Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
AT&T

Principal Cybersecurity – Incident Response Analyst

AT&T

. Lead cybersecurity investigations associated with escalated security incidents and suspicious activity .

Posted 9/18/2026full-timeCharlotte • North Carolina • United StatesLead💰 $155,400 - $233,200 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Cyber Incident Response, Threat Hunting, and Digital Forensics, with a strong focus on leading investigations and developing detection methodologies. Proficient in providing executive-level communications and mentoring within the cybersecurity domain.

Highest-signal resume keywords
Cyber Incident ResponseThreat HuntingDigital ForensicsSIEM TechnologiesCloud Security

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Malware Analysis FundamentalsVulnerability AssessmentIntrusion DetectionNetwork Protocol AnalysisScripting and Automation
Soft Skills
Executive-Level CommunicationMentoring
Tools & Technologies
SplunkAWSAzureEDR/XDRCloud Environments
Certifications & Qualifications
GCIHGCFAGCFEGPENCISSP
Industry Keywords
Threat Intelligence AnalysisSecurity OperationsIncident Lifecycle ManagementThreat Actor TacticsEnterprise Network Security

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityLinuxMacOSPythonSplunk

About the role

Key responsibilities & impact
  • Lead cybersecurity investigations associated with escalated security incidents and suspicious activity
  • Serve as Lead Investigator (Handler) for assigned escalated cybersecurity incidents
  • Coordinate and oversee investigative, containment, eradication, and recovery activities for major cybersecurity events
  • Conduct major and micro-hunt investigations to identify malicious activity, assess risk, and improve detection capabilities
  • Investigate threats, exploits, vulnerabilities, malware families, and advanced adversary activity across enterprise environments
  • Perform advanced host, network, log, cloud, and threat intelligence analysis
  • Produce technical reports, after-action reviews, executive summaries, and leadership briefings
  • Collaborate with Security Operations, Threat Intelligence, Digital Forensics, Malware Analysis, Engineering, Legal, Privacy, and other stakeholders
  • Support development and continuous improvement of incident response playbooks, processes, automation, and investigative methodologies
  • Design and facilitate tabletop exercises and cybersecurity incident simulations
  • Identify security control gaps and recommend improvements to organizational resilience
  • Mentor analysts and investigators across the Incident Response organization
  • Provide executive-level communications during significant cybersecurity events
  • Support investigations involving endpoint systems, cloud environments, identity platforms, network infrastructure, telecommunications systems, applications, and emerging technologies
  • Participate in an on-call rotation supporting critical cybersecurity events

Requirements

What you’ll need
  • Experience or working knowledge in several of the following areas: Cyber Incident Response; Threat Hunting; Digital Forensics; Threat Intelligence Analysis; Security Operations; SIEM Technologies (Splunk or equivalent); Endpoint Detection and Response (EDR/XDR); Cloud Security (AWS, Azure, and SaaS platforms); Host and Network Forensics; Malware Analysis Fundamentals; Vulnerability Assessment and Exploitation Techniques; Intrusion Detection and Anomaly Detection; Security Alert Design and Detection Engineering; Network Protocol Analysis; Windows, Linux, and macOS Investigations; Threat Actor Tactics, Techniques, and Procedures (TTPs); Scripting and Automation (Python, PowerShell, Bash, or similar); Telecommunications and Enterprise Network Security; Artificial Intelligence and AI-Assisted Security Analysis
  • 7+ years of experience in Incident Response, Security Operations, Threat Hunting, Digital Forensics, or related cybersecurity disciplines
  • Experience leading large-scale or high-impact cybersecurity investigations
  • Experience developing detection logic, investigative methodologies, and response processes
  • Experience supporting cloud-native and hybrid enterprise environments
  • Strong understanding of threat actor behavior, attack frameworks, and incident lifecycle management
  • Industry certifications such as GCIH, GCFA, GCFE, GPEN, GCIA, CISSP, GNFA, or equivalent
  • Bachelor’s degree (BS/BA) desired in Computer Science or Cybersecurity
  • Certification is required in some areas
  • Participation in an on-call rotation
  • Ability to provide executive-level communications during significant cybersecurity events

Benefits

Comp & perks
  • Medical/Dental/Vision coverage
  • 401(k) plan
  • Tuition reimbursement program
  • Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)
  • Paid Parental Leave
  • Paid Caregiver Leave
  • Additional sick leave beyond what state and local law require may be available but is unprotected
  • Adoption Reimbursement
  • Disability Benefits (short term and long term)
  • Life and Accidental Death Insurance
  • Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
  • Employee Assistance Programs (EAP)
  • Extensive employee wellness programs
  • Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone