Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Threat Analyst (Black Lotus Labs)

$105.79k - $141.05k

Lumen Technologies

Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments, and communities. At Lumen, you’ll work on infrastructure customers rely on today and build for what’s next, where performance, security, and resilience matter. This is a high accountability environment where bold ideas drive real innovation for our customers, partners, and industry. The work is challenging, expectations are clear, and trust is built into how we operate. If you’re ready to take ownership, deliver meaningful impact, and help shape the future of AI‑ready connectivity, join us today. The Role Black Lotus Labs has an opening for a Lead Information Security Engineer who will support threat hunting, investigation, and discovery of evolving malicious activity using Lumen’s unique network visibility, analytic platforms, and approved AI‑enabled tools. Our global visibility into one of the world’s largest and most interconnected IP backbones, combined with our computing cluster and analytic platforms, presents exciting opportunities to apply machine learning, graph analytics, automation, and AI‑enabled tools to help identify threats across the internet. Black Lotus Labs has detected and disrupted key evolving threats at an internet scale for years. This position will work alongside Black Lotus Labs advanced security researchers, data engineers, malware reverse engineers, data scientists, and our customers to support investigations into evolving threats using technologies like our Hadoop ecosystem (HBase, HDFS, Spark, Kafka, AirFlow), Elasticsearch and Redis clusters, Docker using Docker Swarm, malware environment, a network of honeypots, and modern AI‑assisted research and development capabilities. This is a close‑knit, experienced, amazingly smart team that you can be a part of and help build out. This is a remote/work‑from‑home opening with requirements for in person collaboration at the customer site as needed in Annapolis Junction, Maryland. This position requires an active TS/SCI security clearance w/ CI Poly. Location This is a hybrid position with customer travel in the MD area approximately 1 to 2 times per week. The Main Responsibilities Research attacker tools, techniques, and procedures (TTPs) and contribute to analytic approaches that support automated detection. Work with cyber operators and senior researchers, when requested, to support investigations into cyber threat activity and assist with mitigation guidance. Support automation of investigations through Python scripting, data analysis, and visualization in Jupyter Notebooks and Grafana. Build and maintain collaborative relationships with internal intelligence teams, law enforcement, and outside groups. Support customer RFIs on incidents and emerging threats with guidance from senior team members as needed. Use approved AI‑enabled tools to assist with research, coding, data exploration, documentation, and knowledge discovery while validating outputs through sound analytical judgment. Contribute to repeatable workflows that combine analyst expertise, automation, and AI‑assisted capabilities to improve investigative efficiency and analytical quality. What We Look For In a Candidate Candidates must effectively communicate complex domain‑specific concepts, ensuring clarity for both technical and non‑technical audiences. Familiarity with adversary capabilities, infrastructure, and techniques, with the ability to apply that knowledge in collaboration with supporting teams and partners. Experience using OSINT methods for investigation, including discovering novel threats in malware repositories. Scripting experience with Python and familiarity with large‑scale or distributed data analysis concepts. Experience supporting cyber threat hunting, security investigations, or analysis of suspicious activity using structured data sets. Familiarity with network‑based threats and identifying suspicious behaviors from network telemetry. Strong analytical thinking and ability to quickly pick up new methods, tools and programming languages. Willingness to learn new cyber threat research tradecraft and apply unfamiliar data sources, investigative methods, analytic tools, and AI‑assisted workflows to mission‑focused problems. User‑level experience in a Unix‑based environment. Familiarity with extracting data through SQL. Strong writing skills to assist in documenting findings and sharing knowledge with technical and non‑technical audiences. Demonstrable knowledge of several of the following areas: cybersecurity concepts, network protocols, firewalls, IDS/IPS systems, cyber threat hunting, malware analysis concepts, cyber threat intelligence, common threat actor TTPs, application security concepts, or cloud security fundamentals. Ability to develop proficiency in unfamiliar technical domains through foundational analytical skills, self‑directed learning, and effective use of AI‑assisted research and problem‑solving tools. Ability to use AI‑enabled tools responsibly to support technical research, analysis, coding, documentation, and report development while maintaining professional skepticism and analytical rigor. Ability to review and validate AI‑generated outputs before using them in analysis, findings, or recommendations. Candidates may also have the following preferred skills or experience Previous work experience with Department of Defense (DoD), Intelligence Community, or other government agencies is preferred. Hands‑on experience with Spark, distributed computing, or large‑scale data analysis platforms is preferred. Experience developing automation and analysis in Python‑based environments. Ability to collaborate with peers and senior team members while developing expertise in new technical topics. Exposure to generative AI, AI‑assisted coding, retrieval‑augmented analysis, or agent‑based workflows in cyber research, threat hunting, or intelligence production is preferred. Preferred Familiarity with analyzing NetFlow data to identify unusual patterns and potential security threats. Interest in conducting trend analysis to uncover patterns and emerging threats, enabling proactive defense strategies. Demonstrated curiosity and sound judgment when using AI‑enabled tools in mission‑focused environments while maintaining data protection requirements, analytical integrity, and human accountability for findings and recommendations. Compensation This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors. Location Based Pay Ranges

