ForgeApply · Job listing
Lead Cybersecurity – Insider Risk Analyst (Telemetry, Insider Risk Detection, and AI-Driven Security Operations)
AT&T
See all 109 open roles at AT&T →
Tailor your resume for this AT&T job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for AT&T's site. Free trial, no card required.
About this role
This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.
Join AT&T and help shape the future of communications and technology that connect the world. We value innovators who seek to explore the unknown and challenge the status quo. Bring your bold ideas and fearless spirit to redefine connectivity and transform how people share stories and experiences. At AT&T, you won’t just imagine the future—you’ll build it.
The Lead Cybersecurity Insider Risk Analyst leads the response to high-priority and escalated cybersecurity incidents, with a focus on insider risk and telemetry-driven detection. This role oversees end-to-end incident handling—including detection, analysis, containment, eradication, recovery, reporting, and prevention—across employees, contractors, and third-party vendors. The position also drives continuous improvement through development of new detection logic, micro-hunts, and the integration of automation and AI-assisted analytics to increase detection fidelity and reduce manual effort. Success in this role requires advanced technical depth, strong operational rigor, and the ability to communicate clearly with both technical teams and executive stakeholders.
Key Roles and Responsibilities • Incident leadership: Serve as lead handler for escalated insider risk and cyber incidents; establish investigation strategy, ensure timely execution, and drive incident closure.
• Advanced investigation and triage: Conduct deep-dive analysis of security events using telemetry, endpoint/network evidence, and threat intelligence to determine scope, impact, and root cause.
• Detection engineering and continuous improvement: Create, tune, and deploy new detection rules and analytics aligned to evolving threats and suspicious behaviors; reduce false positives and improve signal-to-noise.
• Micro-hunts and threat intelligence: Perform targeted hunts to discover emerging behaviors and translate findings into actionable detections, controls, and playbooks.
• Remediation and containment: Partner with IT and security stakeholders to drive containment, remediation, and recovery actions across endpoints, identities, and cloud services.
• Process and program maturity: Contribute to incident response process improvements, documentation standards, and after-action reviews; support development of tabletop exercise scenarios.
• Executive communication: Produce clear, concise updates for leadership (status, impact, risk, and next steps) and deliver required incident reports and post-incident summaries.
• Mentorship and SME support: Coach and mentor analysts in triage and investigation practices; serve as a subject matter expert across the incident response organization.
Integrations, Automation, and AI-Driven Security Operations • Build and maintain integrations between multiple enterprise security tools to improve automation, asset inventory accuracy, vulnerability identification, and response workflows.
• Implement AI-assisted monitoring and analytics to improve correlation, enrichment, prioritization, and triage of alerts; reduce manual effort and improve time to decision.
• Develop and maintain risk-scoring approaches for endpoints and users based on security posture, vulnerabilities, and behavioral signals.
• Produce trend analyses and operational health reporting (e.g., coverage, agent health, patch/compliance drift, and incident patterns) and translate results into improvement actions.
• Develop and maintain automation via APIs, scripting, and orchestration to support agent deployment/upgrade workflows, compliance checks and remediation, rapid scoping, containment support, targeted remediation, and continuous control validation.
Technical Scope • Use case management platforms, endpoint/network telemetry, and threat intelligence sources to investigate, document, and resolve incidents.
• Apply incident handling methodologies and attack frameworks (e.g., kill chain / MITRE ATT&CK-aligned thinking) to guide response and reporting.
• Perform in-depth analysis of threats, exploits, vulnerabilities, and malware families; validate hypotheses using host and network evidence.
• Conduct investigations across Windows, macOS, and Linux environments.
• Leverage Endpoint Detection and Response (EDR) tooling and cloud security telemetry to scope activity and support containment/remediation actions.
• Use Splunk and related analytics tooling to query, correlate, and operationalize security data for investigations and reporting.
• Demonstrate strong understanding of enterprise infrastructure and connectivity (e.g., VPN/partner connectivity) and common network protocols.
• Design, implement, and tune security detections in response to emerging threats and insider risk behaviors.
• Develop scripts and automation (e.g., Python, PowerShell, Bash) to enrich investigations and streamline operational workflows.
• Collaborate with partner analytic and engineering teams to align detections, telemetry, and response actions across the broader security ecosystem.
Required Qualifications • 5+ years of hands-on cybersecurity experience in incident response, security operations, insider risk, threat detection, or a closely related function.
• Demonstrated experience leading or handling escalated incidents, including triage, investigation, containment, remediation, and post-incident reporting in complex enterprise environments.
• Proficiency with security telemetry and investigation workflows across endpoint and network data sources; experience using SIEM analytics (e.g., Splunk) and EDR tooling.
• Working knowledge across multiple domains such as host analysis, network forensics, cloud environments, UEBA/anomaly detection, intrusion detection, threat research/intelligence, detection engineering, and data analysis.
• Ability to develop or maintain automation using scripting
Salary insight
The midpoint of this range ($189k) is about 43% above the median disclosed salary for Dallas roles listed on ForgeApply ($133k across 893 jobs).
See full Security Engineer salary data for Dallas →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this AT&T role before you apply.
Tailor my resume for this jobSimilar jobs
- Security Specialist – Insider Risk, Threat Intelligence & Physical Security, AI & Automation — Micron · Manassas, VA - Fab 6
- Security Engineer, Insider Threat Detection & Response — Openai · San Francisco
- Cybersecurity Operations Analyst & Cyber Threat Intelligence Lead — The Aerospace Corporation · Colorado Springs, CO
- AI Threat Analyst - Insider Risk — SNC · Herndon, VA | Sparks, NV | Hagerstown, MD
- Information Security Engineer - Insider Risk — Palantir · New York, NY
- Information Security Engineer - Insider Risk — Palantir · Washington, D.C.
- Information Security Engineer - Insider Risk — Palantir · Seattle, WA
- Lead Cyber Threat Intelligence Data Architect — Humana · Remote
More like this: Security & Cybersecurity Jobs · Remote Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Dallas · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)