Appsec Vulnerability Risk Lead

AT&T AT&T · Telecom · Dallas, TX +1

This role focuses on identifying, assessing, and mitigating AI security threats within the context of application security and infrastructure vulnerability management. It involves evaluating AI-specific risks and recommending controls to strengthen the organization's security posture.

What you'd actually do

  1. Identify, assess, and document controls and risks across Vulnerability Management & Application Security activities, maintaining a proactive approach to emerging threats and vulnerabilities.
  2. Continuously evaluate emerging AI security threats and proactively recommend mitigations and enhancements to existing controls.
  3. Drive efforts around Issues Management and Remediation in line with the Technology Risk Management program.
  4. Partner with and advise key stakeholders across technology, business, and risk partners to identify, assess, respond, and monitor key risks to keep AT&T and our customers safe and resilient.
  5. Support Tech Risk teams responsible for risk monitoring, periodic controls testing, evidence collection, remediation, and audit readiness efforts.

Skills

Required

  • 5+ years of work experience in technology, operational risk management, or a related discipline at a global company.
  • Significant (5-7 years) experience in multiple industry risk, control, and governance disciplines (e.g., Audit, Information Security, Regulatory Compliance).
  • Proven experience in vulnerability management and application security, including identifying, assessing, prioritizing, and remediating vulnerabilities in complex environments
  • Strong understanding of AI-specific threats (e.g., adversarial attacks, model theft, data poisoning) and practical experience in mitigating these risks within enterprise environments.
  • Strong experience in Information security risk and cybersecurity control capabilities with extensive knowledge of information and technology risk management policies, methods, standards, tools, and processes (e.g., ISO, COSO, COBIT, NIST) as well as knowledge of compliance, legal, internal/external audit, and regulatory requirements.
  • Experience identifying, tracking, monitoring, and remediating critical non-compliance issues throughout the issue management lifecycle.
  • Strong client relationship management experience, communication, and influencing skills.
  • Strong interpersonal and oral/written communication skills, able to build relationships with people at all levels.

Nice to have

  • Bachelor's Degree in Information Systems, Engineering, Cyber Security, or a related field.

What the JD emphasized

  • AI security threats
  • mitigating these risks