FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Lead Cybersecurity – Insider Risk Analyst, Telemetry, Insider Risk Detection, AI-Driven Security Operations
AT&T. Lead response to high-priority and escalated cybersecurity incidents focused on insider risk and telemetry-driven detection .
Posted 9/18/2026full-timeCharlotte • North Carolina • United StatesSenior💰 $141,300 - $237,400 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in incident response and cybersecurity operations, with a strong focus on insider risk, threat detection, and automation. Proficient in utilizing security telemetry, analytics tools, and investigation methodologies to drive effective incident management and reporting.
Highest-signal resume keywords
Incident ResponseThreat DetectionSecurity TelemetryAutomation DevelopmentSplunk Analytics
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
CybersecurityIncident HandlingThreat IntelligenceData AnalysisEndpoint ForensicsNetwork ForensicsDetection EngineeringAutomation ScriptingCloud SecurityVulnerability Analysis
Soft Skills
Communication SkillsMentoringIntegrityDiscretionCollaboration
Tools & Technologies
SplunkEDR ToolsSIEM AnalyticsTaniumAPIsAI-Assisted AnalyticsCloud ServicesCase Management PlatformsScripting LanguagesOrchestration Tools
Certifications & Qualifications
GCIAGCIHGCFACISSPBachelor's Degree in Computer ScienceBachelor's Degree in Cybersecurity
Industry Keywords
Insider RiskTelemetry-Driven DetectionIncident ClosureOperational ReportingPost-Incident ReportingUEBABehavior-Based DetectionCloud Threat InvestigationComplex Enterprise EnvironmentsTabletop Exercises
Tech Stack
Tools & technologiesCloudCyber SecurityLinuxMacOSPythonSplunk
About the role
Key responsibilities & impact- Lead response to high-priority and escalated cybersecurity incidents focused on insider risk and telemetry-driven detection
- Establish investigation strategy, ensure timely execution, and drive incident closure
- Conduct deep-dive analysis using telemetry, endpoint/network evidence, and threat intelligence to determine scope, impact, and root cause
- Create, tune, and deploy detection rules and analytics for evolving threats and suspicious behaviors
- Perform targeted micro-hunts and translate findings into detections, controls, and playbooks
- Partner with IT and security stakeholders on containment, remediation, and recovery across endpoints, identities, and cloud services
- Contribute to incident response process improvements, documentation standards, after-action reviews, and tabletop scenarios
- Produce leadership updates and incident reports covering status, impact, risk, and next steps
- Coach and mentor analysts and serve as a subject matter expert
- Build and maintain integrations among enterprise security tools
- Implement AI-assisted monitoring and analytics for correlation, enrichment, prioritization, and alert triage
- Develop and maintain risk-scoring approaches for endpoints and users
- Produce trend analyses and operational health reporting
- Develop automation through APIs, scripting, and orchestration for deployments, compliance checks, remediation, scoping, containment, and control validation
- Investigate and resolve incidents using case management platforms, endpoint/network telemetry, and threat intelligence
- Apply incident handling methodologies and frameworks such as kill chain and MITRE ATT&CK
- Analyze threats, exploits, vulnerabilities, and malware across Windows, macOS, and Linux
- Use EDR and cloud security telemetry to scope activity and support containment/remediation
- Use Splunk and related analytics tools to query and correlate security data
- Design and tune detections for emerging threats and insider risk behaviors
- Collaborate with analytics and engineering teams across the security ecosystem
Requirements
What you’ll need- 5+ years of hands-on cybersecurity experience in incident response, security operations, insider risk, threat detection, or a closely related function
- Experience leading or handling escalated incidents, including triage, investigation, containment, remediation, and post-incident reporting in complex enterprise environments
- Proficiency with security telemetry and investigation workflows across endpoint and network data sources
- Experience using SIEM analytics such as Splunk and EDR tooling
- Working knowledge of host analysis, network forensics, cloud environments, UEBA/anomaly detection, intrusion detection, threat research/intelligence, detection engineering, and data analysis
- Ability to develop or maintain automation using Python, PowerShell, Bash, and/or APIs
- Strong written and verbal communication skills, including executive-ready summaries and stakeholder discussions
- Integrity and discretion in handling sensitive investigations and confidential data
- Preferred: Tanium or comparable endpoint management/telemetry platforms
- Preferred: SOAR, APIs, pipelines, and scripted workflows
- Preferred: AI-assisted analytics for alert enrichment, correlation/deduplication, prioritization, and operational reporting
- Preferred: Insider risk programs, UEBA, and behavior-based detection strategies
- Preferred: Cloud and SaaS threat investigation and response
- Preferred: Mentoring analysts and contributing to training, playbooks, and tabletop exercises
- Preferred: Relevant certifications such as GCIA, GCIH, GCFA, CISSP, or equivalent and/or a bachelor’s degree in a related field
- Bachelor’s degree in Computer Science or Cybersecurity desired
- Certification is required in some areas
- Availability for office presence a minimum of 5 days per week
- No relocation offered
Benefits
Comp & perks- Medical/Dental/Vision coverage
- 401(k) plan
- Tuition reimbursement program
- Paid Time Off and Holidays (at least 23 days of vacation each year and 9 company-designated holidays)
- Paid Parental Leave
- Paid Caregiver Leave
- Additional sick leave beyond what state and local law require may be available but is unprotected
- Adoption Reimbursement
- Disability Benefits (short term and long term)
- Life and Accidental Death Insurance
- Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
- Employee Assistance Programs (EAP)
- Extensive employee wellness programs
- Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone