Database Vulnerability Scanning Engineer

AT&T AT&T · Telecom · Charlotte, NC

This role focuses on operating and advancing database vulnerability management capabilities, including discovery, scanning, authentication, and reporting, in partnership with database and application teams for remediation and risk reduction. Responsibilities include administering scanning platforms, performing authenticated scans, tuning policies, supporting various database solutions, coordinating credential access, developing SQL queries, analyzing findings, maintaining dashboards, integrating with ServiceNow, and automating tasks with scripting.

What you'd actually do

  1. Administer and maintain vulnerability scanning platforms and processes focused on database technologies.
  2. Perform authenticated database vulnerability scans, validate results, and tune policies to reduce false positives/negatives.
  3. Support scanning coverage across multiple database solutions including Oracle, MySQL, MariaDB, and DB2.
  4. Coordinate with DBAs, infrastructure, and application teams to configure secure credentials, network paths, and least-privilege access required for scanning.
  5. Develop and maintain SQL queries and scripts to support validation, triage, reporting, and data quality checks.

Skills

Required

  • Hands-on experience performing and supporting database vulnerability scanning (authenticated scanning, policy tuning, and results validation).
  • Experience with multiple database solutions such as Oracle, MySQL, MariaDB, and DB2.
  • SQL development skills (writing queries for validation, triage, reporting, and automation support).
  • Knowledge of various database attack vectors and practices (e.g., privilege escalation, injection patterns, weak authentication, insecure configuration, excessive permissions).
  • Understanding of database security fundamentals: authentication models, roles/privileges, encryption options, auditing/logging, and configuration baselines.
  • Experience with system administration (Linux and Windows) to support scanners, agents, and connectors.
  • Proficiency in scripting/programming (Python, Bash, Perl) for automation and operational support.
  • Minimum of 5-7 years of experience in cybersecurity or vulnerability management, with demonstrated experience supporting database technologies.

Nice to have

  • Experience with vulnerability management tooling and workflows (asset onboarding, credential management, scan scheduling, exception handling, and reporting).
  • Strong knowledge of database security compliance and hardening standards (e.g., CIS Benchmarks, DISA STIGs) and the ability to map scanner findings to control requirements and remediation evidence.
  • Experience supporting audit and regulatory compliance efforts by producing vulnerability metrics, remediation evidence, and documentation aligned to internal policy and applicable standards (e.g., SOX, PCI DSS, HIPAA, GDPR) as required by the environment.
  • Expertise with additional database platforms such as Microsoft SQL Server, Cassandra, MongoDB, and/or Sybase.
  • Knowledge of web site APIs.
  • Understanding of ServiceNow integrations and vulnerability response.
  • Experience with AI technologies (LLM, RAG).
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Relevant certifications (e.g., CISSP, CEH, CompTIA Security+).
  • Familiarity with applying Artificial Intelligence (AI) or Machine Learning (ML) techniques in cybersecurity contexts (e.g., anomaly detection, threat hunting, behavioral analytics, or risk scoring).

What the JD emphasized

  • database vulnerability scanning
  • authenticated scanning
  • policy tuning
  • results validation
  • multiple database solutions
  • SQL development skills
  • scripting/programming (Python, Bash, Perl)
  • cybersecurity or vulnerability management
  • database technologies
  • audit and regulatory compliance efforts
  • AI technologies (LLM, RAG)
  • Artificial Intelligence (AI) or Machine Learning (ML) techniques in cybersecurity contexts