security controls such as firewalls, intrusion detection and prevention, web application firewall, endpoint security, data loss prevention, and web proxies.
- Solid networking skills: Understanding and hands on experience with networking technologies such as network addressing, routing and routing protocols, and LAN technologies.
- Cloud fundamentals: Understanding of cloud fundamentals as well as hands-on experience working within cloud environments as well as deploying cloud components
- Solid ability with common operating systems such as Windows, MacOS and Linux and experience in basic administrative tasks such as OS native security controls, networking, and patch management
- Ability to communicate security findings well in terms of risk
- Ability to communicate value of the program in te
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s