Associate Director Cyber Risk Management
Company: AT&T
Location: Charlotte
Posted on: April 6, 2025
Job Description:
Job Description:This position requires office presence of a
minimum of 5 days per week and is only located in the location(s)
posted. No relocation is offered.Join AT&T and reimagine the
communications and technologies that connect the world. Our Chief
Security Office ensures that our assets are safeguarded through
truthful transparency, enforce accountability and master
cybersecurity to stay ahead of threats. Bring your bold ideas and
fearless risk-taking to redefine connectivity and transform how the
world shares stories and experiences that matter. When you step
into a career with AT&T, you won't just imagine the
future-you'll create it.As AT&T Technology Risk AD - Cyber Risk
Lead, you will be responsible for providing independent oversight
of the company's enterprise-wide Cybersecurity control functions in
accordance with the Technology Risk Program. Increasing levels of
risk and regulatory requirements demand additional risk management
rigor, and we must implement highly resilient, reliable, and
effective solutions that meet and in some cases exceed performance
standards found in other information-rich industries. You will
provide leadership and support for Technology Risk initiatives
across the business and advocate for best practices, while
incorporating an independent oversight lens. You will utilize
risk-based management to integrate information and technology risk
processes into the way AT&T operates.Reporting to AT&T's
AVP of Technology Risk - Cyber & Third Party Risk Management, you
will lead a team responsible for identifying, assessing, responding
to, and monitoring risks pertaining to information security, use of
technology third parties, and end-of-service/end-of-life. You will
ensure that regulatory/risk policies and standards and their impact
on business operations are understood and addressed consistently
across AT&T, and that technology risks of new and existing
technology facilities, as well as third-party facilities, are
assessed, monitored, and remediated as necessary. You will help to
provide coverage for regulatory issues with our global technology
partners and assist with regulatory exams, requests, and
meetings.Responsibilities:
- Lead the Cyber risk advisory team in accordance with the
Technology Risk Program and in support of compliance initiatives
within respective business units/functions.
- Provide thought leadership on, as well as, manage the
development of Technology Risk policies, processes, frameworks and
oversee the integration and implementation of proposed
solutions.
- Ensure IT Standards and Policies are fit for purpose and are
appropriate from a regulatory, risk and compliance
perspective.
- Provide expertise to business units around emerging technology
risk topics.
- Work with applicable business, operational and IT organizations
to help ensure that business and IT projects are appropriately
monitored for Cyber risks.
- Provide subject matter advice to technology and business
leaders in support of Tech Risk compliance initiatives.
- Support Tech Risk teams responsible for risk monitoring,
periodic controls testing, evidence collection, remediation and
audit readiness efforts.
- Support efforts to improve the Technology Risk Program's
onboarding capabilities, with the goal of facilitating and
streamlining Program adoption, and simplifying the process for
business units to understand and comply with Program
requirements/controls.
- Periodically assess Technology Program capabilities and
associated maturity levels to identify Program enhancement
opportunities.
- Develop strong relationships and interact with Senior
Leadership, Business Unit Heads, Global Functions, Internal Audit,
External Regulators, Legal and Compliance, Privacy and IT teams to
coordinate activities.
- Develop and deliver executive-level IT risk presentations to
describe risk exposures and actions required.
- Support with escalation of high-risk observations to executive
leadership.
- Support teams conducting risk and control assessments of new
and existing business capabilities.Qualifications:
- Requires Daily Office Presence (5 days a week). No relocation
assistance is provided.
- Preferred Master's degree in Information Systems, Engineering
or Cyber Security related fields.
- 8 - 10 years of work experience in technology, operational risk
management, or a related discipline at a global company.
- Significant (10+ years) experience in multiple industry risk,
control and governance disciplines (e.g. Audit, Information
Security, and Regulatory Compliance).
- Deep experience in:
- Information security risk and cybersecurity control
capabilities in an ownership or oversight capacity.
