Lead Cybersecurity - Insider Risk Analyst (Telemetry, Insider Risk Detection, and AI-Driven Security Operations)
$141.3k - $237.4kJobleads-US
This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered. Join AT&T and help shape the future of communications and technology that connect the world. We value innovators who seek to explore the unknown and challenge the status quo. Bring your bold ideas and fearless spirit to redefine connectivity and transform how people share stories and experiences. At AT&T, you won’t just imagine the future—you’ll build it.
The Lead Cybersecurity Insider Risk Analyst leads the response to high-priority and escalated cybersecurity incidents, with a focus on insider risk and telemetry-driven detection. This role oversees end-to-end incident handling—including detection, analysis, containment, eradication, recovery, reporting, and prevention—across employees, contractors, and third-party vendors. The position also drives continuous improvement through development of new detection logic, micro-hunts, and the integration of automation and AI-assisted analytics to increase detection fidelity and reduce manual effort. Success in this role requires advanced technical depth, strong operational rigor, and the ability to communicate clearly with both technical teams and executive stakeholders.
Key Roles and Responsibilities
- Incident leadership: Serve as lead handler for escalated insider risk and cyber incidents; establish investigation strategy, ensure timely execution, and drive incident closure.
- Advanced investigation and triage: Conduct deep-dive analysis of security events using telemetry, endpoint/network evidence, and threat intelligence to determine scope, impact, and root cause.
- Detection engineering and continuous improvement: Create, tune, and deploy new detection rules and analytics aligned to evolving threats and suspicious behaviors; reduce false positives and improve signal-to-noise.
- Micro-hunts and threat intelligence: Perform targeted hunts to discover emerging behaviors and translate findings into actionable detections, controls, and playbooks.
- Remediation and containment: Partner with IT and security stakeholders to drive containment, remediation, and recovery actions across endpoints, identities, and cloud services.
- Process and program maturity: Contribute to incident response process improvements, documentation standards, and after-action reviews; support development of tabletop exercise scenarios.
- Executive communication: Produce clear, concise updates for leadership (status, impact, risk, and next steps) and deliver required incident reports and post-incident summaries.
- Mentorship and SME support: Coach and mentor analysts in triage and investigation practices; serve as a subject matter expert across the incident response organization.
Integrations, Automation, and AI-Driven Security Operations
Build and maintain integrations between multiple enterprise security tools to improve automation, asset inventory accuracy, vulnerability identification, and response workflows. Implement AI-assisted monitoring and analytics to improve correlation, enrichment, prioritization, and triage of alerts; reduce manual effort and improve time to decision. Develop and maintain risk-scoring approaches for endpoints and users based on security posture, vulnerabilities, and behavioral signals. Produce trend analyses and operational health reporting (e.g., coverage, agent health, patch/compliance drift, and incident patterns) and translate results into improvement actions. Develop and maintain automation via APIs, scripting, and orchestration to support agent deployment/upgrade workflows, compliance checks and remediation, rapid scoping, containment support, targeted remediation, and continuous control validation.
Technical Scope
Use case management platforms, endpoint/network telemetry, and threat intelligence sources to investigate, document, and resolve incidents. Apply incident handling methodologies and attack frameworks (e.g., kill chain / MITRE ATT&CK-aligned thinking) to guide response and reporting. Perform in-depth analysis of threats, exploits, vulnerabilities, and malware families; validate hypotheses using host and network evidence. Conduct investigations across Windows, macOS, and Linux environments. Leverage Endpoint Detection and Response (EDR) tooling and cloud security telemetry to scope activity and support containment/remediation actions. Use Splunk and related analytics tooling to query, correlate, and operationalize security data for investigations and reporting. Demonstrate strong understanding of enterprise infrastructure and connectivity (e.g., VPN/partner connectivity) and common network protocols. Design, implement, and tune security detections in response to emerging threats and insider risk behaviors. Develop scripts and automation (e.g., Python, PowerShell, Bash) to enrich investigations and streamline operational workflows. Collaborate with partner analytic and engineering teams to align detections, telemetry, and response actions across the broader security ecosystem.
Required Qualifications
- 5+ years of hands-on cybersecurity experience in incident response, security operations, insider risk, threat detection, or a closely related function. Demonstrated experience leading or handling escalated incidents, including triage, investigation, containment, remediation, and post-incident reporting in complex enterprise environments.
- Proficiency with security telemetry and investigation workflows across endpoint and network data sources; experience using SIEM analytics (e.g., Splunk) and EDR tooling.
