Skip to content

Principal Cybersecurity Attack Surface Mgmt – Process Engineer
Company | AT&T |
---|
Location | Charlotte, NC, USA |
---|
Salary | $141300 – $211900 |
---|
Type | Full-Time |
---|
Degrees | Bachelor’s |
---|
Experience Level | Senior, Expert or higher |
---|
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field. A master’s degree is preferred.
- Minimum of 5-7 years of experience in process engineering, with a focus on attack surface management and inventory hydration.
- Experience with Six Sigma process improvement principles.
- Strong knowledge of Attack Surface Management tools, such as: Xpanse, Censys, Armis, Tenable.
- Proven experience in developing and optimizing processes for security awareness and inventory management.
- Excellent analytical, problem-solving, and communication skills.
- Ability to work effectively in a collaborative, fast-paced environment.
Responsibilities
- Design and implement processes for effective use of Attack Surface Management tools.
- Develop and maintain accurate security inventories through inventory hydration techniques.
- Collaborate with security teams to ensure comprehensive attack surface management and inventory accuracy.
- Optimize processes to enhance security awareness and reduce vulnerabilities.
- Monitor and analyze data from Attack Surface Management tools to identify and address security risks.
- Provide expert guidance on process engineering and inventory hydration to internal and external stakeholders.
- Stay current with the latest trends, threats, and technologies in attack surface management and inventory hydration.
- Conduct training and awareness programs on process engineering and inventory hydration for security teams.
- Prepare and present detailed reports on process effectiveness and security inventory status.
- Develop and document key performance indices for trending and parodic reporting.
- Work with AI technologies, including training Large Language Models (LLM) and utilizing Retrieval-Augmented Generation (RAG).
Preferred Qualifications
- PMP Certification helpful but not required.
- Relevant certifications such as CISSP, CEH, or equivalent are highly desirable.