AT&T
Posted 1d ago

Senior Cybersecurity Engineer – Endpoint Security (AI Enabled Operations)

AT&T
Charlotte, North Carolina, United States
$128k-$193k/yrOnsiteFull Time
Responsibilities
  • engineering controls
  • troubleshooting policies
  • automating workflows
Requirements
  • Requires 3+ years in endpoint security or enterprise endpoint engineering
  • Endpoint platform experience
  • Operating system knowledge
  • Troubleshooting
  • Communication, and AI
  • Analytics, or automation experience
Technical tools mentioned
Endpoint Detection & Response (EDR)SentinelOneMicrosoft DefenderCortex XDRData Loss Prevention (DLP)Microsoft PurviewForcepointRemote Access VPNPalo Alto GlobalProtectTaniumWindowsiOSAndroidmacOSLinuxPowerShellPythonREST APIsMicrosoft Security

Job description

This position requires office presence of a minimum of 5 days per week and is only located in the location(s) posted. No relocation is offered.

Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it.

Role Summary

We are seeking a Senior Cybersecurity Engineer to secure and modernize our enterprise endpoint security environment. The role will support broader endpoint security platforms such as EDR, DLP, VPN, secure web access, and endpoint visibility platforms. Across both mobile and endpoint domains, the role emphasizes AI‑enabled monitoring, analytics, triage, automation, and reporting to improve security outcomes while reducing operational overhead.

This is a hands‑on engineering role operating at enterprise scale, working closely with Security Operations, Endpoint, IT, and business teams.

Key Responsibilities

Support and help engineer endpoint security controls for:

  • Endpoint Detection & Response (EDR) (e.g., SentinelOne, Microsoft Defender, Cortex XDR)
  • Data Loss Prevention (DLP) (e.g., Microsoft Purview/Defender, Forcepoint)
  • Remote Access VPN (e.g., Palo Alto GlobalProtect or equivalent)
  • Proxy / Secure Web Access controls (endpoint agent and policy enforcement where applicable)
  • Endpoint visibility, posture, and response platforms (e.g., Tanium or equivalent endpoint management and telemetry platforms)

Additional responsibilities include:

  • Provide Tier‑3 engineering support, including troubleshooting, policy tuning, exclusions, performance analysis, and vendor escalation.
  • Standardize endpoint security baselines and deployment patterns to ensure consistent control coverage and user experience.
  • Extend and adapt AI‑driven intake, enrichment, and approval workflows established in Mobile Security Operations to endpoint security use cases, including:
    • Automated triage of endpoint security exceptions and access requests
    • Correlation of endpoint posture, telemetry, and behavioral signals to defined risk criteria
    • Generation of structured risk and justification summaries to support faster, more consistent decisions
  • Design and maintain policy‑as‑code and AI‑assisted approval orchestration for endpoint controls, enabling:
    • Fast‑track handling of low‑risk exceptions
    • Escalation of high‑risk cases for engineering or security review
    • Integration with EDR, DLP, VPN, proxy, endpoint visibility platforms, and ticketing systems to reduce operational friction and manual effort
  • Apply AI‑assisted techniques for alert correlation, risk scoring, trend analysis, and control drift detection to continuously improve endpoint security operations.

AI‑Enabled Security Modernization & Automation (Cross‑Cutting)

  • Apply AI and analytics across mobile and endpoint security operations, including:
    • AI‑assisted alert enrichment, correlation, and triage
    • Risk scoring based on device posture, compliance, vulnerabilities, and behavioral signals
    • Trend analysis for control coverage, health, drift, and recurring incidents
    • Automated operational, compliance, and executive‑level reporting
  • Develop or support automation using APIs and scripting to:
    • Improve policy deployment and exception handling
    • Accelerate incident response actions
    • Reduce repetitive manual tasks and administrative overhead

Cross‑Functional Collaboration & Operational Excellence

  • Partner with Security Operations, Endpoint, IT, and business teams to align security controls with operational needs.
  • Translate technical security requirements into clear, actionable guidance for technical and non‑technical stakeholders.
  • Maintain runbooks, standards, and operational documentation, leveraging AI‑enabled tools to keep content current and consistent.
  • Support continuous improvement through root cause analysis, metrics, and feedback loops.

Experience & Skills

Required

  • 3+ years of experience in endpoint security or enterprise endpoint engineering.
  • Experience supporting at least one endpoint security technology (EDR, DLP, VPN, proxy/web, or endpoint visibility platforms).
  • Strong understanding of endpoint operating systems (Windows, iOS, Android; macOS/Linux a plus).
  • Proven troubleshooting and analytical skills in large enterprise environments.
  • Strong written and verbal communication skills.