- Working knowledge across multiple domains such as host analysis, network forensics, cloud environments, UEBA/anomaly detection, intrusion detection, threat research/intelligence, detection engineering, and data analysis.
- Ability to develop or maintain automation using scripting (e.g., Python, PowerShell, Bash) and/or APIs to improve security operations.
- Strong written and verbal communication skills, including the ability to produce executive-ready summaries and lead discussions with technical and non-technical stakeholders.
- Demonstrated integrity and discretion in handling sensitive investigations and confidential data.
Preferred Qualifications
- Experience with Tanium (or comparable endpoint management/telemetry platforms) and building integrations across enterprise security tools.
- Experience implementing automation or orchestration in security operations (SOAR, APIs, pipelines, scripted workflows) to accelerate response and improve consistency.
- Experience applying AI-assisted analytics for alert enrichment, correlation/deduplication, prioritization, and operational reporting.
- Experience with insider risk programs, user/entity behavior analytics (UEBA), and behavior-based detection strategies.
- Experience investigating and responding to threats in cloud and SaaS environments.
- Experience mentoring analysts and contributing to training, playbooks, and tabletop exercise development.
- Relevant industry certifications (e.g., GCIA, GCIH, GCFA, CISSP, or equivalent) and/or a bachelor’s degree in a related field.
Education/Experience
Bachelor’s degree (BS/BA) desired in Computer Science or Cybersecurity. 5+ years of related experience. Certification is required in some areas.
Salary
Supervisor: No. Our Lead Cybersecurity jobs earn between $141,300.00 - $237,400.00 USD Annual. Not to mention all the other amazing rewards that working at AT&T offers. Individual starting salary within this range may depend on geography, experience, expertise, and education/training.
Perks and Benefits
- Medical/Dental/Vision coverage
- 401(k) plan
- Tuition reimbursement program
- Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)
- Paid Parental Leave
- Paid Caregiver Leave
- Additional sick leave beyond what state and local law require may be available but is unprotected
- Adoption Reimbursement
- Disability Benefits (short term and long term)
- Life and Accidental Death Insurance
- Supplemental benefit programs: critical illness/accident hospital indemnity/group legal Employee Assistance Programs (EAP)
- Extensive employee wellness programs
- Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone
Weekly Hours: 40
Time Type: Regular
Location: Dallas, Texas, USA:NC:Charlotte / Ibm Dr - Adm:8505 Ibm Dr
Salary Range: $141,300.00 - $237,400.00
AT&T and its subsidiaries are committed to equal employment opportunity. All hiring, promotion, and other employment decisions remain merit-based and free from discrimination on the basis of race, color, religion, religious creed, national origin, ancestry, age, sex, sexual orientation, gender, gender identity, gender expression, physical disability, mental disability, pregnancy, medical condition, genetic information, marital status, citizenship status, military status, veteran status, or any other characteristic protected by federal, state, or local laws. In addition, AT&T will provide reasonable accommodations to qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made.
We are pioneers of making connections and have been ever since Alexander Graham Bell invented the telephone and founded our company. That was nearly 150 years ago, and we haven’t stopped innovating since. At our core, we help bring families, communities, and businesses together with the products and services they need to thrive every day. From the widespread and growing availability of 5G and Fiber to working on things we once only dreamed of—at AT&T, we create connections that change the world.
