Senior Cybersecurity - Digital Forensic Investigator

AT&T

Charlotte (NC)

On-site

USD 128,000 - 193,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement
Paid Time Off and Holidays
Paid Parental Leave
Adoption Reimbursement
Life and AD&D Insurance
Employee Discounts

Job summary

AT&T is seeking a Senior Cybersecurity Digital Forensic Investigator to lead investigations across the enterprise. You will analyze evidence, reconstruct timelines, determine scope and impact, and communicate findings to technical and non-technical audiences.

The role supports endpoint, cloud, identity, and network investigations and participates in on-call rotations. A strong foundation in threat culture and AI-assisted analysis is beneficial.

Qualifications

  • Bachelor’s degree in Computer Science or Cybersecurity required.
  • Minimum 3 years of experience in Digital Forensics, Incident Response, or related cybersecurity disciplines.
  • Ability to communicate findings to both technical and non-technical audiences.

Responsibilities

  • Conduct digital forensic investigations associated with cybersecurity incidents and suspicious activity.
  • Collect, preserve, process, and analyze digital evidence while maintaining chain of custody.
  • Perform endpoint, memory, log, cloud, network, and live-response forensic analysis.
  • Determine attack scope, affected assets, root cause, and extent of compromise.
  • Reconstruct timelines using forensic artifacts, telemetry, and logs.
  • Produce detailed technical reports and executive summaries documenting findings.

Skills

Digital Forensics
Incident Response
Threat Intelligence
Malware Analysis Fundamentals
Cloud Forensics
Scripting/Automation
Generative AI in security

Education

Bachelor's degree in Computer Science or Cybersecurity

Tools

SIEM Platforms
EDR Platforms
Public Cloud (AWS/Azure)
Python scripting

Job description

Position Summary

The Senior Cybersecurity Digital Forensic Investigator is responsible for conducting digital forensic investigations in support of cybersecurity incidents across AT&T's enterprise environment. This role partners closely with Incident Response, Threat Intelligence, Malware Analysis, Engineering, and platform teams to determine what occurred, how it occurred, what systems were impacted, and what actions are required to reduce future risk.

The investigator is responsible for analyzing digital evidence, reconstructing timelines, determining scope and impact, identifying attack vectors, and producing technically accurate and defensible reports. This position requires independent investigative work, strong technical analysis skills, and the ability to communicate findings to both technical and non-technical audiences.

This role participates in an on-call rotation and supports investigations involving endpoint systems, cloud environments, identity platforms, network infrastructure, applications, and enterprise telecommunications systems. The position requires a strong foundation in digital forensics and a working understanding of modern threat actor tradecraft, incident response, cloud technologies, and artificial intelligence.

Key Responsibilities
  • Conduct digital forensic investigations associated with cybersecurity incidents and suspicious activity.
  • Collect, preserve, process, and analyze digital evidence while maintaining evidentiary integrity and chain of custody.
  • Perform endpoint, memory, log, cloud, network, and live-response forensic analysis.
  • Determine attack scope, affected assets, root cause, and extent of compromise.
  • Reconstruct investigative timelines using forensic artifacts, telemetry, and log sources.
  • Produce detailed technical reports and executive-level summaries documenting investigative findings.
  • Collaborate with Incident Response, Threat Intelligence, Malware Analysis, platform teams, Legal, and other stakeholders during investigations.
  • Support investigations involving on-premises, cloud, and hybrid environments.
  • Utilize forensic findings to identify security control gaps and recommend improvements.
  • Assist with the development and improvement of forensic processes, methodologies, automation, and tooling.
  • Participate in an on-call rotation supporting time-sensitive investigations.
  • Remain current on emerging threats, attack techniques, forensic methodologies, and investigative technologies.
  • Evaluate and utilize emerging technologies, including artificial intelligence, to improve investigative efficiency and analytical effectiveness while understanding associated risks and limitations.
  • Minimum 3 years of experience in Digital Forensics, Incident Response, Cyber Threat Hunting, Security Operations, or a related cybersecurity discipline.
  • Experience conducting investigations involving Windows, Linux, macOS, cloud platforms, or enterprise network environments.
  • Experience analyzing forensic artifacts, logs, endpoint telemetry, and other investigative data sources.
  • Experience documenting findings and preparing technical reports.
Required Technical Knowledge

Experience or working knowledge in several of the following areas:

