Conduct Deliverable Security Reviews (DSRs) for Terraform modules, automation tools,
and orchestrator components (SMO, UNO, DMO, ARA) prior to deployment. Not all
reviews will utilize the full DSR methodology. The Technical Lead will determine the
appropriate DSR processes to apply to a particular review.
o Perform STRIDE-based threat modeling for new platform components and
architecture changes
o Triage automated scan findings (Checkov, Semgrep, SAST/SCA) and produce
verified remediation guidance with severity classification
o Review and validate cross-account IAM role designs, permission boundaries,
trust policies, and OIDC federation for GitHub Actions
o Assess IaC security Terraform module review, provider/module version
pinning, state file protection, HCP workflow security
Conduct security assessments of new tooling integrations entering the AMP ecosystem
Integrate and operationalize SAST/SCA scanning in CI/CD pipelines (GitHub Actions,
CodeBuild, Astra Pipeline)
Support supply chain security SBOM generation, dependency scanning, secrets
scanning
Validate golden AMI security agent installation (Astra, Sentinel) on Outpost VMs
Triage vulnerability findings from Astra, Wiz, and CheckR across HAF and workload
accounts
Assist in AT&T CCOE security alignment across IAM, logging, CI/CD, and application
security domains
Assist in compliance evidence collection for SOX, PCI DSS, and audit readiness
Ensure all project artifacts comply with both AT&T and AWS security policies and
standards.
Experience Requirements
Minimum 5+ years of experience in cloud security with hands-on AWS implementation
Minimum 3+ years of experience with Infrastructure-as-Code security (Terraform,
CloudFormation)
Demonstrated experience with CI/CD pipeline security and DevSecOps practices
Certification Requirements
We also request supporting documentation for at least one of the following active certifications:
AWS Certified Security Specialty
AWS Solutions Architect Professional
The following certification is also preferred for all Security Technical Leads
CISSP (Certified Information Systems Security Professional)