Principal Cybersecurity - Incident Response Analyst

Posted Yesterday
Be an Early Applicant
Charlotte, NC, USA
In-Office
155K-233K Annually
Senior level
Internet of Things • Mobile • Retail
The Role
Leads complex enterprise cybersecurity investigations and incident response, serving as lead investigator for escalated incidents. Coordinates containment, eradication, recovery, threat hunting, forensics, malware and threat intelligence analysis, and executive communications. Improves response playbooks, detection capabilities, automation, and investigative methods; facilitates exercises, identifies security gaps, and mentors incident response personnel. Supports endpoint, cloud, identity, network, telecommunications, application, and emerging technology investigations while participating in an on-call rotation.
Summary Generated by Built In
Position Summary

The Principal Cybersecurity Incident Response Analyst is responsible for leading complex cybersecurity investigations and incident response activities across AT&T's enterprise environment. This role serves as the Lead Investigator for escalated security incidents, partnering closely with Security Operations, Digital Forensics, Threat Intelligence, Malware Analysis, Engineering, and business stakeholders to identify, contain, eradicate, and recover from cybersecurity threats.

The Principal Analyst provides expert-level technical leadership during significant cybersecurity incidents, conducts proactive threat hunting activities, and drives continuous improvement of incident response processes, detection capabilities, and investigative methodologies. This position requires strong investigative skills, deep technical expertise, executive-level communication abilities, and the ability to mentor others across the Incident Response organization.

This role participates in an on-call rotation and supports investigations involving endpoint systems, cloud environments, identity platforms, network infrastructure, telecommunications systems, applications, and emerging technologies.

Key Responsibilities:
  • Lead cybersecurity investigations associated with escalated security incidents and suspicious activity.
  • Serve as Lead Investigator (Handler) for all assigned escalated cybersecurity incidents.
  • Coordinate and oversee all investigative, containment, eradication, and recovery activities associated with major cybersecurity events.
  • Conduct major and micro-hunt investigations to identify malicious activity, assess risk, and improve organizational detection capabilities.
  • Investigate threats, exploits, vulnerabilities, malware families, and advanced adversary activity across enterprise environments.
  • Perform advanced host, network, log, cloud, and threat intelligence analysis.
  • Produce technical reports, after-action reviews, executive summaries, and leadership briefings documenting investigative findings and recommendations.
  • Collaborate with Security Operations, Threat Intelligence, Digital Forensics, Malware Analysis, Engineering, Legal, Privacy, and other stakeholders during active investigations.
  • Support the development and continuous improvement of incident response playbooks, processes, automation, and investigative methodologies.
  • Design and facilitate tabletop exercises and cybersecurity incident simulations.
  • Identify security control gaps and provide recommendations to improve organizational resilience.
  • Mentor analysts and investigators throughout the Incident Response organization in both technical and professional development areas.
  • Provide executive-level communications during significant cybersecurity events.
Required Technical Knowledge:

Experience or working knowledge in several of the following areas:

  • Cyber Incident Response
  • Threat Hunting
  • Digital Forensics
  • Threat Intelligence Analysis
  • Security Operations
  • SIEM Technologies (Splunk or equivalent)
  • Endpoint Detection and Response (EDR/XDR)
  • Cloud Security (AWS, Azure, and SaaS platforms)
  • Host and Network Forensics
  • Malware Analysis Fundamentals
  • Vulnerability Assessment and Exploitation Techniques
  • Intrusion Detection and Anomaly Detection
  • Security Alert Design and Detection Engineering
  • Network Protocol Analysis
  • Windows, Linux, and macOS Investigations
  • Threat Actor Tactics, Techniques, and Procedures (TTPs)
  • Scripting and Automation (Python, PowerShell, Bash, or similar)
  • Telecommunications and Enterprise Network Security
  • Artificial Intelligence and AI-Assisted Security Analysis
Preferred Qualifications:
  • 7+ years of experience in Incident Response, Security Operations, Threat Hunting, Digital Forensics, or related cybersecurity disciplines.
  • Experience leading large-scale or high-impact cybersecurity investigations.
  • Experience developing detection logic, investigative methodologies, and response processes.
  • Experience supporting cloud-native and hybrid enterprise environments.
  • Strong understanding of threat actor behavior, attack frameworks, and incident lifecycle management.
  • Industry certifications such as GCIH, GCFA, GCFE, GPEN, GCIA, CISSP, GNFA, or equivalent.
What Candidates Should Expect:

This is a senior incident response leadership role. Successful candidates should expect:

  • Leading complex cybersecurity investigations from detection through remediation.
  • Managing high-priority cybersecurity incidents with significant business impact.
  • Conducting proactive threat hunting activities and intelligence-driven investigations.
  • Producing executive-level communications and technical reporting.
  • Mentoring analysts and investigators across the Incident Response organization.
  • Collaborating with cross-functional cybersecurity and technology teams.
  • Participating in an on-call rotation supporting critical cybersecurity events.
  • Operating with a high degree of independence, accountability, and technical authority.

Job Contribution: An expert in their field, applying broad business knowledge and strategic insight surrounding emerging trends and technologies to solve complex problems and drive organizational results. Leads critical, high-impact projects and designs/implements innovative business strategies. Works with minimal oversight, frequently consulting senior leadership and influencing executive decisions. Serves as a mentor and assists others with challenging issues. Supervisor: No
TCP Career Step Differentiator: Manages and leads very complex cybersecurity work and is an expert in a specific cyber area. Creates plans that impact large organizations, multiple very complex applications/system, etc.
Education/Experience: Bachelor’s degree (BS/BA) desired in Computer Science or Cybersecurity. 7+ years of related experience. Certification is required in some areas.

Our Principal Cybersecurity jobs earn between $155,400.00 - $233,200.00 USD Annual. Not to mention all the other amazing rewards that working at AT&T offers. Individual starting salary within this range may depend on geography, experience, expertise, and education/training.

Joining our team comes with amazing perks and benefits:

  • Medical/Dental/Vision coverage
  • 401(k) plan
  • Tuition reimbursement program
  • Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)
  • Paid Parental Leave
  • Paid Caregiver Leave
  • Additional sick leave beyond what state and local law require may be available but is unprotected
  • Adoption Reimbursement
  • Disability Benefits (short term and long term)
  • Life and Accidental Death Insurance
  • Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
  • Employee Assistance Programs (EAP)
  • Extensive employee wellness programs
  • Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone

Weekly Hours:

40

Time Type:

Regular

Location:

USA:NC:Charlotte / Ibm Dr - Adm:8505 Ibm Dr

Salary Range:

$155,400.00 - $233,200.00

AT&T and its subsidiaries are committed to equal employment opportunity. All hiring, promotion, and other employment decisions remain merit-based and free from discrimination on the basis of race, color, religion, religious creed, national origin, ancestry, age, sex, sexual orientation, gender, gender identity, gender expression, physical disability, mental disability, pregnancy, medical condition, genetic information, marital status, citizenship status, military status, veteran status, or any other characteristic protected by federal, state, or local laws. In addition, AT&T will provide reasonable accommodations to qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made. Click here to learn more or request an application accommodation here.

Skills Required

  • Working knowledge or experience in several areas including cyber incident response, threat hunting, digital forensics, threat intelligence, security operations, SIEM, EDR/XDR, cloud security, host and network forensics, malware analysis, vulnerability assessment, intrusion detection, detection engineering, network protocol analysis, operating system investigations, threat actor TTPs, scripting and automation, telecommunications and enterprise network security, and AI-assisted security analysis.
  • Bachelor's degree in Computer Science, Cybersecurity, or a related field.
  • 7+ years of related experience.
  • Certification in relevant cybersecurity areas.
  • Experience leading large-scale or high-impact cybersecurity investigations.
  • Experience developing detection logic, investigative methodologies, and incident response processes.
  • Experience supporting cloud-native and hybrid enterprise environments.
  • Industry certification such as GCIH, GCFA, GCFE, GPEN, GCIA, CISSP, GNFA, or equivalent.

AT&T Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about AT&T and has not been reviewed or approved by AT&T.

  • Healthcare Strength Health coverage spans medical, dental, vision, and mental health services, plus a personal healthcare team, wellness apps, and supplemental options such as fertility care, cancer support, doula services, and wigs for chemotherapy. These comprehensive offerings are portrayed as supporting a wide range of employee needs.
  • Leave & Time Off Breadth Paid time off includes vacation, holidays, sick days, caregiver time, parental leave, and adoption assistance, with some roles reaching about 23 days of PTO after several years. Community volunteer days and flexible time off options add further support for work-life balance.
  • Wellbeing & Lifestyle Benefits Employees receive sizable service discounts like 50% off most wireless plans and broadband, along with savings on travel, event tickets, and insurance. Additional workplace perks such as hybrid work models and relocation assistance contribute to overall value.

AT&T Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Dallas, TX
150,000 Employees

What We Do

Bring us your biggest career aspirations. Share your boldest dreams. This is a moment to get energized. Through 5G and Fiber, AT&T provides connectivity that leads to smarter homes, safter communities, higher quality health care and more life-changing innovations. With AT&T, Connecting Changes Everything.

Gallery

Gallery

Similar Jobs

PNC Bank Logo PNC Bank

Product Owner

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
Hybrid
Charlotte, NC, USA
205000 Employees
Hybrid
Gastonia, NC, USA
205000 Employees

Wells Fargo Logo Wells Fargo

Senior Software Engineer

Fintech • Financial Services
Hybrid
Charlotte, NC, USA
205000 Employees
100K-163K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account