This position requires Daily Office Presence at the listed location(s). No relocation assistance is provided.
Reporting to the Associate Director of Cyber Risk Management, you will be responsible for overseeing the end-to-end Technology Risk Management Lifecycle within the Infrastructure and Data Security domains. This pivotal role collaborates closely with the respective teams, with a particular emphasis on Infrastructure and Data Security in the cloud and on premises. The individual in this position is tasked with identifying and assessing risks in these areas, working with stakeholders to develop and implement effective controls, and ensuring the thorough execution of the issues management lifecycle. You will oversee projects related to risk remediation and control implementation and engage with stakeholders to ensure alignment and effective communication regarding risk management efforts. Additionally, this role provides strategic risk management guidance aimed at strengthening the organization’s overall security posture.
What You Will Do:
Identify, assess, and document Infrastructure and Data Security risks across on-premises and cloud environments, evaluate control effectiveness, and proactively address emerging threats, vulnerabilities, and security control gaps related to endpoint security, encryption, and data protection.
Continuously evaluate emerging cybersecurity threats impacting infrastructure, endpoints, cloud platforms, and data security technologies, including Endpoint Detection and Response (EDR), encryption, and key management capabilities, recommending mitigations and enhancements to strengthen the security posture.
Drive Issues Management and Remediation activities related to infrastructure, endpoint security, encryption, and data protection control deficiencies in alignment with the Technology Risk Management program and established risk governance processes.
Partner with technology, security, business, and risk stakeholders to identify, assess, respond to, and monitor infrastructure and data security risks, helping ensure the confidentiality, integrity, availability, and resilience of AT&T systems and customer data.
Lead and support Technology Risk efforts to assess control effectiveness, monitor risk, validate remediation activities, collect audit evidence, and provide ongoing oversight of infrastructure, endpoint security, encryption, and cloud security controls to strengthen organizational resilience and security posture.
What You Will Bring:
Preferred bachelor’s degree in information systems, Engineering, Cybersecurity, Computer Science, or a related field.
7+ years of experience in cybersecurity, technology risk management, infrastructure security, cloud security, operational risk management, or a related discipline within a large enterprise environment.
Significant (5-7 years) experience across multiple risk, control, and governance functions, including Information Security, Technology Risk, Audit, Regulatory Compliance, or Cybersecurity Operations.
Proven experience identifying, assessing, prioritizing, and mitigating Infrastructure and Data Security risks, including risks associated with endpoint security, EDR technologies, encryption, cryptographic key management, cloud services, operating systems, servers, networks, and data protection capabilities.
Strong understanding of cybersecurity threats affecting enterprise infrastructure and data security, including malware, ransomware, unauthorized access, data loss, cloud security risks, endpoint compromise, and encryption-related risks, with demonstrated experience implementing effective risk mitigation strategies.
Strong experience with cybersecurity risk management and security control frameworks, with extensive knowledge of infrastructure security, cloud security, endpoint protection, EDR, encryption technologies, key management systems, vulnerability management, logging and monitoring, and industry standards and frameworks (e.g., NIST, ISO 27001, CIS Controls).
Knowledge of compliance, legal, regulatory, internal audit, and external audit requirements related to infrastructure security, data protection, encryption, and cybersecurity risk management.
Strong client relationship management, communication, and influencing skills, with the ability to build trusted partnerships and effectively communicate technical and risk concepts to stakeholders at all organizational levels.
Familiarity with applying Artificial Intelligence (AI) or Machine Learning (ML) techniques in cybersecurity contexts (e.g., anomaly detection, threat hunting, behavioral analytics, or risk scoring).
AT&T will not hire any applicants for this position who require employer sponsorship now or in the future.
Our Principal Cybersecurity jobs earn between $155,400.00 - $261,100.00 USD Annual. Not to mention all the other amazing rewards that working at AT&T offers. Individual starting salary within this range may depend on geography, experience, expertise, and education/training.
Joining our team comes with amazing perks and benefits:
- Medical/Dental/Vision coverage
- 401(k) plan
- Tuition reimbursement program
- Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)
- Paid Parental Leave
- Paid Caregiver Leave
- Additional sick leave beyond what state and local law require may be available but is unprotected
- Adoption Reimbursement
- Disability Benefits (short term and long term)
- Life and Accidental Death Insurance
- Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
- Employee Assistance Programs (EAP)
- Extensive employee wellness programs
- Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone
Weekly Hours:
40
Time Type:
Regular
Location:
Alpharetta, Georgia, Atlanta, Georgia, Bedminster, New Jersey, Dallas, Texas, Middletown, New Jersey, USA:NC:Charlotte / Ibm Dr - Adm:8505 Ibm Dr
Salary Range:
$155,400.00 - $261,100.00