AI & Automation Experience (Required or Strongly Preferred)

  • Experience using AI, analytics, or automation to improve security operations or IT workflows.
  • Practical exposure to:
    • Alert triage and signal correlation
    • Risk scoring or posture analysis
    • Trend analysis and operational reporting
    • Documentation or support automation
  • Ability to apply AI responsibly and pragmatically to improve security outcomes and reduce operational friction.

Preferred Qualifications

  • Experience supporting 10,000+ endpoints.
  • Familiarity with compliance or regulatory requirements impacting endpoint and mobile security (e.g., GDPR, HIPAA).
  • Scripting or automation experience (e.g., PowerShell, Python, REST APIs).
  • Security or platform certifications (e.g., CompTIA Security+, Microsoft Security certifications, vendor‑specific endpoint, mobility, or Tanium certifications).

Supervisor:

No

Our Senior Cybersecurity earns between $128,400-$192,600 USD Annual not to mention all the other amazing rewards that working at AT&T offers. Individual starting salary within this range may depend on geography, experience, expertise, and education/training.  

Joining our team comes with amazing perks and benefits:

  • Medical/Dental/Vision coverage  
  • 401(k) plan  
  • Tuition reimbursement program  
  • Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)  
  • Paid Parental Leave  
  • Paid Caregiver Leave  
  • Additional sick leave beyond what state and local law require may be available but is unprotected  
  • Adoption Reimbursement  
  • Disability Benefits (short term and long term)  
  • Life and Accidental Death Insurance  
  • Supplemental benefit programs: critical illness/accident hospital indemnity/group legal  
  • Employee Assistance Programs (EAP)  
  • Extensive employee wellness programs  
  • Employee discounts up to 50% off on eligible AT&T mobility plans and accessories,
  • AT&T internet (and fiber where available) and AT&T phone.

#LI-Onsite – Full-time office role-

Ready to join our team? Apply today.

Our Senior Cybersecurity jobs earn between $128,400.00 - $192,600.00 USD Annual. Not to mention all the other amazing rewards that working at AT&T offers. Individual starting salary within this range may depend on geography, experience, expertise, and education/training.

Joining our team comes with amazing perks and benefits:

  • Medical/Dental/Vision coverage
  • 401(k) plan
  • Tuition reimbursement program
  • Paid Time Off and Holidays (based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays)
  • Paid Parental Leave
  • Paid Caregiver Leave
  • Additional sick leave beyond what state and local law require may be available but is unprotected
  • Adoption Reimbursement
  • Disability Benefits (short term and long term)
  • Life and Accidental Death Insurance
  • Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
  • Employee Assistance Programs (EAP)
  • Extensive employee wellness programs
  • Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available) and AT&T phone

Weekly Hours:

40

Time Type:

Regular

Location:

Charlotte, North Carolina

Salary Range:

$128,400.00 - $192,600.00

AT&T and its subsidiaries are committed to equal employment opportunity. All hiring, promotion, and other employment decisions remain merit-based and free from discrimination on the basis of race, color, religion, religious creed, national origin, ancestry, age, sex, sexual orientation, gender, gender identity, gender expression, physical disability, mental disability, pregnancy, medical condition, genetic information, marital status, citizenship status, military status, veteran status, or any other characteristic protected by federal, state, or local laws. In addition, AT&T will provide reasonable accommodations to qualified individuals with disabilities. AT&T is a fair chance employer and does not initiate a background check until an offer is made. Click here to learn more or request an application accommodation here.

About AT&T

A leading provider of telecommunications, broadband, and digital connectivity services.

Year founded
1876
Employees
133030
Organization type
Public
Latest investment
IPO (1983)
Headquarters
US

Similar jobs

Cybersecurity Engineer roles near Charlotte, North Carolina
3w
Save
Mark Applied
Hide
Principal Cybersecurity Engineer
Chicago or Quincy or Salisbury
$109k-$188k/yr HybridFull Time
Ahold Delhaize USA
Ahold Delhaize USAEuronext Amsterdam: AD: The U.S. service division for a global grocery retailer.
10+ YOE10+ years in cybersecurity, security engineering, and architecture; bachelor's degree or equivalent; cloud, IAM, SIEM, infrastructure-as-code, scripting, compliance, and executive communication expertise.
Azure, AWS, GCP, Python, PowerShell, Terraform, Bicep, SIEM, CI/CD, Agile, Kanban, Lean, HIPAA, PCI DSS, SOX
1mo
Save
Mark Applied
Hide
Cybersecurity Engineer II
Concord, North Carolina, United States
$5k-$8k/mo OnsiteFull Time
Cabarrus County School District
Cabarrus County School District: Public school district serving Cabarrus County, North Carolina.
5+ YOE5+ years IT experience, 2+ years incident detection/response, bachelor\u0002s degree preferred, experience with Microsoft 365/Entra/Intune and Google Workspace, EDR/MDR, firewalls, networking, PowerShell, strong communication and customer-service skills.
firewalls, VPNs, DLP, IDS/IPS, Microsoft 365, Microsoft Entra ID, Microsoft Intune, Google Workspace, CrowdStrike, Arctic Wolf, VSX, Powershell, Microsoft Office, Windows, Apple
1mo
Save
Mark Applied
Hide
Cybersecurity Engineer III
Phoenix or Charlotte
$104k-$175k/yr HybridFull Time
American Express
American ExpressNYSE: AXP: Global financial services offering payment and travel products.
Bachelor's in CS/IS/Cybersecurity or comparable experience; expertise in cloud, data, AI security, IAM, SIEM, IDS/IPS, scripting (Python/Bash/PowerShell); CISSP/CISM/CISA or equivalent preferred.
Python, Bash, PowerShell, Splunk, ArcSight, QRadar, Wireshark, Sysinternals, Palo Alto, Cisco ASA, Snort, Suricata, Symantec, McAfee, Microsoft Copilot, Azure AI Foundry, OpenAI, Google Vertex AI
2mo
Save
Mark Applied
Hide
Senior Cybersecurity Engineer
Louisville or New York City or Dallas or Charlotte or Tampa or Miami or Fort Lauderdale or Washington or Chicago or Boston or Atlanta or Nashville
$118k-$162k/yr RemoteFull Time
Humana
HumanaNYSE: HUM: Health insurance and care services provider.
3+ YOE3+ years in cybersecurity and incident response, hands-on automation (PowerShell/Python), Azure DevOps and Azure monitoring experience, CI/CD and shell scripting, SDLC and Agile knowledge, experience with cloud security and data protection tools (Privacera).
Privacera, Microsoft Azure, GCP, Microsoft Azure DevOps, Microsoft PowerShell, Python, CI/CD, Kubernetes, Shell scripting, SIEM, Firewall, Proxy, AV
2mo
Save
Mark Applied
Hide
Senior Cybersecurity Engineer
Atlanta or Hackensack or Washington or Austin or Boston or Charlotte or Dallas or Denver or New York or Philadelphia or Chicago or Rockville
$100k-$125k/yr RemoteFull Time
Aprio
Aprio: Full-service CPA-led business advisory and accounting firm.
5+ YOE5+ years security engineering experience with hands-on responsibility for identity, network, cloud, endpoint, and monitoring controls; experience with Azure/AWS/GCP; ability to produce architecture docs and runbooks; mentoring and cross-team leadership; U.S. person required for CUI.
Terraform, Bicep, Pulumi, Sentinel, Open Policy Agent (OPA), SIEM, EDR, Azure, AWS, GCP, IAM, IaC
2w
Save
Mark Applied
Hide
Senior Lead Application Pen Testing Cybersecurity Research Engineer
Irving or Chandler or San Francisco or Charlotte or North Carolina or Texas or California or Arizona
$159k-$305k/yr RemoteFull Time
Wells Fargo
Wells FargoNYSE: WFC: Multinational financial services providing banking and investment products.
7+ YOERequires 7+ years of cybersecurity research experience or equivalent. Deep application penetration testing expertise, AI-assisted development, offensive security research, and strong communication skills required.
GitHub Copilot, Burp Suite, GCP, Azure
3mo
Save
Mark Applied
Hide
Cybersecurity Engineer Senior
Columbus or Austin or Chicago or Detroit or Charlotte or Dallas or Minnetonka or Atlanta or Houston or Birmingham
$57k-$113k/yr OnsiteFull Time
Huntington Bank
Huntington BankNASDAQ: HBAN: A regional bank offering consumer, commercial, and financial services.
3+ YOE3+ years in internet proxy/filtering; 1-3+ years data reporting; associate degree or 4+ years related experience.
Internet Proxy, Internet Filtering, SIEM, Orchestration, Automation, Remote Browser Isolation
5mo
Save
Mark Applied
Hide
Principal Cybersecurity Engineer
Salisbury or Quincy
$109k-$188k/yr HybridFull Time
Ahold Delhaize USA
Ahold Delhaize USAEuronext Amsterdam: AD: The U.S. service division for a global grocery retailer.
10+ YOE10+ years in cybersecurity with security engineering/architecture leadership; cloud security, IAM, IaC, SIEM, scripting; strong communication and collaboration.
Terraform, Bicep, SIEM, PowerShell, Python, Azure, AWS, GCP, CI/CD, Security automation