#J-18808-Ljbffr Jobleads-US$128.4k - $192.6k
Senior Security Engineer - IS07FEWe... ...Threat Detection Engineer to... ...integrate cloud telemetry into Splunk... ...with Cloud Operations, Incident Response... ...analytics, risk-based... ...to support AI/SOAR automation... ...and L2 SOC analysts on: Cloud attack... ...5+ years of cybersecurity experience...OperationsFull timeTemporary workWork at office3 days per week$119k - $206k
...Fargo is seeking a Lead Systems... ...- Application Security to join the Security... ...platforms, and AI-enabled solutionsAssist... ...reviews, and risk assessments for... ...risks, and operational... ...architecture, risk, and cybersecurity teams to drive... ...regulated and risk-driven environmentInfluence...SuggestedFull timeWork experience placement$153k - $297k
...Our growth is driven by... ...Associate Director, AI Security Frontier Engineering... ..., from risk and gap... ...schedule while operating comfortably... ...of security telemetry, monitoring, and detection engineering... ...computer science, Cybersecurity, or a... ...independently leading technical initiatives...OperationsH1bLocal area- ...Performing Team Join the cybersecurity operations organization of a... ...monitoring, threat detection, incident response, and cyber-risk visibility capabilities... ...distributed team works across security, cloud, infrastructure... ...cloud and on-premises telemetry. This role will...OperationsRemote work
- ...description:The AI Security Engineer is... ...development, platform, cybersecurity, governance,... ..., and operationally ready.As a key... ...identifying security risks, design... ...validation results.Detection, Monitoring,... ...analysis of telemetry used to monitor... ...compliance, or audit-driven technology...OperationsFull timePart timeShift workDay shift
- ...The Cybersecurity Engineer is responsible for protecting... ...and management of security solutions. This... ...on cybersecurity operations, Azure cloud security, threat detection, incident response... ...adoption of AI technologies. Key... ...identify and mitigate risks. Conduct...Operations
- Our client, a leading organization in the cybersecurity and information security industry, is seeking... ...Security Analyst to join their... ...initiatives and operational improvements.... ...metrics, and risk indicators to... ...on automation, AI-enabled capabilities... ...on data-driven solutions. Chance...Weekly payTemporary workFlexible hours
- ...is putting AI agents to work... ...and run securely from day one... ...Security Engineer Lead owns the... ...builds and operates the controls... ...communicates risk and progress... ...Partner with Cybersecurity Architects and... ...gateway telemetry with Microsoft... ...monitoring, detection, and response...Full timeTemporary workShift workNight shiftWeekend workDay shift
- ...We AreAccenture Security helps... ...prepare, protect, detect, respond and recover... ...security lifecycle. Cybersecurity challenges are... ...security operations center, we will... ...within. We blend risk strategy, digital... ...ability to lead and manage business... ..., data and AI with unmatched...OperationsFull timeWork experience placementLive inWork at officeLocal areaRemote work
- ...seeking an Information Security Analyst to support and... ...posture across data- and AI-driven initiatives. This role... ...security questionnaires and risk assessments, and... ...security or cybersecurity; Cloud engineering, data... ...engineering, or platform operations with security exposure...OperationsInternship
- ...job description:Leads an IAM AuthN/... ...delivering AI-enabled automation... ..., technology-driven solutions that... ...productivity, operational effectiveness,... ...architecture, security, risk, and... ...engineers and analysts through solution... ...architecture, cybersecurity, risk, compliance...OperationsPermanent employmentFull timePart timeWork experience placementH1bWork visaShift workDay shift
- ...SecurityAccenture Security delivers... ...prepare, protect, detect, respond and recover... ...lifecycle. Cybersecurity challenges are... ...entire security operations center, we will... ...within. We blend risk strategy,... ...response etc.)Leads large/ complex... ...knowledge on usage of AI (demonstrate AI...OperationsFull timeWork experience placementLive inWork at officeLocal area
$60 - $70 per hour
...digital products operating across multiple... ...technology and cybersecurity teams support a... ...application security program continues... ..., and AI-assisted capabilities... ...What You’ll Do Lead application discovery... ...profiling, and risk tiering.... ...presentations, research, detection rules, or...OperationsHourly payLocal area3 days per week- ...banking, leasing, securities, credit cards,... .... The Group’s operating companies in... ...SUMMARY As an AI Security Engineer... ..., data, and risk teams to build... ...implementing logging, telemetry collection, threat detection, and security... ...experience in cybersecurity, security...OperationsWork at officeLocal areaWork from homeWorldwide
$114.1k - $268.18k
...collaborative, team-driven culture. At... ...facility, and leading market tools, we... ..., Cloud Security to join our Managed... ...reporting of security risks,... ...adoption of cloud and AI-enabled services... ...firewall security operations through Tufin... ...liaison between cybersecurity, engineering, infrastructure...OperationsH1bLocal area- ...AreAccenture Security helps... ..., protect, detect, respond, and... ...lifecycle. Cybersecurity challenges... ...entire security operations center, we... .... We blend risk strategy,... ...works embedded inside a client’s... ...—to make AI systems secure... ..., or GCP)Lead AI... ...hypothesis-driven problem decompositionTeam...OperationsFull timeWork experience placementLive inWork at officeLocal area
