Overall Purpose:
This career step requires expert level experience. Responsible for cyber security areas across products, services, infrastructure, networks, and/or applications while providing protection for AT&T, our customers and our vendors/partners. Works with senior team members on various projects relating to the protection of devices, customers, assets, data, information technology, and networks. Supports innovation, strategic planning, technical proof of concepts, testing, lab work, and various other technical program management related tasks associated with the cyber security programs.
Key Roles and Responsibilities:
Includes ideation, testing, proof of concept and support for various cyber related projects. Analysis, of complex security issues and the development and engineering activities to help mitigate risk. Analyzes various hardware and/or software solutions recommending purchases and identifying modifications to fit AT&T's cyber security needs and that of our managed services teams. Develops policies and procedures to minimize network intrusion, malware events and vulnerability issues for internal and external customers. Applies measures to block malicious code and applications. Includes forward looking research, planning and strategy to strengthen our stance against future cyber security threats and enhance our mitigation techniques and technology solutions. Areas of work include, but are not limited to: Cyber Incident Response, cyber proudct testing, cyber risk & strategic analysis, cyber research, cyber awareness & training, cyber vulnerability detection & assessment, cyber intelligence & investigation, cyber networks & systems engineering, cyber security application testing, cyber digital forensics & forensics analysis, cyber software assurance, cyber business operations & support, cyber application development & testing, cyber operational support, cyber IoT planning & testing, cyber policy & requirements & standards.
The candidate will work as a principal member of the AT&T Chief Security Office, Threat Analytics Expansion Program, as a lead on a project that analyzes event data for security relevant events using a variety of network-data processing platforms. The candidate will work in a collaborative manner across teams, leading other analysts to identify, characterize, provide recommendations for remediation, tools creation and define analytical methods to automate the analysis. The candidate will perform ad-hoc analytical processing on a variety of network data feeds, system processed data derivatives (metadata), automated system alerts, and open source information utilizing appropriate system tools and software. This will require collaboration with other analysts, as well as collaboration with outside organizations. The analyst will require knowledge in some of the newest areas of security including Cloud technology, Big Data environments, Mobility, and Advanced Persistent Threats. Some aspects of the analysis may require use of deep packet inspection packet analysis.
The candidate will be responsible for reporting findings in written and verbal form. Results of analysis will be used to inform management, notify affected customers, advise network operations, and advise network engineering on security issues as well as recommended remediation and solutions. The candidate will also work with researchers to help define algorithms for automation of ad-hoc analysis methods and will work with the analysis platform engineering and development team to help define automated processing reports and alerts for automation of ad-hoc processes.
Responsibilities Include:
80% Cyber Security Data Developer. Lead the creation and maintenance of enhanced analytics security platforms, algorithms, tools and portals to evaluate threat events and risks for AT&T customers and AT&T infrastructure. Leads development teams by mentoring, training and evaluating progress and advancement of new team members and creates learning and training programs to enhance skillsets of analyst team members. Principle lead in developing, deploying and utilizing new tools, algorithms and applications to enhance the current Flood Analyst platform to allow for more detailed investigations by evolving platforms to utilize machine learning, artificial intelligence, automation, orchestration and virtualization. The lead builds requirements, strategies, and tactics to meet the needs of Threat Analytics security services.
20% Lead the use and maintenance of enhanced analytics security platforms, algorithms, tools and portals to determine threats against AT&T infrastructure, customers and assets. Principle lead will work with AT&T BU’s, AT&T customers and vendor community to evaluate new and evolving cyber threats, via newly developed Cyber collaboration tools, platforms and processes which will enhance and increase the communication collaboration cycle.
Training/Special Skills:
Programming expertise using Python, C and C++
- Industry knowledge of software security testing principles, practices, and tools, experience of vulnerability assessments in a complex environment.
- Experience or familiarity with cybersecurity principles, security investigation and protocol analysis
- Excellent teamwork skills for collaboration on analysis techniques, implementation, and reporting. Must be able to work both independently as well as effectively work in teams of individuals with a variety of skills and backgrounds.
- Excellent written and verbal communication skills and have demonstrated ability to present material to senior officials.
- Technical knowledge of Windows and linux operating systems as both an user and system administrator
- Highly self-motivated requiring little direction.
- Demonstrates creative/out-of-the-box thinking and good problem solving skills.
- Demonstrates strong ethical behavior.
Job Contribution: Expert level technical professional. Advisor on technical knowledge and ATT technologies.
Education: Preferred Bachelors degree in Information Systems, Engineering, Mathematics or Cyber Security or equivalent experience.
Experience: Typically requires 8-10 years experience. Technical Career Pathway (TCP) role.
Supervisory: No.