- Third party security risk and technology third party management
control capabilities within technology organizations or in an
oversight capacity.
- Experience designing, implementing, and sustaining programs
that effectively manage risk throughout the risk management
lifecycle; including:
- Strategic technology risk advisory.
- Risk identification, including emerging risks.
- Maturity and risk assessment, scenario analysis.
- Risk response, mainly issue remediation.
- Risk monitoring.
- Policy and committee governance.
- Demonstrated success in remediating self-identified,
internal/external audit, and regulatory/compliance issues.
- In-depth understanding of information technology and best
practices across the industry as well as project management
principles.
- Extensive knowledge of information and technology risk
management policies, methods, standards, tools, and processes (e.g.
ISO, COSO, COBIT, NIST) as well as knowledge of compliance, legal,
internal/external audit & regulatory requirements.
- Ability to weigh business needs against risk concerns and
effectively articulate issues to different audiences.
- Strong expertise in the collaboration, facilitation and
coordination of the mitigation of risks. Adept at navigating
governance structures. Ability to manage and analyze data.
Experience raising awareness of information and technology risk
throughout an organization.
- Understanding of metrics development and reporting. Strong
problem solving and program execution skills. Ability to prioritize
and drive difficult decisions among business partners.
- Ability to solve very complex risk issues that span legal,
compliance and regulatory obligations across various lines of
business and shared service areas of the company.
- Strong client relationship management experience,
communication, and influencing skills.
- Strong interpersonal and oral/written communication skills,
able to build relationships with people at all levels. Experience
developing and delivering presentations to all levels of
management. Strong ability to develop, lead and manage a
professional staff.Desired Qualification:
- Advanced degree preferred.Our AD - Cyber Risk Lead earns
between $174,100.00-$261,100.00 USD Annual, not to mention all the
other amazing rewards that working at AT&T offers. Individual
starting salary within this range may depend on geography,
experience, expertise, and education/training.Joining our team
comes with amazing perks and benefits:
- Medical/Dental/Vision coverage.
- 401(k) plan.
- Tuition reimbursement program.
- Paid Time Off and Holidays (based on date of hire, at least 23
days of vacation each year and 9 company-designated holidays).
- Paid Parental Leave.
- Paid Caregiver Leave.
- Additional sick leave beyond what state and local law require
may be available but is unprotected.
- Adoption Reimbursement.
- Disability Benefits (short term and long term).
- Life and Accidental Death Insurance.
- Supplemental benefit programs: critical illness/accident
hospital indemnity/group legal.
- Employee Assistance Programs (EAP).
- Extensive employee wellness programs.
- Employee discounts up to 50% off on eligible AT&T mobility
plans and accessories, AT&T internet (and fiber where
available) and AT&T phone.#LI-Onsite - Full-time office
roleAT&T is leading the way to the future - for customers,
businesses, and the industry. We're developing new technologies to
make it easier for our customers to stay connected to their world.
Together, we've built a premier integrated communications and
entertainment company and an amazing place to work and grow. Team
up with industry innovators every time you walk into work, creating
the world you always imagined. Ready to #transformdigital with
us?Apply now!Weekly Hours:40Time Type:RegularLocation:Bedminster,
New JerseySalary Range:$155,400.00 - $261,100.00It is the policy of
AT&T to provide equal employment opportunity (EEO) to all
persons regardless of age, color, national origin, citizenship
status, physical or mental disability, race, religion, creed,
gender, sex, sexual orientation, gender identity and/or expression,
genetic information, marital status, status with regard to public
assistance, veteran status, or any other characteristic protected
by federal, state or local law. In addition, AT&T will provide
reasonable accommodations for qualified individuals with
disabilities.AT&T is a fair chance employer and does not
initiate a background check until an offer is made.
#J-18808-Ljbffr
Keywords: AT&T, Charlotte , Associate Director Cyber Risk Management, Executive , Charlotte, North Carolina
Didn't find what you're looking for? Search again!
Loading more jobs...