Jobs and Careers
AT

Associate Director Cybersecurity Policy Compliance Management (PCM)

AT&T
United Statesfull_timeVerifiedPosted 29 Sept 2025
💰 $233,200/yr($155,400/yr$233,200/yr)

About the role

Job Description:

This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.

Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it.

The Associate Director –Cybersecurity, Policy Compliance Management (PCM) will lead and manage the team responsible for AT&T’s Policy Exception Request (PER) process within the Chief Security Office. This role is critical for ensuring all non-compliances to AT&T Security Policies and Standards are proactively identified, thoroughly assessed, documented, tracked, and resolved in accordance with corporate risk management and audit requirements.

What You Will Do:

  • Lead the PCM team, ensuring effective execution of all phases of the PER process—including intake, quality review, risk assessment, approvals, and closure.

  • Oversee identification, documentation, and management of non-compliances to AT&T Security Policies and Standards, ensuring each PER is rigorously and rapidly assessed for risk, business impact, and remediation planning.

  • Leverage AI-driven tools and analytics for risk scoring, decision support, and automated non-compliance risk ratings—integrating data from PER, iTAP, and policy sources to deliver actionable insights for mitigation and business decision-making.

  • Drive the creation and delivery of streamlined, simplified leadership dashboard reports highlighting key compliance metrics and trends for executive audiences, ensuring both comprehensive coverage and timely delivery.

  • Ensure close collaboration between the PCM team, Business Units, risk owners, and CSO partners (e.g., BISOs, Tech Risk, PCI, SOX, FirstNet) across the PER workflow, providing expert guidance on compliance requirements and risk mitigation strategies.

  • Champion the use of ServiceNow for workflow automation, reporting, and record-keeping, maximizing operational efficiency, AI integration, and auditability across all PER activities.

  • Collaborate closely with CSO Security Policy Governance leadership, peer teams, and the CSO Security Policy Governance Innovation expert/architect to foster a cohesive, innovative partnership that leverages AI and drives alignment.

  • Work closely with the CSO Technology Risk team to identify and align Technology Risk Issues (TRIs) with Policy Exception Requests (PERs), ensuring an auditable process for detecting significant systemic risks across the AT&T enterprise.

  • Monitor and report on remediation progress, including funding status and escalations, to ensure business units are accountable for timely compliance or properly documented business decisions.

  • Create and maintain comprehensive, auditable process documentation and playbooks for the PCM/PER process, ensuring accessibility and clarity.

What You Will Bring:

  • Master’s Degree in Computer Science or Cybersecurity preferred.

  • 5+ years in information security, risk management, or policy compliance, with significant experience managing compliance exception processes and cross-functional teams.

  • Expert knowledge of Security Policies and Standards, the PER process, risk assessment methodologies (e.g., NIST 800-30), Technology Risk Issues, and AT&T’s strategic ServiceNow technologies.

  • Demonstrated experience reviewing user stories and leading User Acceptance Testing (UAT) within ServiceNow or similar agile environments, ensuring robust adoption of agile methodologies and successful delivery of business requirements.

  • Experience leveraging AI or advanced analytics for risk scoring, compliance automation, and data-driven decision support.

  • Proven leadership in managing teams responsible for compliance artifact creation, risk evaluation, remediation tracking, and stakeholder engagement.

  • Ability to review, interpret, and provide feedback on tools, user stories, and UAT processes developed by Security Policy Governance Innovation experts/architects, ensuring alignment with agile methodologies and organizational goals.

  • Proven ability to build and maintain collaborative relationships with Security Policy Governance leadership, peer teams, and the Security Policy Governance Innovation expert/architect, driving innovative, AI-aligned teamwo

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

AT&T

View company profile →