Principal Cybersecurity - Endpoint Security Engineer
AT&TAbout the role
Job Description:
This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.
Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it.
This is an action-oriented, operational role. We are seeking a candidate with extensive operational experience in creating and optimizing security policies, troubleshooting complex enterprise technology issues, and supporting clients using the following technologies: Tanium, Data Loss Prevention (DLP), Endpoint Detection and Response (EDR), and network controls such as Proxy, Firewall, and Web Application Firewall (WAF).
Key Roles and Responsibilities:
- Plan and deploy Tanium agent, develop remediation workflow, and create executive reporting
- Operate and maintain enterprise security solutions including Tanium, DLP, EDR, Proxy, Firewall, and WAF.
- Perform application onboarding to security platforms.
- Conduct hands-on deployment, configuration, policy creation, and maintenance for security tools.
- Integrate security platforms with other security solutions and data sources.
- Manage lifecycle activities such as software upgrades, hardware upgrades, and replacements for security tools.
- Respond to end-user issues, outages, and security incidents.
- Lead and coordinate troubleshooting efforts in high-pressure, outage situations with leadership scrutiny.
- Provide thought leadership on operational direction for security tools and associated processes.
- Develop advanced alerts and reports to meet the requirements of key stakeholders and business units.
- Automate security tools management and workflow integration.
- Collaborate with key stakeholders within Information Security and Engineering teams to develop specific use cases to address business requirements.
- Create and implement custom alerting dashboards in SIEM for regular monitoring and investigations.
- Work extensively with business units and stakeholders across organizations to set up and tune security policies.
- Gather and present metrics for measuring key performance and key risk indicators.
- Provide ongoing support to existing monitoring capabilities and data collection systems.
- Lead troubleshooting efforts in complex issues involving multiple platforms and network flows.
- Coordinate with vendors and other technical teams on troubleshooting and escalations.
- Execute scaled security controls engineering and operations work responsibilities.
- Operate within a follow-the-sun model and participate in an on-call rotation to ensure 24/7 response to issues and incidents.
- Track and analyze performance metrics and KPIs, identifying areas for improvement and implementing solutions to enhance efficiency, security efficacy, and ROI.
- Prepare and present regular reports to senior management, highlighting the program's progress, challenges, and achievements.
- Manage and optimize security operations, including monitoring, detection, and response to security incidents. Ensure the continuous improvement of security processes and technologies.
Qualifications:
- 7+ years of experience in cybersecurity engineering with experience configuring, operating, and managing on-premises and cloud-based security solutions.
- Extensive experience providing SME-level support in large, highly dynamic enterprise environments.
- Engineering and administrative experience with Tanium, DLP, EDR, Proxy, Firewall, and WAF.
- Experience with Identity Providers, SSO, SAML, AD, and Microsoft Entra.
- Solid understanding and practical experience with web applications, web platforms, web application security, application firewalls, frameworks, and protocols with respect to application development, deployment, and operation.
- Strong understanding of TCP/IP, web protocols, networking, DNS, and security concepts.
- Expertise with mainstream operating systems, web services, programming languages, network devices, and attack vectors.
- Advanced expertise reviewing and analyzing log files, data correlation, and packet captures.
- Script writing and programming using common shell and mainstream languages.
- Senior-level understanding of PKI technology.
- Working knowledge of open-source and commercial application security tools and fra
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s