Performing formal and informal targeted “Hunts” to identify vulnerabilities.
Actively building and participating in Red Team exercises.
Design and execute red team engagements, simulating advanced attack scenarios to identify vulnerabilities and assess the effectiveness of security measures.
Conduct penetration tests on networks, applications, and physical security controls.
Employing tactics to uncover security holes in user practices and procedures.
Develop and execute red team strategies and methodologies to uncover potential security gaps.
Analyze and report on findings from red team exercises, including detailed recommendations for remediation.
Providing feedback and verification as security issues are fixed.
Stay current with the latest security threats, attack techniques, and industry trends.
Communicate complex security concepts to both technical and non-technical stakeholders.
Collaborate with other security teams to improve overall security practices and incident response capabilities.
Be proactive and demonstrate the ability to analyze issues, generate ideas, and initiate action while achieving results.
Effectively manages multiple tasks / projects with close attention to detail and meets short turnarounds and deadlines.
Collaborate with leadership teams, provide subject matter expertise and insights.
Support and guide team members in providing high-quality and actionable intelligence products / deliverables.
Support, guide and mentor team members in technical and functional matters
The expert in this role will perform analysis of complex security issues and corresponding activities to help mitigate risk. Includes forward looking research, planning and strategy to strengthen our stance against future cyber security threats and attacks, and enhancing our mitigation techniques, processes, and technology solutions.
Required skills:
At least 12+ years of experience in penetration testing and red team operations.
Expert level understanding of Transmission Control Protocol / Internet Protocol (TCP/IP) protocols, devices, security mechanisms and how they operate.
Strong understanding of network security threats including APT, botnets, Distributed Denial of Service (DDoS) attacks, worms, and network exploits.
Expert knowledge of attack vectors, exploitation techniques, and vulnerability assessment methodologies.
Experience with industry-standard penetration testing tools and frameworks.
Experience with network probing/testing/analysis tools (Nessus, nmap, burp, wireshark, etc.)
Deep technical knowledge of Windows, UNIX and Linux operating systems as both an expert user and system administrator
Programming skills that will be used to construct, modify, and execute testing tools including shell (ksh, bash), [g]awk, Python, PERL, regex, .NET Programming, Java, C, C++, C#, PowerShell, curl, Web application development (PHP, ASP.NET, etc.)
Comprehensive knowledge of software security testing principles, practices, and tools, experience of vulnerability assessments in a complex environment.
Experience or familiarity with vulnerability analysis, computer forensics tools, cryptography principles
Excellent teamwork skills for collaboration on analysis techniques, implementation, and reporting. Must be able to work both independently as well as effectively in teams of individuals with a variety of skills and backgrounds.
Excellent written and verbal communication skills and have demonstrated ability to present material to senior officials.
Highly self-motivated requiring little direction.
Demonstrates creative/out-of-the-box thinking and good problem-solving skills.
Demonstrates strong ethical behavior.
Sense of urgency and attention to detail
Flexible to provide coverage in US morning hours on a need-basis, and as required
Desirable skills:
Strong knowledge of an enterprise architecture
Ability to obtain a strong and ongoing understanding of the technical details involved in current APT threats and exploits involving various operating systems, applications and networking protocols.
Knowledge of tactics, techniques, and procedures associated with malicious insider activity, organized crime/fraud groups and both state and non-state sponsored threat actors.
Understanding of cloud-based architectures and highly distributed big data architectures
Experience with application security testing tools, such as the Metasploit framework and Burp Suite
It is the policy of AT&T to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, AT&T will provide reasonable accommodations for qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made.
This one's for the grads and early careerists: Our leading internship and development program recruiters weigh in on how to prepare for and handle your interview.
Learn more
September 19, 2024ArticleCareer AdviceRelated Content
Go behind the scenes of our Fiber Sales team. An executive walks us through career growth, commission structure, and why a career with AT&T is more than just a job.
T&T’s India Development Centers (IDC) plays a pivotal role in AT&T’s connectivity strategy, and no one is better suited to speak to that importance more than Santosh Bijur, Vice President of the India Development Center
In our India Development Center (IDC), we’re building a talented technology team. By offering essential resources and the chance to work alongside industry leaders, our goal is to support the next generation of innovators in India.
Looking forward to staying in touch with you. We’ve always got a ton of awesome things going on and by connecting to our Talent Network, you will receive updates on #LifeAtATT, events, and opportunities.
Learn more
February 26, 2025
Benefits
Your needs? Met. Your wants? Considered. Take a look at our comprehensive benefits.