Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
AT&T

Lead Cybersecurity – Insider Risk Analyst, Telemetry, Insider Risk Detection, AI-Driven Security Operations

AT&T

. Lead response to high-priority and escalated cybersecurity incidents focused on insider risk and telemetry-driven detection .

Posted 9/18/2026full-timeCharlotte • North Carolina • United StatesSenior💰 $141,300 - $237,400 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in incident response and cybersecurity operations, with a strong focus on insider risk, threat detection, and automation. Proficient in utilizing security telemetry, analytics tools, and investigation methodologies to drive effective incident management and reporting.

Highest-signal resume keywords
Incident ResponseThreat DetectionSecurity TelemetryAutomation DevelopmentSplunk Analytics

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
CybersecurityIncident HandlingThreat IntelligenceData AnalysisEndpoint ForensicsNetwork ForensicsDetection EngineeringAutomation ScriptingCloud SecurityVulnerability Analysis
Soft Skills
Communication SkillsMentoringIntegrityDiscretionCollaboration
Tools & Technologies
SplunkEDR ToolsSIEM AnalyticsTaniumAPIsAI-Assisted AnalyticsCloud ServicesCase Management PlatformsScripting LanguagesOrchestration Tools
Certifications & Qualifications
GCIAGCIHGCFACISSPBachelor's Degree in Computer ScienceBachelor's Degree in Cybersecurity
Industry Keywords
Insider RiskTelemetry-Driven DetectionIncident ClosureOperational ReportingPost-Incident ReportingUEBABehavior-Based DetectionCloud Threat InvestigationComplex Enterprise EnvironmentsTabletop Exercises

Tech Stack

Tools & technologies
CloudCyber SecurityLinuxMacOSPythonSplunk

About the role

Key responsibilities & impact
  • Lead response to high-priority and escalated cybersecurity incidents focused on insider risk and telemetry-driven detection
  • Establish investigation strategy, ensure timely execution, and drive incident closure
  • Conduct deep-dive analysis using telemetry, endpoint/network evidence, and threat intelligence to determine scope, impact, and root cause
  • Create, tune, and deploy detection rules and analytics for evolving threats and suspicious behaviors
  • Perform targeted micro-hunts and translate findings into detections, controls, and playbooks
  • Partner with IT and security stakeholders on containment, remediation, and recovery across endpoints, identities, and cloud services
  • Contribute to incident response process improvements, documentation standards, after-action reviews, and tabletop scenarios
  • Produce leadership updates and incident reports covering status, impact, risk, and next steps
  • Coach and mentor analysts and serve as a subject matter expert
  • Build and maintain integrations among enterprise security tools
  • Implement AI-assisted monitoring and analytics for correlation, enrichment, prioritization, and alert triage
  • Develop and maintain risk-scoring approaches for endpoints and users
  • Produce trend analyses and operational health reporting
  • Develop automation through APIs, scripting, and orchestration for deployments, compliance checks, remediation, scoping, containment, and control validation
  • Investigate and resolve incidents using case management platforms, endpoint/network telemetry, and threat intelligence
  • Apply incident handling methodologies and frameworks such as kill chain and MITRE ATT&CK
  • Analyze threats, exploits, vulnerabilities, and malware across Windows, macOS, and Linux
  • Use EDR and cloud security telemetry to scope activity and support containment/remediation
  • Use Splunk and related analytics tools to query and correlate security data
  • Design and tune detections for emerging threats and insider risk behaviors
  • Collaborate with analytics and engineering teams across the security ecosystem

Requirements

What you’ll need
  • 5+ years of hands-on cybersecurity experience in incident response, security operations, insider risk, threat detection, or a closely related function
  • Experience leading or handling escalated incidents, including triage, investigation, containment, remediation, and post-incident reporting in complex enterprise environments
  • Proficiency with security telemetry and investigation workflows across endpoint and network data sources
  • Experience using SIEM analytics such as Splunk and EDR tooling
  • Working knowledge of host analysis, network forensics, cloud environments, UEBA/anomaly detection, intrusion detection, threat research/intelligence, detection engineering, and data analysis
  • Ability to develop or maintain automation using Python, PowerShell, Bash, and/or APIs
  • Strong written and verbal communication skills, including executive-ready summaries and stakeholder discussions
  • Integrity and discretion in handling sensitive investigations and confidential data
  • Preferred: Tanium or comparable endpoint management/telemetry platforms
  • Preferred: SOAR, APIs, pipelines, and scripted workflows
  • Preferred: AI-assisted analytics for alert enrichment, correlation/deduplication, prioritization, and operational reporting
  • Preferred: Insider risk programs, UEBA, and behavior-based detection strategies
  • Preferred: Cloud and SaaS threat investigation and response
  • Preferred: Mentoring analysts and contributing to training, playbooks, and tabletop exercises
  • Preferred: Relevant certifications such as GCIA, GCIH, GCFA, CISSP, or equivalent and/or a bachelor’s degree in a related field
  • Bachelor’s degree in Computer Science or Cybersecurity desired
  • Certification is required in some areas
  • Availability for office presence a minimum of 5 days per week
  • No relocation offered

Benefits

Comp & perks
  • Medical/Dental/Vision coverage
  • 401(k) plan
  • Tuition reimbursement program
  • Paid Time Off and Holidays (at least 23 days of vacation each year and 9 company-designated holidays)
  • Paid Parental Leave
  • Paid Caregiver Leave
  • Additional sick leave beyond what state and local law require may be available but is unprotected
  • Adoption Reimbursement
  • Disability Benefits (short term and long term)
  • Life and Accidental Death Insurance
  • Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
  • Employee Assistance Programs (EAP)
  • Extensive employee wellness programs
  • Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone