Technology Risk Vulnerability Management and Application Security Domain Lead jobs in United States
cer-icon
Apply on Employer Site
company-logo

AT&T · 23 hours ago

Technology Risk Vulnerability Management and Application Security Domain Lead

AT&T is a global leader in communications and technology, and they are seeking a Technology Risk Vulnerability Management and Application Security Domain Lead. This role is pivotal in overseeing the Technology Risk Management Lifecycle, focusing on application security and infrastructure vulnerability management, while collaborating with teams to enhance the organization's security posture.

CollaborationCommunications InfrastructureMobileService IndustryTelecommunicationsWireless
badNo H1Bnote

Responsibilities

Identify, assess, and document controls and risks across Vulnerability Management & Application Security activities, maintaining a proactive approach to emerging threats and vulnerabilities
Continuously evaluate emerging AI security threats and proactively recommend mitigations and enhancements to existing controls
Drive efforts around Issues Management and Remediation in line with the Technology Risk Management program
Partner with and advise key stakeholders across technology, business, and risk partners to identify, assess, respond, and monitor key risks to keep AT&T and our customers safe and resilient
Support Tech Risk teams responsible for risk monitoring, periodic controls testing, evidence collection, remediation, and audit readiness efforts

Qualification

Vulnerability ManagementApplication SecurityAI Security ThreatsInformation Security RiskCybersecurity ControlsRisk Management PoliciesClient Relationship ManagementCommunication SkillsInterpersonal Skills

Required

5+ years of work experience in technology, operational risk management, or a related discipline at a global company
Significant (5-7 years) experience in multiple industry risk, control, and governance disciplines (e.g., Audit, Information Security, Regulatory Compliance)
Proven experience in vulnerability management and application security, including identifying, assessing, prioritizing, and remediating vulnerabilities in complex environments
Strong understanding of AI-specific threats (e.g., adversarial attacks, model theft, data poisoning) and practical experience in mitigating these risks within enterprise environments
Strong experience in Information security risk and cybersecurity control capabilities with extensive knowledge of information and technology risk management policies, methods, standards, tools, and processes (e.g., ISO, COSO, COBIT, NIST) as well as knowledge of compliance, legal, internal/external audit, and regulatory requirements
Experience identifying, tracking, monitoring, and remediating critical non-compliance issues throughout the issue management lifecycle
Strong client relationship management experience, communication, and influencing skills
Strong interpersonal and oral/written communication skills, able to build relationships with people at all levels

Preferred

Bachelor's Degree in Information Systems, Engineering, Cyber Security, or a related field

Benefits

Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement program
Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)
Paid Parental Leave
Paid Caregiver Leave
Additional sick leave beyond what state and local law require may be available but is unprotected
Adoption Reimbursement
Disability Benefits (short term and long term)
Life and Accidental Death Insurance
Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
Employee Assistance Programs (EAP)
Extensive employee wellness programs
Employee discounts up to 50% off on eligible AT&T mobility plans and accessories
AT&T internet (and fiber where available) and AT&T phone.

Company

AT&T is a telecommunications company that provides wireless communications, internet and digital television services.

Funding

Current Stage
Public Company
Total Funding
$5.04B
Key Investors
National Telecommunications and Information Administration
2025-09-19Post Ipo Debt· $5B
2024-02-12Grant· $42.3M
2023-01-19Grant· $2.2M

Leadership Team

leader-logo
Jeremy Legg
Chief Technology Officer
linkedin
leader-logo
Pascal Desroches
Senior Executive Vice President and Chief Financial Officer
linkedin
Company data provided by crunchbase