  • 105,786 - $141,047 in these states: AL AR AZ FL GA IA ID IN KS KY LA ME MO MS MT ND NE NM OH OK PA SC SD TN UT VT WI WV WY
  • 111,074 - $148,099 in these states: CO HI MI MN NC NH NV OR RI
  • 116,364 - $155,152 in these states: AK CA CT DC DE IL MA MD NJ NY TX VA WA
Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. We're able to answer any additional questions you may have about our bonus structure (short‑term incentives, long‑term incentives and/or sales compensation) as you move through the selection process. Learn more about Lumen's:Benefits Bonus Structure Requisition # 342922 Life at Lumen Life at Lumen is human and connected, even in a fast moving, AI‑focused organization. We set clear expectations and trust people to meet them. With real support and shared accountability, teams collaborate better, move faster, and deliver meaningful outcomes. Our Lumen 8 behaviors guide how we interact, make decisions, and work together, shaping a culture built to perform and win. To learn more about Life at Lumen and how we live the Lumen 8, please visit: Background Screening If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. For more information on these checks, please refer to the Post Offer section of our FAQ page. Job‑related concerns identified during the background screening may disqualify you from the new position or your current role. Background results will be evaluated on a case‑by‑case basis. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Equal Employment Opportunities We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training. Privacy Notice Lumen is committed to protecting the privacy and security of personal information collected during the recruitment and hiring process. Our Applicant Privacy Notice explains how we collect, use, disclose, and protect applicant information, as well as how individuals may request access to or deletion of their personal data. To review Lumen’s Global Employment Applicant and Talent Community Privacy Notice, please visit: Disclaimer The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions. In any materials you submit, you may redact or remove age‑identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information. Please be advised that Lumen does not require any form of payment from job applicants during the recruitment process. All legitimate job openings will be posted on our official website or communicated through official company email addresses. If you encounter any job offers that request payment in exchange for employment at Lumen, they are not for employment with us, but may relate to another company with a similar name. #J-18808-Ljbffr Lumen Technologies

Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the Lead Threat Analyst (Black Lotus Labs) in Fort Washington, MD vacancy
  • Lumen Technologies is seeking a Lead Information Security Engineer to advance threat hunting and investigations using our AI-enabled tools and large-scale data platforms. You will work with Black Lotus Labs researchers, data engineers, and security professionals to identify... 
    Suggested
    Remote job

    Lumen Technologies

    Fort Washington, MD
    12 hours ago
  • $80k - $85k

     ...deploy globally as a TXP & AXC-GO team member.Understanding of lab processes and workflow for device exploitation efforts.Knowledge...  ...global IED devices and Tactics, Techniques, and Procedures (TTP) threat.Experience must include electronic printed circuit board (PCB) assembly... 
    Suggested
    For contractors
    Work experience placement
    Remote work

    AMERICAN SYSTEMS

    Indian Head, MD
    2 days ago
  • $100k - $110k

     ...Training.ResponsibilitiesAs a Senior WTI Analyst with AMERICAN SYSTEMS you will have the opportunity...  ...closely with the electronic exploitation Lab to create and assign device profiles.#TXP...  ...Tactics, Techniques and Procedures (TTP) threat.Experience with collaborating with... 
    Suggested
    For contractors
    Work experience placement
    Work at office
    Local area

    AMERICAN SYSTEMS

    Indian Head, MD
    2 days ago
  • $160k - $175k

     ...and science and technology. SPA has a need for an experienced analyst to help lead a long-term study that assesses the vulnerabilities of...  ...individual with a demonstrated record of success in assessing threats and vulnerabilities from unmanned systems and developing operational... 
    Suggested
    Immediate start
    Flexible hours

    Systems Planning and Analysis, Inc.

    Alexandria, VA
    1 day ago
  • A defense contractor is seeking a Senior All-Source Analyst (Production / Janus/Hard Target) to support USCYBERCOM J2 in the National...  ...+ years with a bachelor's degree, alongside knowledge in cyber threat analysis and the ability to work independently. The position offers... 
    Suggested
    For contractors

    Kinsley Power Systems

    Alexandria, VA
    1 day ago
  • $150k - $165k

     ...Job Description Job Description Position Title: Threat Intelligence Lead Location: Camp Springs, MD Employment Type: Full‑Time Salary Range: $150,000 - $165,000 Clearance Requirement: Ability to obtain and maintain Top Secret / SCI Position Overview... 
    Full time
    Immediate start
    Flexible hours

    Corinth

    Camp Springs, MD
    2 days ago
  •  ...Bachelor Degree and 10 years of experience serving as a Business Analyst supporting large scale technology initiatives Min 5 years of...  ...be local to the DMV area The Gist… The Business Analyst Lead serves as the primary liaison between business stakeholders, program... 
    Local area

    Amivero

    Suitland, MD
    1 day ago
  • Information International Associates, Inc. is seeking a Cyber Threat Intelligence (CTI) Lead in Alexandria, VA. This role involves providing technical support to a 24x7 cyber program with responsibilities including the development of CTI analysis and incident response.... 

    Information International Associates, Inc.

    Alexandria, VA
    14 hours ago
  • Ventus Solutions (VES) is looking for a Senior Technical Program Analyst in Alexandria, VA. The role involves providing essential technical support to manage the program, liaising with senior government officials, and ensuring compliance with federal standards. The ideal... 

    Ventus Solutions (VES)

    Alexandria, VA
    12 hours ago
  • Systems Planning and Analysis, Inc. seeks an experienced analyst to lead a long-term study on the vulnerabilities of U.S. submarines during surfaced operations and to develop robust operational and technical countermeasures. You will coordinate with Navy staff, the IC,... 

    Systems Planning and Analysis, Inc.

    Alexandria, VA
    1 day ago
  • Systems Planning & Analysis is seeking a technology-based Wargame Analyst in Alexandria, VA. You will lead the design and execution of complex wargames for government clients, providing strategic insights and contributing to critical decision-making. The ideal candidate... 

    Systems Planning & Analysis

    Alexandria, VA
    12 hours ago
  • BryceTech is seeking an Experimentation Analyst to lead a team conducting DoD experimentation activities for CWMD software capabilities. Based in Alexandria, VA with a hybrid on-site/remote schedule and occasional travel, you will partner with government and industry to... 
    Remote work

    Doist

    Alexandria, VA
    1 day ago
  • Booz Allen Hamilton is seeking an All-Source Analyst to conduct defense-industries analysis on foreign programs, infrastructure, and capabilities supporting a country’s military. You will produce strategic analyses and briefs for senior policymakers, applying IC/Combatant... 

    Booz Allen Hamilton

    Alexandria, VA
    3 days ago
  • Radiance Technologies, located in Alexandria, Virginia, is seeking a Signals Intelligence (SIGINT) Analyst to support the U.S. Army Tactical Exploitation of National Capabilities (TENCAP) program. The role includes providing assessments and evaluations on performance and... 

    Radiance Technologies

    Alexandria, VA
    12 hours ago
  • $130k - $180k

     ...and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Lead Cyber Threat Intelligence Analyst Location: Onsite – Government-controlled secure facility Terms: Full-time Salary: $130-$180k DOE... 
    Full time
    Work experience placement
    Flexible hours
    Shift work

    Revolutional, LLC

    Silver Hill, MD
    26 days ago
  • A veteran-owned consulting firm based in Northern Virginia is seeking a Mentor-Protégé Program Analyst to support a federal small business office. The role involves program oversight, stakeholder coordination, and budget tracking. Ideal candidates will have 5-7 years of... 
    Work at office

    Polaris Consulting Group

    Alexandria, VA
    2 days ago
  • Systems Planning and Analysis, Inc. (SPA) is looking for a Wargame Analyst in Alexandria, VA, to lead the design and execution of complex wargames and workshops for government clients. The role requires 7+ years of experience and a Bachelor's degree in a relevant field... 

    Systems Planning and Analysis, Inc.

    Alexandria, VA
    3 days ago
  • $145k - $160k

     ...Transparency, and Excellence form the foundation for everything we do. Explore further at Roles and Responsibilities This Lead Salesforce Business Analyst will work to help analyze, define, and document requirements to translate customer needs into Salesforce technology... 
    Contract work
    Work experience placement
    Work at office
    Flexible hours

    NSS

    Alexandria, VA
    2 days ago
  • Arenatechnologies is seeking a Configuration Management Analyst in Alexandria, Virginia. You will provide crucial configuration management expertise to support Navy and DoD programs, ensuring technical baselines are maintained effectively. Ideal candidates will have a Bachelor... 

    Arenatechnologies

    Alexandria, VA
    1 day ago
  • $115.2k - $155k

     ...STINGRAI Tech Advisor (Operations Research Analyst 4) - 29231 Location: Fort Washington, MD,...  ..., we define how every employee grows, leads, and contributes—regardless of role. It sets...  ...mission partners stay ahead of evolving threats by delivering the intelligence,... 
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Worldwide

    Huntington Ingalls Industries

    Fort Washington, MD
    2 days ago
  •  ...success across complex defense environments. The role produces CONOPS, roadmaps, TTPs, and strategic plans, while integrating policy, threat projections, and intelligence Estimates to ensure plans align with doctrine and requirements. #J-18808-Ljbffr Huntington Ingalls... 

    Huntington Ingalls Industries

    Fort Washington, MD
    1 day ago
  • Huntington Ingalls Industries (HII) is seeking a Data Analyst for the STINGRAI program in Fort Washington, MD. The role focuses on delivering...  ..., mitigate supply chain risks, and strengthen defenses against threats to IT systems. Top Secret clearance is required and experience... 

    Huntington Ingalls Industries

    Fort Washington, MD
    2 days ago
  • Systems Planning and Analysis, Inc. (SPA) seeks an experienced analyst to lead a long-term Navy-focused study on submarine vulnerabilities during surfaced operations and to develop countermeasures. The role requires deep analysis and collaboration with Navy staff, the Intelligence... 

    Arenatechnologies

    Alexandria, VA
    4 days ago
  •  ...acquisition, and science and technology.SPA is seeking a Program Analyst to support NAVSEA's Naval Special Warfare Program Office....  ...and future systems definitions and designs based on projected threats and new technologies, utilizing client systems. Assists the Program... 
    Full time
    Contract work
    Work at office
    Flexible hours

    MCR

    Alexandria, VA
    1 day ago
  • $103.8k - $218.1k

     ...Continental US* * *The Opportunity:CACI is seeking a Spectrum Analyst to support Joint Interagency Task Force 401 (JIATF 401). The Spectrum...  ...to identify, characterize, and assess electromagnetic threats, optimize spectrum utilization, and provide decision support for... 
    Contract work
    Work experience placement
    Work at office
    Flexible hours

    CACI International

    Alexandria, VA
    1 day ago
  • $87.1k - $157.45k

    Leidos' Digital sector has frequent opportunities available for SOC Analysts to join our team in Alexandria, VA. We recruit for these...  ...organization.Demonstrated understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an... 
    Full time
    Work experience placement
    All shifts
    Shift work

    Leidos

    Alexandria, VA
    4 days ago
  • $130k - $150k

     ...Support, Engineering & Analysis, and Training.ResponsibilitiesAs an Analyst, Technology Protection, you will have the opportunity to do the...  ...Status/Veteran StatusJob SummaryCategory: Security / Intel / Threat AnalysisPosition Type: Full-TimeRemote: NoClearance Required:... 
    For contractors

    AMERICAN SYSTEMS

    Alexandria, VA
    2 days ago
  •  ...deliver, and sustain new technologiesAnalysis of vulnerabilities and threats to undersea platforms and systemsQuantitative analysis and...  ...and their missionsSPA has an immediate need for for a Program Analyst for upcoming support to the Program Executive Office (PEO) for... 
    Full time
    Contract work
    For contractors
    Casual work
    Work at office
    Immediate start
    Remote work
    Flexible hours

    MCR

    Alexandria, VA
    4 days ago
  • DescriptionSAIC is hiring a Senior CFIUS-Export Control Analyst to lead our team of qualified, diverse, and highly motivated individuals supporting...  ..., influence, cyber penetration, and other exploitation threats to the US technology and manufacturing industrial basesReview... 
    Work at office
    Local area

    Science Applications International Corporation

    Alexandria, VA
    22 hours ago
  • Lead Identity and Access Management (IAM) Engineer Job ID 25287 Location Toll Brothers - Fort Washington, Pennsylvania 19034 United States...  ...repeatable access management processes. Security Operations & Threat Detection Integrate IAM capabilities with security monitoring,... 
    Full time
    Work at office
    Local area

    Toll Brothers

    Fort Washington, MD
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Threat Analyst (Black Lotus Labs). Be the first to apply!