- The Lead Data Quality and Governance Analyst manages large projects and processes... ...reporting for operations and management to enable data driven decision making.... ...(e.g., risk tiering models,... ...Working knowledge of AI/ML lifecycle and... ...deserves a secure retirement. For...OperationsFull timeWork experience placementWork at office
- Position: Information Security Analyst 3 - Contingent Location: Charlotte... ...the onboarding and operation of the Securiti.ai data scanning platform within the Cybersecurity organization. This position... ...data owners to ensure accurate risk identification and remediation...OperationsContract work
- ...Information Security ConsultantLocation... ...enterprise insider threat... ...as a senior analyst. The role focuses... ...of insider-driven and employee... ...of high-risk activity.Key... ...security or cybersecurity investigations... ...or security operations or incident... ...source security telemetry into...Operations
- ...client seeks a Lead Scrum Master /... ...Agilist to support AI-enabled... ...Owners, Product Analysts, technical leads... ...Own the Agile operating rhythm for teams... ...track impediments, risks, and... ...coordinating with cybersecurity, architecture,... ...outcomes. We are driven by a purpose to...OperationsHourly payLocal area
$136.75k - $218.8k
...that belonging leads to better... ...opportunity to secure annual grants... ...as a Security Operations Engineer at Capital... ...partners with cybersecurity,... ...response, threat detection, security monitoring... ...cybersecurity risks. The role also... ...support data-driven decision making...OperationsFull timeTemporary workLocal areaFlexible hours$164.78k - $314.96k
...to achieve financial security through highly competitive... ...dedicated Bank Credit Risk Analyst Lead, you will have a... ...appetite. You will own operational and compliance risk inherent... ...and communicate data-driven credit strategy... ...experience utilizing AI and LLM-based tools (e...OperationsFull timeH1bWork at officeRemote workHome officeShift work- ...passionate about cloud security and leadership? Then... ...Manager, you will lead a high-performing... ...infrastructure.You’ll operate at the intersection of security risk, automation, and emerging AI-driven capabilities—driving... ...capabilities, and enhanced detective capabilitiesPartner...OperationsFull timeWork experience placementShift work
- ...automation, and AI. We built... ...technology, data, AI, cybersecurity, and... ...cloud, AI, and security expertise so clients... ...practitioner who leads the full functional... ...of finance operations, technology, and... ...Financials workstream risks and issues... ...of AI-driven Finance automation...OperationsFull timeWork experience placementLive inWork at officeLocal area
- ...industries. Our growth is driven by delivering real... ...Director, KDN Solution Lead - AI to join our KPMG... ...portfolioAccountable for operational and Financial KPIs set... ...management, AI governance, and risk management, including... ...business, product, security, and data leadership...OperationsH1bLocal area
$60k - $80k
...engineering, IST, IT, CIS, security, risk, cybersecurity, or a related technical or... ...strategies that help Vanguard operate at its best and protect... ...We are Vanguard, and we are driven by a long-term mission to improve... ...our cybersecurity-focused Analyst track, and the program is...Full timeInternshipSummer internship- ...group-approach to lead teams in the forefront of cybersecurity? Are you ready to put... ...our investors from risk requires clear... ...action. As part of the Analyst track, you'll play... ...you will: Drive security strategies for Vanguard... ...our mission-driven and highly collaborative...Full timeInternshipSummer internship
- ...currently seeking a Cyber Security Threat Analyst (Onsite Hybrid) to... ...to reduce risk.Track zero-day vulnerabilities... ...publish tactical, operational, and strategic... ...intelligence reports for cybersecurity teams, business... ...one of the world's leading AI and digital infrastructure...OperationsWork experience placementWork at officeRemote workFlexible hours
$91k - $202.8k
...a(n) Technology Risk Advisor within PNC... ...making through data-driven risk insights.The... ..., Information Security, Operational Risk, Audit, Compliance... ..., including:· Cybersecurity events· System... ...technology dependencies· AI and emerging... ...measures, and leading indicators that improve...Full timeTemporary workPart timeWork experience placementWork at office- ...seeking an Information Security Manager to join our Cybersecurity Technology group.... ...security risk, providing identity... ...security engineering, and operating the Cybersecurity function... ...be responsible for leading IAM operational... ...and compliance-driven culture which firmly...OperationsFull timeWork experience placementWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Cybersecurity - Insider Risk Analyst (Telemetry, Insider Risk Detection, and AI-Driven Security Operations). Be the first to apply!
- it risk analyst Charlotte, NC
- risk consultant Charlotte, NC
- risk analyst Charlotte, NC
- risk officer Charlotte, NC
- operational risk specialist Charlotte, NC
- operational risk consultant Charlotte, NC
- senior quantitative risk analyst Charlotte, NC
- at risk youth Charlotte, NC
- risk intern Charlotte, NC
- technology risk Charlotte, NC




