Jobs and Careers
AT

Senior – Cyber Risk Management

AT&T
Bedminster, United Statesfull_timeVerifiedPosted 3 Feb 2025
💰 $196,100/yr($116,700/yr$196,100/yr)

About the role

Job Description:

Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it.

As AT&T Technology Risk Senior – Cyber Risk Management, you will be responsible for providing independent oversight of the company’s enterprise-wide Cybersecurity control functions in accordance with the Technology Risk Program.  Increasing levels of risk and regulatory requirements demand additional risk management rigor, and we must implement highly resilient, reliable, and effective solutions that meet and in some cases exceed performance standards found in other information rich industries.  You will provide leadership and support for Technology Risk initiatives across the business and advocate for best practices, while incorporating an independent oversight lens.  You will utilize risk-based management to integrate information and technology risk processes into the way AT&T operates.

Reporting to AT&T’s AD of Technology Risk – Senior Cyber Risk Management, you will be responsible for identifying, assessing, responding to, and monitoring risks pertaining to information security. You will ensure that regulatory / risk policies and standards and their impact on business operations are understood and addressed consistently across AT&T, and that technology risks of new and existing technologies are assessed, monitored, and remediated as necessary. You will help to provide coverage for regulatory issues with our global technology partners and assist with regulatory exams, requests, and meetings.

Responsibilities:

  • Drive efforts around Cyber Risk Management in line with the Technology Risk Management program

  • Partner with and advise key stakeholders across technology, business, and risk partners to identify, assess, respond, and monitor key risks in order to keep AT&T and our customers safe and resilient

  • Guide IT Standards and Policies to be fit for purpose and are appropriate from a regulatory, risk and compliance perspective

  • Research emerging technology risk topics to provide thought leadership to business units

  • Support Tech Risk teams responsible for risk monitoring, periodic controls testing, evidence collection, remediation and audit readiness efforts

  • Support efforts to improve the Technology Risk Program’s onboarding capabilities, with the goal of facilitating and streamlining Program adoption, and simplifying the process for business units to understand and comply with Program requirements/controls

  • Support with escalation of high risk observations to executive leadership

Qualifications:

  • Requires Daily Office Presence at one of the listed locations. No relocation assistance is provided.

  • Preferred Bachelor's degree in Information Systems, Engineering, or Cyber Security. 

  • 3 - 5 years of work experience in technology, operational risk management, or a related discipline at a global company

  • Significant (5 years) experience in multiple industry risk, control and governance disciplines (e.g. Audit, Information Security, and Regulatory Compliance)

  • Strong experience in Information security risk and cybersecurity control capabilities with extensive knowledge of information and technology risk management policies, methods, standards, tools, and processes (e.g. ISO, COSO, COBIT, NIST) as well as knowledge of compliance, legal, internal / external audit & regulatory requirements

  • Experience designing, implementing, and sustaining programs that effectively manage risk throughout the risk management lifecycle; including:

    • Strategic technology risk advisory

    • Risk identification, including emerging risks

    • Maturity and risk assessment, scenario analysis

    • Risk response, mainly issue remediation

    • Risk monitoring

    • Policy and committee governance

  • Demonstrated success in remediating self-identified, internal / external audit, and regulatory / compliance issues

  • Ability to weigh business needs against risk concerns and effectively articulate issues to different audiences

  • Strong expertise in the collaboration, facilitation and coordination of the mitigation of risks. Adept at navigating governance structures. Ability to manage and analyze data. Experience

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

AT&T

View company profile →