Jobs · Information Technology · North Carolina

Lead Cybersecurity - Network Threat Analyst

AT&T · Charlotte, NC · 1 wk ago
On-siteInformation Technology$141k–$212k/yrFull-time

About the role

This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.

Responsibilities

  • Perform deep technical analysis of suspicious network activity using internal network collection platforms, including but not limited to flow analysis, packet analysis, review of metadata and intelligence sources.
  • Use proprietary and open-source intelligence sources to analyze and interpret network telemetry, produce informative products, briefs, reports, and indicators of compromise.
  • Configure and optimize internal and external threat monitoring systems to increase AT&T's intelligence holdings to maintain a high standard of quality for network cyber indicators.
  • Document findings and recommend remediation action to a team of highly technical professionals with expertise in cybersecurity, threat intelligence, threat detection, networking, log, malware, and vulnerability analysis.
  • Identify and implement new analysis techniques, beyond those currently available.
  • Detect network threats beyond the capabilities of common tools.
  • Reduce the risk of False Positive or False Negative detections and improve detection logic for advanced and targeted threats that are missed by existing tools and controls.
  • Implement new automation solutions to improve workflow efficiency.
  • Create detailed and accurate reports and professional briefings documenting findings to share with a variety of audiences.
  • Recommend and oversee implementation of technical requirements to ensure platform meets analysis needs.
  • Develop, test, and operationalize AI-assisted threat analysis workflows (e.g., enrichment, clustering, summarization, and triage) to improve speed and consistency of investigations.
  • Evaluate and validate AI outputs for accuracy, bias, and security relevance; apply human-in-the-loop review and document decision rationale for key analytical judgments.
  • Use AI tools in alignment with enterprise security, privacy, and data-handling requirements; ensure sensitive data is protected and only approved tools and datasets are used.
  • Create and maintain reusable prompts, playbooks, and automation scripts that integrate AI with existing detection, telemetry, and case-management workflows.
  • Define and track quality metrics for AI-assisted analysis (e.g., precision/recall impact, time-to-triage, false positive reduction) and iterate based on outcomes.
  • Partner with detection engineering, data science, and platform teams to onboard new AI capabilities, test changes safely, and transition prototypes into repeatable operations.
  • Provide guidance to analysts on effective and responsible use of AI during investigations, including limitations, verification steps, and escalation paths.

Qualifications

  • Bachelor's degree in computer science, cybersecurity, information technology, or a related field.
  • 5+ years of experience in cybersecurity, threat intelligence, networking or a related field.
  • Demonstrated Knowledge or use of: Common cybersecurity concepts, tools, and frameworks (e.g., NIST, MITRE ATT&CK, SIEM, IDS/IPS, etc.).
  • Common network threats, attack methods and techniques (DDoS, brute force, spoofing, MITM, etc.).
  • Common network concepts, technologies, controls, and protocols (e.g. IDS/IPS/Routing/VPN/ICMP/BGP/UDP/TCP/SSL/HTTP/SMTP, etc.).
  • Cyber-attack stages (e.g. reconnaissance, scanning, enumeration, exploitation, privilege escalation, lateral movement, persistence, etc.).
  • Network analysis tools/technologies (Wireshark, Netwitness, SNORT, SURICATA, ZEEK, PCAP, NETFLOW, etc.).
  • Programming or scripting languages (e.g., Python, PowerShell, or equivalent).
  • Investigative tools and techniques.
  • Demonstrated ability to: Identify network threats and create detective measures and IOCs.
  • Identify patterns and trends in data with strong analytical and problem-solving skills.
  • Identify False Positives and False Negatives.
  • Use and configure threat intelligence platforms and tools (e.g., MISP, ThreatQ, OpenCTI or equivalent).
  • Stay current with the latest developments in cybersecurity and threat intelligence.
  • Work independently and collaboratively in a fast-paced & dynamic environment.
  • Use Windows and Linux.
  • Use Open-Source Research Techniques to discover related threats.
  • Adhere to established rules, regulations, conventions, and information protection requirements with a demonstrated sense of responsibility and ethics.
  • Apply feedback to future work products.
  • Effectively communicate to convey complex information in a clear and concise manner in both written and oral formats.
  • Use AI tools, analysis techniques, and technologies and expertly apply them to network threat analysis, including validating outputs and documenting methodology.

Desired

  • Relevant cybersecurity certifications (e.g., CISSP, Security+, CEH, or equivalent).

Supervisor

No

Pay

Our Lead Cybersecurity earns between $141,300.00 - $211,900.00 USD Annual, not to mention all the other amazing rewards that working at AT&T offers.

Schedule

Full-time office role

Location

USA:NC:Charlotte / IBM Dr - Adm:8505 IBM Dr

Similar jobs

Cybersecurity Engineer, Lead

Independence Pet GroupChicago, IL· 2 mo ago
Information Technologyapply on independencepetgroup.wd12.myworkdayjobs.com

Lead Cybersecurity Engineer

Ritchie Bros.Westchester, IL· 2 wk ago
Information Technologyapply on fa-exew-saasfaprod1.fa.ocs.oraclecloud.com

Cyber Threat Analyst

Parsons CorporationAnnapolis Junction, MD· 2 mo ago
Information Technology$134k–$241k/yrapply on parsons.wd5.myworkdayjobs.com