Jobs Companies AT&T Lead Cybersecurity – Insider Risk Analyst (Telemetry, Insider Risk Detection, and AI-Driven Security Operations)

Über diese Lead Cybersecurity – Insider Risk Analyst (Telemetry, Insider Risk Detection, and AI-Driven Security Operations) Stelle bei AT&T

AT&T · Vor Ort · USA:NC:Charlotte / Ibm Dr - Adm:8505 Ibm Dr

This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.

Join AT&T and help shape the future of communications and technology that connect the world. We value innovators who seek to explore the unknown and challenge the status quo. Bring your bold ideas and fearless spirit to redefine connectivity and transform how people share stories and experiences. At AT&T, you won’t just imagine the future—you’ll build it.

The Lead Cybersecurity Insider Risk Analyst leads the response to high-priority and escalated cybersecurity incidents, with a focus on insider risk and telemetry-driven detection. This role oversees end-to-end incident handling—including detection, analysis, containment, eradication, recovery, reporting, and prevention—across employees, contractors, and third-party vendors. The position also drives continuous improvement through development of new detection logic, micro-hunts, and the integration of automation and AI-assisted analytics to increase detection fidelity and reduce manual effort. Success in this role requires advanced technical depth, strong operational rigor, and the ability to communicate clearly with both technical teams and executive stakeholders. 

Key Roles and Responsibilities 

  • Incident leadership: Serve as lead handler for escalated insider risk and cyber incidents; establish investigation strategy, ensure timely execution, and drive incident closure. 
  • Advanced investigation and triage: Conduct deep-dive analysis of security events using telemetry, endpoint/network evidence, and threat intelligence to determine scope, impact, and root cause. 
  • Detection engineering and continuous improvement: Create, tune, and deploy new detection rules and analytics aligned to evolving threats and suspicious behaviors; reduce false positives and improve signal-to-noise. 
  • Micro-hunts and threat intelligence: Perform targeted hunts to discover emerging behaviors and translate findings into actionable detections, controls, and playbooks. 
  • Remediation and containment: Partner with IT and security stakeholders to drive containment, remediation, and recovery actions across endpoints, identities, and cloud services. 
  • Process and program maturity: Contribute to incident response process improvements, documentation standards, and after-action reviews; support development of tabletop exercise scenarios. 
  • Executive communication: Produce clear, concise updates for leadership (status, impact, risk, and next steps) and deliver required incident reports and post-incident summaries. 
  • Mentorship and SME support: Coach and mentor analysts in triage and investigation practices; serve as a subject matter expert across the incident response organization. 

  

Integrations, Automation, and AI-Driven Security Operations 

  • Build and maintain integrations between multiple enterprise security tools to improve automation, asset inventory accuracy, vulnerability identification, and response workflows. 
  • Implement AI-assisted monitoring and analytics to improve correlation, enrichment, prioritization, and triage of alerts; reduce manual effort and improve time to decision. 
  • Develop and maintain risk-scoring approaches for endpoints and users based on security posture, vulnerabilities, and behavioral signals. 
  • Produce trend analyses and operational health reporting (e.g., coverage, agent health, patch/compliance drift, and incident patterns) and translate results into improvement actions. 
  • Develop and maintain automation via APIs, scripting, and orchestration to support agent deployment/upgrade workflows, compliance checks and remediation, rapid scoping, containment support, targeted remediation, and continuous control validation. 

Technical Scope 

  • Use case management platforms, endpoint/network telemetry, and threat intelligence sources to investigate, document, and resolve incidents. 
  • Apply incident handling methodologies and attack frameworks (e.g., kill chain / MITRE ATT&CK-aligned thinking) to guide response and reporting. 
  • Perform in-depth analysis of threats, exploits, vulnerabilities, and malware families; validate hypotheses using host and network evidence. 
  • Conduct investigations across Windows, macOS, and Linux environments. 
  • Leverage Endpoint Detection and Response (EDR) tooling and cloud security telemetry to scope activity and support containment/remediation actions. 
  • Use Splunk and related analytics tooling to query, correlate, and operationalize security data for investigations and reporting. 
  • Demonstrate strong understanding of enterprise infrastructure and connectivity (e.g., VPN/partner connectivity) and common network protocols. 
  • Design, implement, and tune security detections in response to emerging threats and insider risk behaviors. 
  • Develop scripts and automation (e.g., Python, PowerShell, Bash) to enrich investigations and streamline operational workflows. 
  • Collaborate with partner analytic and engineering teams to align detections, telemetry, and response actions across the broader security ecosystem. 

  

Required Qualifications 

  • 5+ years of hands-on cybersecurity experience in incident response, security operations, insider risk, threat detection, or a closely related function. 
  • Demonstrated experience leading or handling escalated incidents, including triage, investigation, containment, remediation, and post-incident reporting in complex enterprise environments. 
  • Proficiency with security telemetry and investigation workflows across endpoint and network data sources; experience using SIEM analytics (e.g., Splunk) and EDR tooling. 
  • Working knowledge across multiple domains such as host analysis, network forensics, cloud environments, UEBA/anomaly detection, intrusion detection, threat research/intelligence, detection engineering, and data analysis. 
  • Ability to develop or maintain automation using scripting (e.g., Python, PowerShell, Bash) and/or APIs to improve security operations. 
  • Strong written and verbal communication skills, including the ability to produce executive-ready summaries and lead discussions with technical and non-technical stakeholders. 
  • Demonstrated integrity and discretion in handling sensitive investigations and confidential data. 

Preferred Qualifications 

  • Experience with Tanium (or comparable endpoint management/telemetry platforms) and building integrations across enterprise security tools. 
  • Experience implementing automation or orchestration in security operations (SOAR, APIs, pipelines, scripted workflows) to accelerate response and improve consistency. 
  • Experience applying AI-assisted analytics for alert enrichment, correlation/deduplication, prioritization, and operational reporting. 
  • Experience with insider risk programs, user/entity behavior analytics (UEBA), and behavior-based detection strategies. 
  • Experience investigating and responding to threats in cloud and SaaS environments. 
  • Experience mentoring analysts and contributing to training, playbooks, and tabletop exercise development. 
  • Relevant industry certifications (e.g., GCIA, GCIH, GCFA, CISSP, or equivalent) and/or a bachelor’s degree in a related field. 


Education/Experience: Bachelor’s degree (BS/BA) desired in Computer Science or Cybersecurity. 5+ years of related experience. Certification is required in some areas.

Supervisor:

No

Our Lead Cybersecurity jobs earn between $141,300.00 - $237,400.00 USD Annual. Not to mention all the other amazing rewards that working at AT&T offers. Individual starting salary within this range may depend on geography, experience, expertise, and education/training.

Joining our team comes with amazing perks and benefits:

  • Medical/Dental/Vision coverage
  • 401(k) plan
  • Tuition reimbursement program
  • Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)
  • Paid Parental Leave
  • Paid Caregiver Leave
  • Additional sick leave beyond what state and local law require may be available but is unprotected
  • Adoption Reimbursement
  • Disability Benefits (short term and long term)
  • Life and Accidental Death Insurance
  • Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
  • Employee Assistance Programs (EAP)
  • Extensive employee wellness programs
  • Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone

Weekly Hours:

40

Time Type:

Regular

Location:

Dallas, Texas, USA:NC:Charlotte / Ibm Dr - Adm:8505 Ibm Dr

Salary Range:

$141,300.00 - $237,400.00

AT&T and its subsidiaries are committed to equal employment opportunity. All hiring, promotion, and other employment decisions remain merit-based and free from discrimination on the basis of race, color, religion, religious creed, national origin, ancestry, age, sex, sexual orientation, gender, gender identity, gender expression, physical disability, mental disability, pregnancy, medical condition, genetic information, marital status, citizenship status, military status, veteran status, or any other characteristic protected by federal, state, or local laws. In addition, AT&T will provide reasonable accommodations to qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made. Click here to learn more or request an application accommodation here.

Bereit, sich bei AT&T zu bewerben?
Bei AT&T bewerben

Wie sich dieses Gehalt für Risk Analyst vergleicht

Diese Stelle zahlt $189,350/yrüber der üblichen Spanne für Risk Analyst Stellen.

$75,370 dem Median $127,500 $195,000

Übliche Spanne $95,500–$161,250/yr, aus 672 vergleichbaren Risk Analyst Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Risk Analyst ansehen →

Über AT&T

We are pioneers of making connections and have been ever since Alexander Graham Bell invented the telephone and founded our company. That was nearly 150 years ago, and we haven’t stopped innovating since. At our core, we help bring families, communities, and businesses together with the products and services they need to thrive every day. From the widespread and growing availability of 5G and Fiber to working on things we once only dreamed of—at AT&T, we create connections that change the world.

Alle Jobs bei AT&T ansehen →

Ähnliche Jobs

The Hartford
Senior Catastrophe Risk Modeling Analyst
The Hartford
⚡ Früh bewerben Coral Gables, FL Hybrid $109,040–$163,560
● Neu 👁 Gesehen ✓ Beworben vor 21 Min.
RSM
Risk Consulting Manager - Financial Services
RSM
⚡ Früh bewerben New York Vor Ort $101,000–$203,000
● Neu 👁 Gesehen ✓ Beworben vor 24 Min.
Deutsche Bank
Business Risk & Control Analyst
Deutsche Bank
⚡ Früh bewerben Mumbai Nirlon Know. Pk B7 Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 46 Min.
PwC
IN_Manager_Assistant Project Manager –Cyber & Digital Risk Managed ServicesAdvisory_Bangalore
PwC
⚡ Früh bewerben Bengaluru Millenia Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 50 Min.
HALA
Cybersecurity GRC Manager
HALA
⚡ Früh bewerben Riyadh, Riyadh, Saudi Arabia Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
ING
Portfolio Credit Risk Manager
ING
⚡ Früh bewerben Bruxelles Avenue Marnix (ING) Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
BT
Internal Audit & Risk Advisory Manager (SOX Focus)
Baker Tilly
⚡ Früh bewerben USA NY New York City 66 Hudson... Vor Ort $140,000–$212,780
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
Roblox
Senior Security GRC Analyst
Roblox
⚡ Früh bewerben San Mateo, CA, United States Vor Ort $209,250–$271,710
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
PNC
Technology Risk Advisor - Risk Quant
PNC
⚡ Früh bewerben PA - Pittsburgh (15222) Vor Ort $91,000–$202,800
● Neu 👁 Gesehen ✓ Beworben vor 4 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei AT&T

Alle Jobs bei AT&T ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos