Turn this role into an interview — a resume and cover letter built around what this employer wants.
AT&T is seeking a Lead Cybersecurity Insider Risk Analyst to lead responses to insider risk and high-priority cybersecurity incidents. The role focuses on telemetry-driven detection, automation, and AI-assisted analytics to improve detection fidelity while reducing manual effort.
The position requires coordinating end-to-end incident handling across employees, contractors, and vendors, with strong communication to executives and stakeholders. Location-based on-site presence in Dallas/Charlotte.
This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered. Join AT&T and help shape the future of communications and technology that connect the world. We value innovators who seek to explore the unknown and challenge the status quo. Bring your bold ideas and fearless spirit to redefine connectivity and transform how people share stories and experiences. At AT&T, you won’t just imagine the future—you’ll build it.
The Lead Cybersecurity Insider Risk Analyst leads the response to high-priority and escalated cybersecurity incidents, with a focus on insider risk and telemetry-driven detection. This role oversees end-to-end incident handling—including detection, analysis, containment, eradication, recovery, reporting, and prevention—across employees, contractors, and third-party vendors. The position also drives continuous improvement through development of new detection logic, micro-hunts, and the integration of automation and AI-assisted analytics to increase detection fidelity and reduce manual effort. Success in this role requires advanced technical depth, strong operational rigor, and the ability to communicate clearly with both technical teams and executive stakeholders.
Build and maintain integrations between multiple enterprise security tools to improve automation, asset inventory accuracy, vulnerability identification, and response workflows. Implement AI-assisted monitoring and analytics to improve correlation, enrichment, prioritization, and triage of alerts; reduce manual effort and improve time to decision. Develop and maintain risk-scoring approaches for endpoints and users based on security posture, vulnerabilities, and behavioral signals. Produce trend analyses and operational health reporting (e.g., coverage, agent health, patch/compliance drift, and incident patterns) and translate results into improvement actions. Develop and maintain automation via APIs, scripting, and orchestration to support agent deployment/upgrade workflows, compliance checks and remediation, rapid scoping, containment support, targeted remediation, and continuous control validation.
Use case management platforms, endpoint/network telemetry, and threat intelligence sources to investigate, document, and resolve incidents. Apply incident handling methodologies and attack frameworks (e.g., kill chain / MITRE ATT&CK-aligned thinking) to guide response and reporting. Perform in-depth analysis of threats, exploits, vulnerabilities, and malware families; validate hypotheses using host and network evidence. Conduct investigations across Windows, macOS, and Linux environments. Leverage Endpoint Detection and Response (EDR) tooling and cloud security telemetry to scope activity and support containment/remediation actions. Use Splunk and related analytics tooling to query, correlate, and operationalize security data for investigations and reporting. Demonstrate strong understanding of enterprise infrastructure and connectivity (e.g., VPN/partner connectivity) and common network protocols. Design, implement, and tune security detections in response to emerging threats and insider risk behaviors. Develop scripts and automation (e.g., Python, PowerShell, Bash) to enrich investigations and streamline operational workflows. Collaborate with partner analytic and engineering teams to align detections, telemetry, and response actions across the broader security ecosystem.
Bachelor’s degree (BS/BA) desired in Computer Science or Cybersecurity. 5+ years of related experience. Certification is required in some areas.
Supervisor: No. Our Lead Cybersecurity jobs earn between $141,300.00 - $237,400.00 USD Annual. Not to mention all the other amazing rewards that working at AT&T offers. Individual starting salary within this range may depend on geography, experience, expertise, and education/training.
Weekly Hours: 40
Time Type: Regular
Location: Dallas, Texas, USA:NC:Charlotte / Ibm Dr - Adm:8505 Ibm Dr
Salary Range: $141,300.00 - $237,400.00
AT&T and its subsidiaries are committed to equal employment opportunity. All hiring, promotion, and other employment decisions remain merit-based and free from discrimination on the basis of race, color, religion, religious creed, national origin, ancestry, age, sex, sexual orientation, gender, gender identity, gender expression, physical disability, mental disability, pregnancy, medical condition, genetic information, marital status, citizenship status, military status, veteran status, or any other characteristic protected by federal, state, or local laws. In addition, AT&T will provide reasonable accommodations to qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made.
We are pioneers of making connections and have been ever since Alexander Graham Bell invented the telephone and founded our company. That was nearly 150 years ago, and we haven’t stopped innovating since. At our core, we help bring families, communities, and businesses together with the products and services they need to thrive every day. From the widespread and growing availability of 5G and Fiber to working on things we once only dreamed of—at AT&T, we create connections that change the world.