Senior Cybersecurity Engineer – Mobile & Endpoint Security (AI Enabled Operations)
AT&TAbout the role
This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.
Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it.
We are seeking a Senior Cybersecurity Engineer to secure and modernize our enterprise mobile and endpoint security environment. The initial focus of this role is mobile device security (iOS and Android), including MDM policy deployment, mobile incident response, and persona‑based compliance controls.
Over time, the role will expand to support broader endpoint security platforms such as EDR, DLP, VPN, secure web access, and endpoint visibility platforms. Across both mobile and endpoint domains, the role emphasizes AI‑enabled monitoring, analytics, triage, automation, and reporting to improve security outcomes while reducing operational overhead.
This is a hands‑on engineering role operating at enterprise scale, working closely with Security Operations, Endpoint, IT, and business teams.
Key Responsibilities
Mobile Security Operations (Primary / Initial Focus)
- Monitor, investigate, and respond to mobile device security events and incidents, including policy violations, compliance drift, and emerging threats.
- Deploy, configure, and tune mobile security policies using MDM/UEM platforms (e.g., Intune, Workspace ONE, MobileIron).
- Develop, test, and maintain persona‑based mobile security baselines and compliance rules for office, field, and remote users.
- Analyze mobile telemetry, compliance posture, and alert data to identify risk, drive remediation, and continuously improve control effectiveness.
- Leverage AI‑ and ML‑enabled workflows (including LLM‑assisted analysis) to improve mobile security operations, including:
- Automating intake, enrichment, and triage of mobile application approval requests by extracting key metadata (e.g., publisher, permissions, SDKs, data types) and mapping findings to defined risk criteria.
- Generating structured security and business‑justification summaries to accelerate review cycles, improve consistency, and enhance user experience.
- Design and maintain AI‑driven mobile app approval orchestration, using policy‑as‑code and automated checks to:
- Fast‑track or auto‑approve low‑risk requests
- Escalate high‑risk or exception cases for deeper review
- Integrate with MDM platforms, app reputation sources, and ticketing/workflow systems to reduce administrative overhead and approval timelines.
- Apply AI‑assisted prioritization techniques to reduce alert noise, focus on highest‑risk issues, and scale mobile security operations effectively in a high‑volume environment.
Endpoint Security Platforms (Expanded / Long‑Term Scope)
Support and help engineer endpoint security controls for:
- Endpoint Detection & Response (EDR) (e.g., SentinelOne, Microsoft Defender, Cortex XDR)
- Data Loss Prevention (DLP) (e.g., Microsoft Purview/Defender, Forcepoint)
- Remote Access VPN (e.g., Palo Alto GlobalProtect or equivalent)
- Proxy / Secure Web Access controls (endpoint agent and policy enforcement where applicable)
- Endpoint visibility, posture, and response platforms (e.g., Tanium or equivalent endpoint management and telemetry platforms)
Additional responsibilities include:
- Provide Tier‑3 engineering support, including troubleshooting, policy tuning, exclusions, performance analysis, and vendor escalation.
- Standardize endpoint security baselines and deployment patterns to ensure consistent control coverage and user experience.
- Extend and adapt AI‑driven intake, enrichment, and approval workflows established in Mobile Security Operations to endpoint security use cases, including:
- Automated triage of endpoint security exceptions and access requests
- Correlation of endpoint posture, telemetry, and behavioral signals to defined risk criteria
- Generation of structured risk and justification summaries to support faster, more consistent decisions
- Design and maintain policy‑as‑code and AI‑assisted approval orchestration for endpoint controls, enabling:
- Fast‑track handling of low‑risk exceptions
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s