This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.
AT&T will not hire any applicants for this position who require employer sponsorship now or in the future.
Job Summary
As AT&T Technology Risk Principal – Technology Third Party Risk Management (TPRM), you will be responsible for driving risk management efforts to ensure strong discipline and control for AT&T’s engagements with technology third parties, and providing advisory for the company’s enterprise-wide TPRM program. Increasing levels of risk and regulatory requirements demand additional risk management rigor, and we must implement highly resilient, secure, and effective solutions that meet and, in some cases, exceed performance standards found in other information rich industries. You will provide leadership and support for Technology Risk initiatives across the business and strengthen third party risk management through development and maturing of governance and controls. You will utilize risk-based management to integrate information and technology risk processes into the way AT&T and its extended third party ecosystem operates.
Key Roles and Responsibilities
Reporting to AT&T’s AVP of Technology Risk – Cyber & Third-Party Risk Management, you will be responsible for orchestrating a diverse set of stakeholders to identify, assess, mitigate, and monitor third party risks and drive improved governance and control across the program. You will keenly focus on inherent and residual risk of technology third parties that support mission critical systems, access and control sensitive data, and provide hardware and software products that support AT&T operations. You will evaluate the maturity of third party risk management practices and drive program enhancements to design key elements like third party inventory, risk tiering, due diligence, and monitoring. You will ensure that regulatory / risk policies and standards and their impact on business operations are understood and addressed consistently across AT&T, and that third party risks of new and existing technologies are assessed, monitored, and remediated, as necessary. In short, you will help make the AT&T Guarantee a reality by mitigating risks across our extended ecosystem.
Responsibilities:
Drive the evolution of AT&T's Technology Third Party Risk Management program, including processes to identify, assess, mitigate, monitor, and report technology third-party risks
Advise on the design and enhancement of foundational TPRM capabilities, including policies and standards, third-party inventory, risk tiering, due diligence, onboarding, monitoring, and termination activities
Evaluate program maturity and lead improvement initiatives across governance, processes, controls, technology enablement, and data management capabilities
Partner with stakeholders across Supply Chain, Enterprise Risk Management, Compliance, Technology, and Legal to advance strategic program objectives and strengthen risk management practices
Develop executive-level risk assessments, point-of-view documents, and escalation materials related to critical third parties, emerging risks, and program gaps
Serve as a trusted advisor to business units on emerging third-party risk topics, regulatory developments, and industry best practices
Qualifications:
7+ years experience in multiple industry risk, control, and governance disciplines (e.g., Audit, Information Security, and Regulatory Compliance)
5+ years of work experience in third party risk management and/or supply chain processes at a global company with strong understanding of technology products, services, and lifecycles
Strong presentation and executive oral/written communication skills with demonstrated experience leading culture and capabilities change across a diverse set of stakeholder groups
Experience designing, implementing, and sustaining programs that effectively manage risk throughout the risk management lifecycle, including:
Strategic technology risk advisory
Risk identification, including emerging risks
Maturity and risk assessment, scenario analysis
Risk response, mainly issue remediation
Risk monitoring
Policy and committee governance
Demonstrated success in remediating self-identified, internal / external audit, and regulatory / compliance issues with proven ability to shape and solve complex problem statements
Extensive knowledge of information and technology risk management policies, methods, standards, tools, and processes (e.g., ISO, COSO, COBIT, NIST) as well as knowledge of compliance, legal, internal / external audit & regulatory requirements
Desired Qualifications
BS and advanced degree preferred
Professional TPRM related certifications such as CTPRP, TPCRA, TPRMP, CRISC, CISSP preferred
Familiarity with applying Artificial Intelligence (AI) or Machine Learning (ML) techniques in cybersecurity contexts (e.g., anomaly detection, threat hunting, behavioral analytics, or risk scoring).
Joining our team comes with amazing perks and benefits:
- Medical/Dental/Vision coverage
- 401(k) plan
- Tuition reimbursement program
- Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)
- Paid Parental Leave
- Paid Caregiver Leave
- Additional sick leave beyond what state and local law require may be available but is unprotected
- Adoption Reimbursement
- Disability Benefits (short term and long term)
- Life and Accidental Death Insurance
- Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
- Employee Assistance Programs (EAP)
- Extensive employee wellness programs
- Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone
Weekly Hours:
40Time Type:
RegularLocation:
Charlotte, North Carolina, USA:TX:Dallas / One AT&T Plaza (208 S Akard - Whitacre Tower) - Adm:208 S Akard StSalary Range:
$155,400.00 - $261,100.00AT&T and its subsidiaries are committed to equal employment opportunity. All hiring, promotion, and other employment decisions remain merit-based and free from discrimination on the basis of race, color, religion, religious creed, national origin, ancestry, age, sex, sexual orientation, gender, gender identity, gender expression, physical disability, mental disability, pregnancy, medical condition, genetic information, marital status, citizenship status, military status, veteran status, or any other characteristic protected by federal, state, or local laws. In addition, AT&T will provide reasonable accommodations to qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made. Click here to learn more or request an application accommodation here.
Skills Required
- 7+ years experience in multiple industry risk, control, and governance disciplines (e.g., Audit, Information Security, Regulatory Compliance).
- 5+ years of work experience in third party risk management and/or supply chain processes at a global company.
- Strong presentation and executive oral/written communication skills with demonstrated experience leading culture and capabilities change.
- Experience designing, implementing, and sustaining programs that manage risk across the risk lifecycle (identification, assessment, response, monitoring, governance).
- Demonstrated success in remediating internal/external audit and regulatory/compliance issues.
- Extensive knowledge of information and technology risk frameworks, methods, standards, tools, and processes (e.g., ISO, COSO, COBIT, NIST).
- Must be authorized to work without employer sponsorship now or in the future.
- Office presence minimum of five days per week in the posted location; no relocation offered.
- BS and advanced degree preferred.
- Professional TPRM-related certifications such as CTPRP, TPCRA, TPRMP, CRISC, CISSP preferred.
- Familiarity with applying AI or Machine Learning techniques in cybersecurity contexts (anomaly detection, threat hunting, behavioral analytics, risk scoring) preferred.
AT&T Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about AT&T and has not been reviewed or approved by AT&T.
-
Healthcare Strength — Health coverage spans medical, dental, vision, and mental health services, plus a personal healthcare team, wellness apps, and supplemental options such as fertility care, cancer support, doula services, and wigs for chemotherapy. These comprehensive offerings are portrayed as supporting a wide range of employee needs.
-
Leave & Time Off Breadth — Paid time off includes vacation, holidays, sick days, caregiver time, parental leave, and adoption assistance, with some roles reaching about 23 days of PTO after several years. Community volunteer days and flexible time off options add further support for work-life balance.
-
Wellbeing & Lifestyle Benefits — Employees receive sizable service discounts like 50% off most wireless plans and broadband, along with savings on travel, event tickets, and insurance. Additional workplace perks such as hybrid work models and relocation assistance contribute to overall value.
AT&T Insights
What We Do
Bring us your biggest career aspirations. Share your boldest dreams. This is a moment to get energized. Through 5G and Fiber, AT&T provides connectivity that leads to smarter homes, safter communities, higher quality health care and more life-changing innovations. With AT&T, Connecting Changes Everything.
Gallery






