×
Register Here to Apply for Jobs or Post Jobs. X

Principal Cybersecurity - Incident Response Analyst

Job in Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listing for: AT&T
Full Time position
Listed on 2026-09-21
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 155400 - 233200 USD Yearly USD 155400.00 233200.00 YEAR
Job Description & How to Apply Below

Position Summary

The Principal Cybersecurity Incident Response Analyst is responsible for leading complex cybersecurity investigations and incident response activities across AT&T's enterprise environment. This role serves as the Lead Investigator for escalated security incidents, partnering closely with Security Operations, Digital Forensics, Threat Intelligence, Malware Analysis, Engineering, and business stakeholders to identify, contain, eradicate, and recover from cybersecurity threats.

The Principal Analyst provides expert-level technical leadership during significant cybersecurity incidents, conducts proactive threat hunting activities, and drives continuous improvement of incident response processes, detection capabilities, and investigative methodologies. This position requires strong investigative skills, deep technical expertise, executive-level communication abilities, and the ability to mentor others across the Incident Response organization.

This role participates in an on-call rotation and supports investigations involving endpoint systems, cloud environments, identity platforms, network infrastructure, telecommunications systems, applications, and emerging technologies.

Key Responsibilities:
  • Lead cybersecurity investigations associated with escalated security incidents and suspicious activity.
  • Serve as Lead Investigator (Handler) for all assigned escalated cybersecurity incidents.
  • Coordinate and oversee all investigative, containment, eradication, and recovery activities associated with major cybersecurity events.
  • Conduct major and micro-hunt investigations to identify malicious activity, assess risk, and improve organizational detection capabilities.
  • Investigate threats, exploits, vulnerabilities, malware families, and advanced adversary activity across enterprise environments.
  • Perform advanced host, network, log, cloud, and threat intelligence analysis.
  • Produce technical reports, after-action reviews, executive summaries, and leadership briefings documenting investigative findings and recommendations.
  • Collaborate with Security Operations, Threat Intelligence, Digital Forensics, Malware Analysis, Engineering, Legal, Privacy, and other stakeholders during active investigations.
  • Support the development and continuous improvement of incident response playbooks, processes, automation, and investigative methodologies.
  • Design and facilitate tabletop exercises and cybersecurity incident simulations.
  • Identify security control gaps and provide recommendations to improve organizational resilience.
  • Mentor analysts and investigators throughout the Incident Response organization in both technical and professional development areas.
  • Provide executive-level communications during significant cybersecurity events.
Required Technical Knowledge:

Experience or working knowledge in several of the following areas:

  • Cyber Incident Response
  • Threat Hunting
  • Digital Forensics
  • Threat Intelligence Analysis
  • Security Operations
  • SIEM Technologies (Splunk or equivalent)
  • Endpoint Detection and Response (EDR/XDR)
  • Cloud Security (AWS, Azure, and SaaS platforms)
  • Host and Network Forensics
  • Malware Analysis Fundamentals
  • Vulnerability Assessment and Exploitation Techniques
  • Intrusion Detection and Anomaly Detection
  • Security Alert Design and Detection Engineering
  • Network Protocol Analysis
  • Windows, Linux, and macOS Investigations
  • Threat Actor Tactics, Techniques, and Procedures (TTPs)
  • Scripting and Automation (Python, Power Shell, Bash, or similar)
  • Telecommunications and Enterprise Network Security
  • Artificial Intelligence and AI-Assisted Security Analysis
Preferred Qualifications:
  • 7+ years of experience in Incident Response, Security Operations, Threat Hunting, Digital Forensics, or related cybersecurity disciplines.
  • Experience leading large-scale or high-impact cybersecurity investigations.
  • Experience developing detection logic, investigative methodologies, and response processes.
  • Experience supporting cloud-native and hybrid enterprise environments.
  • Strong understanding of threat actor behavior, attack frameworks, and incident lifecycle management.
  • Industry certifications such as GCIH, GCFA, GCFE, GPEN, GCIA, CISSP, GNFA, or equivalent.
What Candidates Should Expect:

This is a senior incident response leadership role. Successful candidates should expect:

  • Leading complex cybersecurity investigations from detection through remediation.
  • Managing high-priority cybersecurity incidents with significant business impact.
  • Conducting proactive threat hunting activities and intelligence-driven…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary