AT&T

Lead Cybersecurity - Application Security Architect – AI Models, Frameworks & Implementation

AT&T$128K — $192K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4-8 years in application security with hands-on DAST experience.
  • Proficiency in testing web applications, APIs, and mobile apps for security flaws.
  • Experience integrating DAST tools into CI/CD pipelines and DevSecOps practices.
  • Strong knowledge of application security standards like OWASP Top Ten.
  • Familiarity with programming languages such as Java, Python, and JavaScript.,

Responsibilities

  • Lead implementation and configuration of DAST tools in development pipelines.
  • Define standards for dynamic application security testing practices.
  • Conduct in-depth vulnerability assessments on various applications.
  • Collaborate with cross-functional teams to integrate DAST into CI/CD workflows.
  • Validate DAST findings and prioritize remediation based on risk.
  • Stay updated on emerging application security threats and vulnerabilities.
  • Provide training on DAST reports and remediation strategies.

Benefits

  • Comprehensive medical, dental, and vision coverage.
  • 401(k) plan with employer contribution.
  • Tuition reimbursement for further education.
  • At least 23 days of paid vacation and 9 paid holidays annually.
  • Paid parental and caregiver leave options.
  • Adoption reimbursement available.
  • Access to disability benefits and life insurance options.
  • Employee wellness programs and assistance programs.
  • Generous discounts on AT&T products and services.
Full Job Description

This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.

We are seeking an Application Security Architectto secure the design, development, integration, and operation of AI/ML-enabled applications, includingLLMs, agent-based systems, RAG pipelines, model-serving APIs, and AI orchestration frameworks, as well as advance the vulnerability management program as it relates to AI based vulnerabilities. This role combinesapplication security architecturewithAI security engineeringto reduce risk across the full AI lifecycle 6om data ingestion and model integration to inference-time protections and production governance 6and leadAI Security from a vulnerability management and risk-reduction perspective. This role is primarily focused on identifying, assessing, prioritizing, and helping remediate security weaknesses across AI-enabled applications, services, models, and integration patterns in order to reduce exploitability and accelerate remediation.

The ideal candidate combines strongApplication Security expertisewith practical experience securingAI/ML systems, LLM-based applications, agentic workflows, and model integrations. This individual should understand both traditional AppSec principles and AI-specific attack patterns and be able to apply that knowledge to improve vulnerability discovery, risk triage, security testing, architecture review, and remediation guidance across the AI lifecycle.

We are looking for a technically minded, hands-on security architect who can evaluate AI implementations for real security risk, define effective controls, partner with engineering teams to remediate issues, and improve how AI-related vulnerabilities are managed across development and production environments. The right candidate will also bring coding aptitude and implementation experience to support secure development workflows, integrate security checks and automation, implement security controls in applications and pipelines, and build practical solutions where necessary to improve coverage, consistency, and speed.

Job Summary:

TheApplication Security Architect is responsible for defining and driving secure-by-design approaches for AI-enabled applications and services. This role focuses on protecting the full lifecycle of AI/ML systems, including:

  • LLM-based applications
  • Agentic workflows
  • Retrieval-augmented generation (RAG)
  • Model APIs and inference services
  • Training/fine-tuning pipelines
  • Third-party AI integrations and SaaS capabilities

The architect will work closely with application teams, enterprise architects, AI/ML engineers, developers, cloud/platform teams, and security stakeholders to establish secure patterns, identify AI-specific risks, implement technical controls, and support responsible adoption of AI capabilities across the organization.

Success in this role requires:

  • Deep understanding ofapplication security architecture
  • Strong knowledge ofAI/ML technologies, frameworks, and deployment models
  • Hands-on experience withAI security controls and implementation
  • Ability tocode, automate, integrate, and validatetechnical solutions
  • Practical familiarity withAI security standards and threat frameworks
  • Hands-on familiarity with source control, repository workflows, CI/CD integration, and artifact/package management, including platforms such as GitHub and JFrog

Detailed Job Description:

This role is centered on securing AI-enabled applications and platforms through a combination ofapplication security architecture, AI threat modeling, technical design review, secure implementation guidance, and control validation.

You will help define how AI solutions are securely adopted and deployed, whether they are built in-house, fine-tuned from existing models, or integrated through third-party APIs and enterprise AI platforms. This includes securing AI-related application flows such as:

  • Prompt handling
  • Model invocation
  • Data retrieval and context injection
  • Plugin/tool calling
  • Agent permissions and action boundaries
  • Output validation and post-processing
  • API exposure and service-to-service integration

You will assess and mitigate AI-specific threats such as:

  • Prompt injection
  • Jailbreaking
  • Data poisoning
  • Training-data leakage
  • Sensitive data exposure
  • Model inversion and extraction
  • Excessive agency in autonomous workflows
  • Unauthorized model/API access
  • Abuse of model-serving endpoints

The right candidate will bring anAppSec mindset first 6understanding secure design, trust boundaries, authn/authz, API risk, abuse cases, and vulnerability management 6while also possessing hands-on familiarity withAI ecosystems, orchestration frameworks, model integration patterns, and AI deployment architectures.

Key Responsibilities:

AI Security Architecture & Design

  • Design, review, and validate secure architectural patterns for AI/ML and LLM-enabled applications, includinglocally hosted models, cloud-native AI services, API-based model access, RAG systems, and agent-based workflows.
  • Define secure reference architectures for AI integrations across applications, services, and platforms.
  • Ensure security is embedded into AI solution design from the start, including trust boundaries, identity controls, data flows, model access, and output handling.
  • Advise teams on secure use of frameworks such asAzure AI Foundry, LangChain, Semantic Kernel, OpenAI/Azure OpenAI integrations, and similar orchestration or inference technologies.

AI Threat Modeling & Security Reviews

  • Leadthreat modelingsessions for AI-enabled applications and platforms to identify abuse cases, architectural weaknesses, and control gaps.
  • Assess risks such asprompt injection, model evasion, data poisoning, jailbreaks, model inversion, model extraction, tool misuse, and unauthorized privilege escalation through agent workflows.
  • Conduct technical security reviews of AI applications, integrations, and architectures with clear remediation recommendations and risk prioritization.
  • Translate AI threat scenarios into practical mitigations that development and engineering teams can implement.

Guardrails, Controls & Secure Implementation

  • Define and implement AI-specific security guardrails, includingprompt/input filtering, context validation, output sanitization, response validation, policy enforcement, model/tool access restrictions, and sensitive data handling controls.
  • Recommend and help implement controls forhuman-in-the-loop approvals, action scoping, tool permissions, content safety, and unsafe output suppression in agentic or autonomous systems.
  • Validate that security controls are effective in real usage scenarios and resilient against adversarial behavior.
  • Support application teams in integrating AI protections into code, middleware, APIs, and orchestration frameworks.

MLSecOps / DevSecOps for AI

  • Embed security into the AI/ML development lifecycle by integrating controls intoCI/CD and ML pipelines, including data ingestion, model packaging, deployment, and runtime validation.
  • Help implement security scanning and policy checks formodels, datasets, dependencies, containers, APIs, infrastructure-as-code, and deployment pipelines.
  • Define secure operational patterns for model versioning, rollback, promotion, and change management.
  • Partner with engineering teams to automate repeatable security checks and guardrails across AI-enabled delivery pipelines.

Software Engineering & Repository Security

  • Write, review, and where needed help implement code to support AI security controls, automation, integrations, and remediation activities.
  • Work within standard software development workflows usingsource control platforms such as GitHub, including branch management, pull requests, code review, and CI/CD integration.
  • Partner with engineering teams to secure repositories, workflows, secrets handling, dependency use, and release processes.
  • Support secure management of artifacts, packages, containers, and model-related assets through repositories and platforms such asJFrog Artifactory.
  • Help establish secure practices for versioning, promotion, provenance, and lifecycle management of code, models, packages, and deployment artifacts.

AI Incident Readiness & Response

  • Develop AI-focused incident response guidance and playbooks for scenarios such as prompt-based abuse, sensitive data leakage, poisoning, model misuse, or unauthorized access to AI components.
  • Support investigations involving AI-enabled applications by providing architectural context, attack-path analysis, and mitigation recommendations.
  • Help teams improve resilience and detection capabilities based on lessons learned from testing, incidents, and near misses.

Vulnerability Management for AI Systems

  • Establish processes for identifying, assessing, prioritizing, and tracking vulnerabilities or control gaps inAI-enabled applications, model-serving endpoints, datasets, orchestration layers, and supporting infrastructure.
  • Drive risk-based prioritization of AI security issues, balancing exploitability, exposure, data sensitivity, and business impact.
  • Support remediation efforts by recommending practical fixes such as architectural changes, guardrail improvements, retraining/tuning strategies, or access-control enhancements.
  • Help define how AI-related findings are documented, triaged, and governed within broader AppSec and vulnerability management workflows.

Application Security & Vulnerability Management Focus

  • Secure thedata supply chainfor AI systems, including training, tuning, embeddings, vector stores, and contextual retrieval components.
  • Protect againstprompt injection and indirect prompt injectionthrough layered controls, trust-boundary design, input validation, and context isolation strategies.
  • SecureAPI endpoints serving AI predictions or orchestration actionsusing strong identity, access control, rate limiting, abuse prevention, and logging/traceability.
  • Focus onrisk reduction and control effectivenessfor AI vulnerabilities, including cases where mitigation relies on architecture, policy, or model behavior controls rather than traditional patching.
  • Ensure securemodel and artifact versioning, provenance awareness, and rollback capabilities in cases of drift, poisoning, or faulty releases.
  • Apply traditional AppSec principles 6such as secure design, authn/authz, secrets protection, input handling, dependency security, and least privilege 6to AI-enabled systems and integrations.

