yoinka

Lead Cybersecurity – Insider Risk Analyst (Telemetry, Insider Risk Detection, and AI-Driven Security Operations)

AT&T

USANCCharlotte Ibm Dr Adm8505 Ibm DrSenior
Sign in to applyVerified 2h ago
Location
USANCCharlotte Ibm Dr Adm8505 Ibm Dr
Work model
On-Site
Level
Senior
Posted
Aug 26, 2026

Skills

Cybersecurity

About this role

This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered. Join AT&T and help shape the future of communications and technology that connect the world. We value innovators who seek to explore the unknown and challenge the status quo. Bring your bold ideas and fearless spirit to redefine connectivity and transform how people share stories and experiences. At AT&T, you won’t just imagine the future—you’ll build it. The Lead Cybersecurity Insider Risk Analyst leads the response to high-priority and escalated cybersecurity incidents, with a focus on insider risk and telemetry-driven detection. This role oversees end-to-end incident handling—including detection, analysis, containment, eradication, recovery, reporting, and prevention—across employees, contractors, and third-party vendors. The position also drives continuous improvement through development of new detection logic, micro-hunts, and the integration of automation and AI-assisted analytics to increase detection fidelity and reduce manual effort. Success in this role requires advanced technical depth, strong operational rigor, and the ability to communicate clearly with both technical teams and executive stakeholders.  Key Roles and Responsibilities  Incident leadership:  Serve as lead handler for escalated insider risk and cyber incidents; establish investigation strategy, ensure timely execution, and drive incident closure.  Advanced investigation and triage:  Conduct deep-dive analysis of security events using telemetry, endpoint/network evidence, and threat intelligence to determine scope, impact, and root cause.  Detection engineering and continuous improvement:  Create, tune, and deploy new detection rules and analytics aligned to evolving threats and suspicious behaviors; reduce false positives and improve signal-to-noise.  Micro-hunts and threat intelligence:  Perform targeted hunts to discover emerging behaviors and translate findings into actionable detections, controls, and playbooks.  Remediation and containment:  Partner with IT and security stakeholders to drive containment, remediation, and recovery actions across endpoints, identities, and cloud services.  Process and program maturity:  Contribute to incident response process improvements, documentation standards, and after-action reviews; support development of tabletop exercise scenarios.  Executive communication:  Produce clear, concise updates for leadership (status, impact, risk, and next steps) and deliver required incident reports and post-incident summaries.  Mentorship and SME support:  Coach and mentor analysts in triage and investigation practices; serve as a subject matter expert across the incident response organization.     Integrations, Automation, and AI-Driven Security Operations  Build and maintain integrations between multiple enterprise security tools to improve automation, asset inventory accuracy, vulnerability identification, and response workflows.  Implement AI-assisted monitoring and analytics to improve correlation, enrichment, prioritization, and triage of alerts; reduce manual effort and improve time to decision.  Develop and maintain risk-scoring approaches for endpoints and users based on security posture, vulnerabilities, and behavioral signals.  Produce trend analyses and operational health reporting (e.g., coverage, agent health, patch/compliance drift, and incident patterns) and translate results into improvement actions.  Develop and maintain automation via APIs, scripting, and orchestration to support agent deployment/upgrade workflows, compliance checks and remediation, rapid scoping, containment support, targeted remediation, and continuous control validation.  Technical Scope  Use case management platforms, endpoint/network telemetry, and threat intelligence sources to investigate, document, and resolve incidents.  Apply incident

Listing verified 2h ago. Applications go through the company's official careers site.

← Back to Yoinka

Lead Cybersecurity – Insider Risk Analyst (Telemetry, Insider Risk Detection, and AI-Driven Security Operations) at AT&T, USANCCharlotte Ibm Dr Adm8505 Ibm Dr | Yoinka