AVP-Cybersecurity
AT&TAbout the role
Job Description:
Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it.
The AVP Cybersecurity – Vulnerability Management is responsible for directing cyber security areas across products, services, infrastructure, networks, and/or applications while providing protection for AT&T, our customers and our vendors/partners. Additionally, this role will be responsible for overseeing the configuration management program ensuring the integrity, security and consistency of systems and assets across the organization. You will work on various projects relating to the protection of devices, customers, assets, data, information technology, and networks. Supports innovation, strategic planning, technical proof of concepts, testing, lab work, and various other technical program management related tasks associated with the cyber security programs both internal and external. This position has Associate Director Cyber Security and other Cyber Security direct reports.
Key Roles and Responsibilities:
- Vulnerability discovery based on network-based scanning or agent-based collection
- Partnering with the broader Technology team to collect accurate and complete inventory of AT&T assets (applications, devices, IP addresses) in the CMDB.
- Develop and implement comprehensive configuration management strategies to secure IT infrastructure.
- Establish and enforce policies standards and procedures to ensure proper configuration of systems in alignment with organizational goals and compliance requirements.
- External attack surface management - which in includes assuring all externally exposed assets are identified and assessed for security risk
- BugBounty - collection and reward associated with vulnerabilities or issues reported by external sources
- Assessment of identified vulnerabilities for efficacy in the context of the environment, application, and risk
- Solution support - to assist applications with remediation or alleviating risk associated with vulnerabilities
- Reporting – in conjunction with peers within the Cybersecurity organization on vulnerabilities identified, and the actions necessary to remediate.
- Leading remediation efforts - assuring application owner teams understand and take action on their responsibilities to minimize the risk due to vulnerabilities.
- Utilizing threat intelligence to prioritize remediation efforts
Qualifications:
- Requires 15 or more years of related cybersecurity experience.
- Due to the nature of work, US citizenship is required for the role.
- 10+ years of experience in information security, with at least 5 years specifically focused on vulnerability management; including experience with vulnerability assessment tools and methodologies.
- Experience managing security controls, including metrics, reporting, establishing KRIs/KPIs
- Proven track record of leading and managing a high-performing team of security professionals.
- Strong leadership skills with the ability to mentor and develop team members.
- In-depth knowledge of various operating systems (Windows, Linux, macOS), network protocols, and application security.
- Proficiency in using vulnerability scanning tools (e.g., Nessus, Xpanse, etc.) and security information and event management (SIEM) systems.
- Understanding of risk management principles and practices. Ability to assess and prioritize vulnerabilities based on risk and business impact.
- Preferred Master’s Degree in Information Systems, Engineering, Mathematics or relative experience in Cyber Security fields.
- No relocation assistance is provided. Requires on site presence (5 days a week) at one of the listed locations.
Preferred Skills:
- Professional certifications such as CISSP, CISM, CEH, or GIAC.
- Experience with Cloud Security: Demonstrated experience in securing cloud environments (e.g., AWS, Azure, Google Cloud) and familiarity with cloud-native security tools and practices.
- Strong knowledge of regulatory standards and frameworks such as ISO 27001, NIST, GDPR, and PCI-DSS.
- Experience with compliance audits and reporting.
- Incident Response Experience: Hands-on experience in incident response, including the ability to lead and coordinate responses to security incidents and vulnerability exploits.
- Experience with Applicati
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s