Principal Cybersecurity Incident Response Analyst

AT&T

Confirmed live yesterday High trust
Closes in 4 days

Quick summary

Work type
On-site
Location
Charlotte, NC
Salary
$155,400–$233,200 / yr
Posted
1 day ago
Freshness
Confirmed live yesterday
Closes
Sep 25, 2026 (soon)

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $158k
This role $194k
$111k most similar roles pay here $246k

This role pays more than 80% of similar roles. Most pay $131,675–$184,325 — the shaded band above. At the midpoint, this role pays about $194k versus about $158k for comparable roles.

Based on 240 similar postings.

Employer

About AT&T

AT&T is a US-based telecommunications company providing wireless, broadband, and fiber internet service along with phone and connectivity products for consumers and businesses.

AT&T currently has 84 open roles on FindRole.

Listed pay typically runs $130,200–$226,800 across 72 roles with salary data.

Most-posted roles

View all roles at AT&T

At a glance

TL;DR · Principal Cybersecurity Incident Response Analyst

The Principal Cybersecurity - Incident Response Analyst leads complex investigations and incident response activities across the enterprise environment. Serving as the Lead Investigator for escalated security incidents, this individual coordinates containment, eradication, and recovery efforts while partnering with teams like Security Operations, Digital Forensics, and Threat Intelligence. The role involves conducting proactive threat hunting, performing advanced host, network, log, and cloud analysis, and producing executive-level reports. Key technical competencies include experience with SIEM technologies like Splunk, EDR/XDR platforms, and cloud security across AWS, Azure, and SaaS environments. Candidates must possess skills in malware analysis, vulnerability assessment, and scripting using Python, PowerShell, or Bash. The role addresses critical threats to telecommunications systems and infrastructure while mentoring other analysts and improving organizational detection capabilities through the development of playbooks and simulation exercises.

What you'll do

  • Lead complex cybersecurity investigations for escalated incidents across enterprise environments.
  • Coordinate containment, eradication, and recovery activities for major security events.
  • Conduct proactive threat hunting to identify malicious activity and improve detection capabilities.
  • Perform advanced host, network, log, cloud, and threat intelligence analysis.
  • Produce technical reports, after-action reviews, and executive-level briefings on investigation findings.
  • Develop and improve incident response playbooks, automation, and investigative methodologies.
  • Design and facilitate tabletop exercises and cybersecurity incident simulations.
  • Mentor analysts and investigators in both technical and professional development areas.

What we're looking for

  • Bachelor's degree in Computer Science or Cybersecurity (preferred).
  • 7+ years of related experience in cybersecurity disciplines.
  • Experience leading large-scale or high-impact cybersecurity investigations (preferred).
  • Proficiency in incident response, threat hunting, digital forensics, and threat intelligence analysis.
  • Technical knowledge of SIEM, EDR/XDR, cloud security (AWS, Azure, SaaS), and network protocol analysis.
  • Ability to perform host, network, log, and malware analysis across Windows, Linux, and macOS systems.
  • Proficiency in scripting and automation using Python, PowerShell, or Bash.
  • Industry certifications such as GCIH, GCFA, GCFE, GPEN, GCIA, CISSP, GNFA, or equivalent (preferred).

More like this

Similar roles

Cyber Defense Response Analyst II

CME Group

Chicago, IL 25 days ago $93,900$156,500
Digital Forensics Incident Response Malware Analysis Python Pandas REST APIs AWS GCP Azure Q Radar Sentinel Splunk Chronicle ArcSight KAPE EnCase Cellebrite FTK Magnet Axiom Autopsy Ghidra Ida Pro PEStudio x64dbg SIEM

Senior Incident Response Analyst

Booz Allen Hamilton

Bethesda, MD 9 days ago $86,800$198,000
Splunk SIEM EDR IDS IPS SOAR Microsoft Defender Packet Analysis Malware Triage Digital Forensics Threat Hunting Behavioral Analytics Threat Intelligence Vulnerability Management Firewalls Identity and Access Management Container Security API Security
5+ yrs exp

Principal Security Engineer, Incident Response

F5 Inc

Remote 17 days ago $182,200$273,200
Incident Response Cybersecurity AWS Azure GCP Kubernetes WAF WAAP API Gateways DDoS Mitigation SIEM EDR CrowdStrike MITRE ATT&CK FedRAMP NIST SP 800-61 ISO 27001 PCI-DSS
10+ yrs exp Remote

Principal Cyber Threat Intelligence Specialist

University of Miami

Remote (Miami, FL) 17 days ago
Cyber Threat Intelligence Artificial Intelligence Security Automation SOC Threat Hunting Incident Response Vulnerability Management Governance, Risk and Compliance Identity and Access Management
10+ yrs exp Remote

Senior Cybersecurity Analyst

Visa

Ashburn, VA 7 days ago $131,600$210,300
Incident Response Threat Hunting Malware Analysis Web Application Security SIEM WAF IDS Netflow Packet Analysis TCP/IP Windows Linux SQL Injection Cross-Site Scripting Cross-Site Request Forgery
5+ yrs exp Hybrid

Computer Security Incident Report Analyst

Salesforce

Herndon, VA 63 days ago $111,000$122,000
Incident Response SIEM Splunk AWS Azure GCP ElasticStack Kibana Grafana Python Bash SQL GraphQL Linux Mac OS Windows TCP/IP Forensics Malware Analysis Network Security
2+ yrs exp