Qualifications / Requirements / Skills:

  • 7+ yearsof experience inapplication security, product security, security architecture, or secure software engineering, with at least2 3 years focused on AI/ML or LLM security, AI-enabled application architecture, or adversarial AI security.
  • Strong background inapplication security principles and methodologies, including secure design review, threat modeling, vulnerability management, API security, authn/authz, and secure SDLC practices.
  • Demonstrated experience securingAI/ML systems, LLM-enabled applications, or AI integration patternsin enterprise or production environments.
  • Practical experience withAI models, frameworks, and orchestration technologies, such asAzure AI Foundry, Azure OpenAI/OpenAI APIs, LangChain, Semantic Kernel, Hugging Face, TensorFlow, PyTorch, or similar ecosystems.
  • Hands-on experience implementing security controls for AI use cases, includingprompt filtering, output validation, model access controls, data protections, agent/tool guardrails, and monitoring.
  • Strong understanding of AI-specific threats such asprompt injection, jailbreaks, model inversion, data poisoning, model extraction, insecure plugins/tools, and sensitive data leakage.
  • Demonstrated ability towrite, review, and implement codewhen needed, including scripting, prototyping, automation, integrating security controls into applications and CI/CD pipelines, and building practical solutions to support AppSec and AI security use cases.
  • Proficiency in one or more programming/scripting languages such asPython, JavaScript/TypeScript, Go, or Bash;Python strongly preferred, with the ability to work comfortably in existing codebases, automation scripts, and integration layers.
  • Experience working withcloud-native platformsand services (Azure preferred; AWS/GCP also valuable), including APIs, containers, IAM, secrets management, logging, and deployment pipelines.
  • Strong familiarity with AI and AppSec frameworks such asOWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, and secure architecture principles for AI systems.
  • Practical experience working withsource code repositories and modern development workflows, including branching, pull requests, code review, repository hygiene, and CI/CD integration.
  • Experience using or supportingGitHub-based development environments, including repository management, Git-based workflows, and security integration into build and deployment pipelines.
  • Familiarity withartifact, package, and binary repository management, including platforms such asJFrog Artifactory, to support secure handling of dependencies, build artifacts, containers, models, or related software assets.
  • Strong communication skills with the ability to work across engineering, architecture, data science, security, risk, and l

About AT&T

Cricket Wireless is a U.S.-based company that offers prepaid wireless voice, text, and data services. Cricket Wireless was founded in 1999 by Leap Wireless International, Inc. Currently, it operates as a subsidiary of AT&T Inc.

AT&T Careers

Joining AT&T means becoming part of a global team known for driving innovation and leading the telecommunications industry. It's an opportunity to grow your career at one of the most diverse and resource-rich companies in the world. Work You'll Do At AT&T, we're not just about phone lines and data plans. We're about connecting people and fostering relationships. As a member of our team, you'll help deliver cutting-edge solutions across various sectors, ensuring that our services are not only available but also transformative. Lead with Innovation Embrace a role at AT&T where technology meets creativity. Our professionals lead the market in developing and deploying technology solutions that transform how people communicate and do business. We are pioneers in creating new paths for technology, with a focus on sustainable and responsible innovation. Join a Diverse and Inclusive Team AT&T is committed to diversity and inclusion, ensuring that all employees can thrive. We are proud to offer diversity training and leadership programs that empower our team members to grow professionally and personally. Our culture is one of inclusivity, where every voice is heard and valued. Explore Job Opportunities Whether you're looking for an entry-level position or a more senior role, AT&T offers a range of job opportunities across various fields. From engineering to marketing, our team is composed of skilled professionals who are leaders in their respective areas. Internship Programs Kickstart your career with an AT&T internship. Gain hands-on experience, work on real projects, and learn from leaders in the industry. Our internships provide a robust platform for learning and growth, helping you build skills that are crucial for future success. Benefits and Growth AT&T is dedicated to the growth and development of its employees. We offer comprehensive benefits, including health care, retirement plans, and continuous professional development opportunities. With resources like career coaching and resume workshops, we support your journey every step of the way. Networking and Professional Development Expand your professional network within AT&T through various networking events, mentorship opportunities, and collaborative projects. Our focus on career development is designed to help you reach your professional goals, enhancing your skills and preparing you for leadership roles. Stay Connected Join Our Team Discover the career you've always wanted by exploring the open positions at AT&T. We are constantly on the lookout for passionate, innovative, and driven individuals to join our team. Check out our current job listings and find where your skills and interests align with our needs. Keep Up to Date Stay informed with the latest career tips, company news, and industry insights—all from the professionals who are part of our team. AT&T is a place where you can make an impact, leading the way in the telecommunications industry. Job Alert Emails Customize your experience by signing up for job alerts that match your career preferences. Stay ahead of the curve and be the first to know about exciting and rewarding opportunities at AT&T. At AT&T, your career is poised for success, equipped with the right tools, culture, and team to make it happen. Join us and be part of a company that values innovation, leadership, and a diverse workforce.
Learn more about AT&T
Size
203,000 employees
Market Cap
$131.2 billion
Industry
Net Income
-$5.1 billion
Founded
1983
5 Year Trend
+0.6%
Revenue
$171.7 billion
NASDAQ

Similar Jobs

More Jobs at AT&T

More Information Technology Jobs

Find similar Lead Cybersecurity - Application Security Architect – AI Models, Frameworks & Implementation jobs: