Senior Cybersecurity Engineer – Endpoint Security (ai Enabled Operations)

AT&T AT&T · Telecom · Charlotte, NC

Senior Cybersecurity Engineer focused on modernizing enterprise endpoint security using AI-enabled operations, including monitoring, analytics, triage, automation, and reporting. The role involves engineering and supporting various endpoint security platforms (EDR, DLP, VPN, etc.) and extending AI-driven workflows for exception handling, risk scoring, and policy orchestration.

What you'd actually do

  1. Support and help engineer endpoint security controls for: Endpoint Detection & Response (EDR) (e.g., SentinelOne, Microsoft Defender, Cortex XDR)
  2. Extend and adapt AI-driven intake, enrichment, and approval workflows established in Mobile Security Operations to endpoint security use cases, including: Automated triage of endpoint security exceptions and access requests
  3. Design and maintain policy‑as‑code and AI‑assisted approval orchestration for endpoint controls, enabling: Fast‑track handling of low‑risk exceptions
  4. Apply AI‑assisted techniques for alert correlation, risk scoring, trend analysis, and control drift detection to continuously improve endpoint security operations.
  5. Apply AI and analytics across mobile and endpoint security operations, including: AI‑assisted alert enrichment, correlation, and triage

Skills

Required

  • 3+ years of experience in endpoint security or enterprise endpoint engineering.
  • Experience supporting at least one endpoint security technology (EDR, DLP, VPN, proxy/web, or endpoint visibility platforms).
  • Strong understanding of endpoint operating systems (Windows, iOS, Android; macOS/Linux a plus).
  • Proven troubleshooting and analytical skills in large enterprise environments.
  • Strong written and verbal communication skills.
  • Experience using AI, analytics, or automation to improve security operations or IT workflows.
  • Practical exposure to: Alert triage and signal correlation
  • Practical exposure to: Risk scoring or posture analysis
  • Practical exposure to: Trend analysis and operational reporting
  • Practical exposure to: Documentation or support automation
  • Ability to apply AI responsibly and pragmatically to improve security outcomes and reduce operational friction.

Nice to have

  • Experience supporting 10,000+ endpoints.
  • Familiarity with compliance or regulatory requirements impacting endpoint and mobile security (e.g., GDPR, HIPAA).
  • Scripting or automation experience (e.g., PowerShell, Python, REST APIs).
  • Security or platform certifications (e.g., CompTIA Security+, Microsoft Security certifications, vendor‑specific endpoint, mobility, or Tanium certifications).

What the JD emphasized

  • AI‑enabled monitoring, analytics, triage, automation, and reporting
  • AI-driven intake, enrichment, and approval workflows
  • policy-as-code and AI-assisted approval orchestration
  • AI‑assisted techniques for alert correlation, risk scoring, trend analysis, and control drift detection
  • AI-Enabled Security Modernization & Automation
  • AI-assisted alert enrichment, correlation, and triage
  • Risk scoring
  • Trend analysis
  • Automated operational, compliance, and executive‑level reporting
  • AI, analytics, or automation to improve security operations or IT workflows
  • Alert triage and signal correlation
  • Risk scoring or posture analysis
  • Trend analysis and operational reporting
  • Documentation or support automation
  • apply AI responsibly and pragmatically

Other signals

  • AI-enabled monitoring, analytics, triage, automation, and reporting
  • Extend and adapt AI-driven intake, enrichment, and approval workflows
  • policy-as-code and AI-assisted approval orchestration
  • Apply AI-assisted techniques for alert correlation, risk scoring, trend analysis, and control drift detection
  • AI-Enabled Security Modernization & Automation