Lead Cybersecurity Insider Risk Analyst

AT&T

Confirmed live yesterday High trust
Closes tomorrow

Quick summary

Work type
On-site
Location
Charlotte, NC
Salary
$141,300–$237,400 / yr
Posted
1 day ago
Freshness
Confirmed live yesterday
Closes
Oct 5, 2026 (soon)

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $160k
This role $189k
$109k most similar roles pay here $251k

This role pays more than 76% of similar roles. Most pay $132,375–$187,687 — the shaded band above. At the midpoint, this role pays about $189k versus about $160k for comparable roles.

Based on 240 similar postings.

Employer

About AT&T

AT&T is a US-based telecommunications company providing wireless, broadband, and fiber internet service along with phone and connectivity products for consumers and businesses.

AT&T currently has 89 open roles on FindRole.

Listed pay typically runs $118,700–$216,703 across 83 roles with salary data.

Most-posted roles

View all roles at AT&T

At a glance

TL;DR · Lead Cybersecurity Insider Risk Analyst

Lead Cybersecurity – Insider Risk Analyst (Telemetry, Insider Risk Detection, and AI-Driven Security Operations) leads the response to high-priority cybersecurity incidents with a focus on insider risk and telemetry-driven detection. This role involves managing end-to-end incident handling for employees and third-party vendors, including investigation, containment, and remediation. The position focuses on building detection logic, conducting micro-hunts, and integrating automation and AI-assisted analytics to improve detection fidelity while reducing manual effort. Key responsibilities include developing risk-scoring models, creating automated workflows via APIs, and performing deep-dive analysis across Windows, macOS, and Linux environments. The role requires proficiency in Splunk, EDR tooling, and scripting languages like Python, PowerShell, and Bash. The work addresses the challenge of identifying suspicious behaviors and emerging threats within complex enterprise infrastructures to protect against internal and external risks through advanced telemetry and threat intelligence.

What you'll do

  • Lead the response for high-priority insider risk and cybersecurity incidents from detection through remediation.
  • Conduct deep-dive investigations using endpoint, network telemetry, and threat intelligence to determine root causes.
  • Create and tune detection rules and analytics to identify suspicious behaviors and reduce false positives.
  • Perform targeted micro-hunts to discover emerging threats and translate findings into actionable playbooks.
  • Develop automation scripts and integrations using Python, PowerShell, or Bash to streamline security workflows.
  • Implement AI-assisted monitoring and risk-scoring models to improve alert prioritization and investigation speed.
  • Produce executive-level reports and technical summaries regarding incident status, impact, and mitigation steps.
  • Mentor junior analysts and serve as a subject matter expert for the incident response organization.

What we're looking for

  • 5+ years of hands-on cybersecurity experience in incident response, security operations, insider risk, or threat detection.
  • Experience leading and handling escalated incidents including triage, investigation, containment, remediation, and reporting in complex environments.
  • Proficiency with security telemetry, SIEM analytics (e.g., Splunk), and EDR tooling across endpoint and network data sources.
  • Working knowledge of host analysis, network forensics, cloud environments, UEBA, intrusion detection, and detection engineering.
  • Ability to develop or maintain automation using scripting (Python, PowerShell, Bash) and/or APIs to improve security operations.
  • Strong written and verbal communication skills for producing executive-ready summaries and leading discussions with diverse stakeholders.
  • Demonstrated integrity and discretion when handling sensitive investigations and confidential data.
  • Bachelor’s degree in Computer Science or Cybersecurity and relevant industry certifications (preferred).

More like this

Similar roles

Lead Cybersecurity Insider Risk Analyst

AT&T

Dallas, TX 1 day ago $141,300–$237,400
Splunk EDR Python PowerShell Bash MITRE ATT&CK SIEM UEBA SOAR Tanium Cloud Security Network Forensics Host Analysis Incident Response Detection Engineering Threat Intelligence Linux macOS Windows
5+ yrs exp

Lead, Insider Risk - Cyber Defense & Response

Prudential Financial

Newark, NJ 82 days ago $123,700–$204,100
Digital Forensics SIEM Behavioral Analytics User Activity Monitoring Cyber Threat Intelligence Data Integration Information Security Risk Management chain-of-custody GCFA GCFR GCTI CITPM CISSP

Lead Detection Engineer, Cyber Defense & Response

Prudential Financial

Newark, NJ 13 days ago
Splunk Enterprise Security SPL KQL Python SOAR CI/CD MITRE ATT&CK Cyber Kill Chain Threat Hunting Incident Response Digital Forensics Security Automation Linux Windows macOS

Cybersecurity Insider Threat Lead

Citi

Remote (Tampa, FL) 39 days ago $141,440–$212,160
Artificial Intelligence Data Analytics Cybersecurity Threat Intelligence Incident Response Risk Management Governance, Risk, and Compliance Information Security Project Management
10+ yrs exp Remote

Insider Risk Security Engineer

Lam Research

Fremont, CA 40 days ago $114,000–$253,000
Insider Risk Management DLP UEBA Microsoft E5 KQL YARA Regex JSON Lucene Query Syntax Cloud Security Cybersecurity Engineering Information Security Counterintelligence
5+ yrs exp Hybrid