  • Digital Forensics
  • Live Response
  • Memory Forensics
  • Endpoint Investigations
  • Cloud Forensics
  • Incident Response
  • Threat Intelligence
  • Malware Analysis Fundamentals
  • Log Analysis
  • Network Security and Protocols
  • SIEM Platforms
  • EDR Platforms
  • Windows, Linux, and macOS
  • Public Cloud Platforms (AWS and Azure)
  • Scripting and Automation (Python, PowerShell, Bash, or similar)
  • Identity and Access Management
  • Web Applications and APIs
  • Security Vulnerabilities and Attack Techniques
  • Generative AI technologies, AI-assisted analysis techniques, and security considerations associated with AI systems. Applicants should be comfortable leveraging AI as a productivity and analytical tool while maintaining human validation of investigative conclusions.
Preferred Qualifications
  • Industry certifications such as GCFA, GCFE, GCIH, GNFA, GCIA, CISSP, EnCE, CFCE, or equivalent.
  • Experience supporting large-scale enterprise investigations.
  • Experience with cloud-native security investigations.
  • Experience supporting investigations involving telecommunications, network infrastructure, or large distributed environments.
What Candidates Should Expect

This is an investigation-focused role. Successful candidates should expect:

  • Writing detailed investigative reports.
  • Leading investigations from evidence collection through final reporting.
  • Working directly with engineers, security teams, and business stakeholders.
  • Participating in an on-call rotation.
  • Handling multiple investigations with competing priorities.
  • Operating with a high degree of independence and accountability.
  • Supporting investigations that may require rapid response and extended collaboration during significant cybersecurity events.
Job Contribution

An experienced professional with advanced, interdisciplinary knowledge, resolving difficult and complex issues using broad professional concepts. Guides others, applying advanced principles and company practices. Leads moderate sized projects (or parts of larger projects) with strategic value. Operates autonomously with frequent senior leadership interaction.

Supervisor

No

TCP Career Step Differentiator

Manages complex cybersecurity work.

Education/Experience

Bachelor’s degree (BS/BA) desired in Computer Science or Cybersecurity. 3+ years of related experience. Certification is required in some areas.

Our Senior Cybersecurity jobs earn between $128,400.00 - $192,600.00 USD Annual. Not to mention all the other amazing rewards that working at AT&T offers. Individual starting salary within this range may depend on geography, experience, expertise, and education/training.

Joining our team comes with amazing perks and benefits
  • Medical/Dental/Vision coverage
  • 401(k) plan
  • Tuition reimbursement program
  • Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)
  • Paid Parental Leave
  • Paid Caregiver Leave
  • Additional sick leave beyond what state and local law require may be available but is unprotected
  • Adoption Reimbursement
  • Disability Benefits (short term and long term)
  • Life and Accidental Death Insurance
  • Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
  • Employee Assistance Programs (EAP)
  • Extensive employee wellness programs
  • Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone
Weekly Hours

40

Time Type

Regular

Location

USA:NC:Charlotte / Ibm Dr - Adm:8505 Ibm Dr

Salary Range

$128,400.00 - $192,600.00

AT&T and its subsidiaries are committed to equal employment opportunity. All hiring, promotion, and other employment decisions remain merit-based and free from discrimination on the basis of race, color, religion, religious creed, national origin, ancestry, age, sex, sexual orientation, gender, gender identity, gender expression, physical disability, mental disability, pregnancy, medical condition, genetic information, marital status, citizenship status, military status, veteran status, or any other characteristic protected by federal, state, or local laws. In addition, AT&T will provide reasonable accommodations to qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Cybersecurity - Incident Response Analyst
Principal Cybersecurity - Incident Response Analyst

AT&T • Charlotte (NC)

On-site
USD 155,000 - 233,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement program
+5
Lead Cybersecurity
Lead Cybersecurity

AT&T • Plano (TX)

On-site
USD 187,000 - 237,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement program
+7
Principal Cybersecurity - Network Security
Principal Cybersecurity - Network Security

AT&T • Charlotte (NC)

On-site
USD 155,000 - 261,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement program
+1
Principal Cybersecurity - Network Security
Principal Cybersecurity - Network Security

AT&T • Dallas (TX)

Hybrid
USD 155,000 - 261,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement program
+9
Principal Cybersecurity - Network Security
Principal Cybersecurity - Network Security

AT&T • Town of Charlotte (NY)

On-site
USD 155,000 - 261,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement
+10
Lead Cybersecurity - Application Security DevSecOps Engineer
Lead Cybersecurity - Application Security DevSecOps Engineer

AT&T • Dallas (TX)

On-site
USD 128,000 - 216,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement program
+2
Risk Response Activation & Assurance Lead
Risk Response Activation & Assurance Lead

AT&T • Town of Charlotte (NY)

On-site
USD 155,000 - 233,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement
+8
Lead Cybersecurity - SOC Team Lead
Lead Cybersecurity - SOC Team Lead

AT&T • Middletown (NJ)

On-site
USD 141,000 - 212,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement program
+3
Senior IT Auditor
Senior IT Auditor

AT&T • Dallas (TX)

On-site
USD 119,000 - 178,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement
Security Lead (Government)
Security Lead (Government)

AT&T • Town of Florida (NY)

Remote
USD 128,000 - 275,000
Medical/Dental/Vision coverage
401(k) plan
Tuition reimbursement
+7