AT&T

Sr Specialist System Engineering - Security Engineer

Bengaluru, India Hyderabad, India
Kubernetes Azure Python Go SQL Shell Docker Ansible Git
Description

Job Description:

About the Job:

As a Specialist Cybersecurity and Member of Technical Staff in the Mobility Core Architecture and Network Services (MCANS) organization, this role is responsible for cybersecurity for AT&T Mobility & Voice Core Platform infrastructure, applications, and networks. Work as a team-member with Cloud/Application Architects, Network Engineers, and QA & Test roles including cross-functional teams in the Chief Security Office and Operations to achieve best-in-class security.  Specifically, this role is responsible for proactively identify security risks, propose remediation options, provide recurring data insights that represent the platform security posture, advance the team DevOps methods that improves security through design, testing, and predictive data insights.

Key Roles and Responsibilities:

  • Contribute to ideation, testing, proof of concept and support for various cyber related projects.
  • Analysis of complex security issues and the development and engineering activities to help mitigate risk.
  • Develops policies and procedures to minimize network intrusion, malware events and vulnerability issues for internal and external customers.
  • Applies measures to block malicious code and applications.
  • Includes forward looking research, planning and strategy to strengthen our stance against future cybersecurity threats and enhance our mitigation techniques and technology solutions.
  • Areas of work in this include, but are not limited to: Cyber Incident Response, cyber product testing, cyber risk & strategic analysis, cyber research, cyber awareness & training, cyber vulnerability detection & assessment, cyber intelligence & investigation, cyber networks & systems engineering, cybersecurity application testing, cyber digital forensics & forensics analysis, cyber software assurance, cyber application development & testing, cyber IoT planning & testing, cyber policy & requirements & standards.  
  • Analyze various hardware, operating systems, and/or software solutions recommending purchases and identifying modifications to fit AT&T's cyber security needs and that of our managed services teams.

Day-to-Day Responsibilities

•    Provide cybersecurity oversight in AT&T’s Non-Production SDLC environments: Lead cybersecurity prevention and remediation across applications, platforms, and cloud infrastructure ensuring robust protection for the enterprise and customers.

•    Project Collaboration and Innovation: Partner with senior team members on projects aimed at advancing methods for security testing and predictive mitigation. Drive innovation by contributing to technical proof of concepts, testing, and lab work.

•    Effectively practice proactive threat Mapping and security analysis: Conduct threat mapping, threat modeling, and analysis of hardware, software, and operating systems to develop comprehensive cybersecurity test plans and risk analysis.

•    Investigate recurring internal CSO requirements and programs to educate the team: Stay on top of cutting-edge security technology, internal CSO standards, and best practices to ensure our security measures are always up-to-date and effective.  Learn and communicate advances made within the AT&T Chief Security Office to help the team evolve its practices.

•    Develop and publish security reporting that depicts the platform security health: Prepare detailed reports documenting security test findings, vulnerabilities, risks, and line of sight to remediation. Conduct risk assessments and provide actionable remediation recommendations.

•         Policy and Procedure Development: Develop and implement DevOps and lab policies and procedures to minimize network intrusions, configuration security defects, and vulnerabilities

•    Vulnerability Lifecycle Management: Manage the cybersecurity vulnerability lifecycle, working with development and other teams to report, track, and lead remediation efforts across the SDLC

•   Assist with forward-looking research and tactics: Conduct forward-looking research and techniques to strengthen our defenses against future cybersecurity threats. Enhance mitigation techniques and technology solutions in areas such as Cyber Incident Response, cyber product testing, vulnerability reporting, cyber risk analysis, cyber research, cyber awareness and training, cyber vulnerability detection and assessment, cyber intelligence and investigation, cyber networks and systems engineering, cyber security application testing, cyber digital forensics, cyber software assurance, cyber application

Qualifications

  • 8+ years as in Security Engineering, Security Analysis, and/or DevSecOps/System Administration
  • Bachelor degree in Information Systems, Computer Science, Engineering, or Cyber Security.
  • Familiarity with the OWASP Top 10 and other security concerns for web applications
  • Understanding of OWASP Application Security Verification Standards (ASVS)
  • Understanding of security concepts such as software vulnerabilities, encryption, logging, firewall, SSL, TLS, key vault, security group, container registry, stateful firewall, WAF, NAT, access-list, perimeter security, identity, and access management Skilled in understanding vulnerabilities, assessment of the risk, and the impact on the software, image, VM, Kubernetes clusters, and cloud platforms
  • Web Application Security: Knowledge of web application security concepts, common vulnerabilities (e.g., OWASP Top 10), and techniques for testing web applications, including manual testing and using automated scanners like Burp Suite or OWASP ZAP
  • Understanding of Vulnerability Concepts:  
    • Definition of Vulnerability: A vulnerability is a weakness or flaw in a system, network, application, or process that could be exploited by threat actors to compromise the confidentiality, integrity, or availability of data or resources
    • Vulnerability Classification: Vulnerabilities can manifest in various forms, including software bugs, misconfigurations, design flaws, human errors, and inadequate security controls. Common types of vulnerabilities include buffer overflows, SQL injection, cross-site scripting (XSS), authentication bypass, and insecure direct object references
    • Common Vulnerability Scoring System (CVSS): CVSS is a standardized framework for assessing the severity and impact of vulnerabilities. It provides a numerical score based on factors such as exploitability, impact, and remediation level to help prioritize and manage vulnerabilities effectively.
    • Zero-Day Vulnerabilities: Zero-day vulnerabilities are vulnerabilities that actively exploit applications by threat actors before a patch or mitigation is available from the vendor. These vulnerabilities pose a significant risk because organizations have no advance notice or protection against them.
    • Business Impact:  Evaluating the potential consequences of disruptions to critical business operations, helping organizations understand the financial, operational, and reputational impacts of such events.
    • Exploitability:  Evaluating the feasibility and potential impact of exploiting vulnerabilities within systems or applications, aiding in determining the level of risk posed by these vulnerabilities and guiding prioritization of mitigation efforts
  • Operating System Knowledge: In-depth understanding of various operating systems (e.g., Windows, Linux, Unix) and vulnerabilities.
  • Networking Knowledge: Familiarity with networking protocols, services, and infrastructure components (e.g., TCP/IP, DNS, DHCP, firewalls, routers) to understand potential vulnerabilities in networked environments.
  • Understanding of virtualization, containerization, and Infrastructure as Code (IaC) concepts Skilled in various cloud platforms. E.g. Microsoft Azure
  • Experience with programming languages like Linux Shell, Python for data manipulation and analysis
  • Working knowledge of Excel and/or PowerBI data visualization, Statistical prediction, and data aggregation for dashboards and security management insights
  • Understanding of Docker, OpenStack, and Kubernetes Experienced Continuous Integration/Continuous Deployment (CI/CD) Familiarity with Azure and ADO concepts Administrator level expertise in Linux.
  • Experienced in Ansible and Python scripting Experienced in YAML and JSON file types and their usage Basic familiarity of GO language and GIT.

#SoftwareEngineering

Weekly Hours:

40

Time Type:

Regular

Location:

Bangalore, Karnataka, India

It is the policy of AT&T to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, AT&T will provide reasonable accommodations for qualified individuals with disabilities.

AT&T
AT&T
Collaboration Communications Infrastructure Mobile Service Industry Telecommunications Wireless

0 applies

11 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say

Sid avatar
Sid
Very nice portal for searching jobs in this rough market.
Mar 6, 2025
Michael Duran avatar
Michael Duran
Software Engineer
I've been using this job search site for a while now, and it’s honestly one of the best out there! The clean and easy-to-navigate UI makes the whole job-hunting process so much smoother. Plus, the job postings are always up-to-date, so I never feel like I’m wasting time. The cherry on top is the owner—super kind and always quick to respond. Definitely recommend checking it out if you're on the job hunt!
Aug 21, 2024
Sai avatar
Sai
It’s really great website for finding jobs based on skills it’s really helpful give a go
Aug 21, 2024
Adinadh avatar
Adinadh
What I like most about Echo Jobs is how easy it is to use. The platform helps me quickly find jobs that match my skills and interests, thanks to its great recommendations and filters. Yes, I would definitely recommend Echo Jobs to a friend. It makes job searching simple and efficient, making it a great tool for anyone looking for a new job.
Jul 23, 2024
As a student navigating the job market, I've found LinkedIn increasingly frustrating due to numerous fake postings by consultancies. In contrast, this job posting website has been a game-changer for me. It offers genuine opportunities and a straightforward application process, making it much easier to find and apply for real jobs. Highly recommend it to fellow students seeking reliable job listings!
Jul 16, 2024
Cliff Gor avatar
Echo Jobs has been exceptional in my job hunt where it provides one platform to job hunt and I don't have to open 10 websites just to look for a job. It has also helped me focus much on the job skill and the location filtering out the onsite jobs and remote ones. The only feature that I would request is to display fully remote jobs that are not restricted to a country since the one available shows ie, Remote, US yet. But if it could show remote only, that would be helpful not only to me but to other people applying for full remote and not tied to only US candidates
Apr 22, 2024
I found EchoJobs in 2022, and I love it. It has a lot of remote jobs. It's exclusive to software and technology jobs (helpful for devs like me). What I like the most are its filters and its API. If you're a tech professional seeking remote work, I highly recommend giving it a try to EchoJobs.
Mar 4, 2024
Would definitely recommend it! Excellent product, dedicated founder, Jobs are easier to find. Congrats 🎉 to the entire team!
Mar 3, 2024
Brandon Banks avatar
Brandon Banks
Echo Jobs is really impressive. It provides a great user experience with an ability to quickly search through the many job postings. There is an impressive amount of jobs here and it is quickly updated. The details in the each job posting is helpful when determining if it is worth pursuing. I would highly recommend using Echo Jobs to find the next step in your career.
Mar 2, 2024
Tyler Young avatar
Tyler Young
tylerayoung.com
Best wishes with EchoJobs—it's become my favorite job board overnight!
Dec 16, 2023
Simply put, it's the most up to date tech jobs aggregator I’ve found. I'm like... "I don't have to check 10+ jobs boards daily just to see if there's a new job listing? sign me up!" The filters are also quite helpful! The UI is very clean and straightforward. Love it!
Oct 5, 2023