Lead Threat Analyst (Black Lotus Labs)
$105.79k - $141.05kLumen Technologies
Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments, and communities. At Lumen, you’ll work on infrastructure customers rely on today and build for what’s next, where performance, security, and resilience matter. This is a high accountability environment where bold ideas drive real innovation for our customers, partners, and industry. The work is challenging, expectations are clear, and trust is built into how we operate. If you’re ready to take ownership, deliver meaningful impact, and help shape the future of AI‑ready connectivity, join us today. The Role Black Lotus Labs has an opening for a Lead Information Security Engineer who will support threat hunting, investigation, and discovery of evolving malicious activity using Lumen’s unique network visibility, analytic platforms, and approved AI‑enabled tools. Our global visibility into one of the world’s largest and most interconnected IP backbones, combined with our computing cluster and analytic platforms, presents exciting opportunities to apply machine learning, graph analytics, automation, and AI‑enabled tools to help identify threats across the internet. Black Lotus Labs has detected and disrupted key evolving threats at an internet scale for years. This position will work alongside Black Lotus Labs advanced security researchers, data engineers, malware reverse engineers, data scientists, and our customers to support investigations into evolving threats using technologies like our Hadoop ecosystem (HBase, HDFS, Spark, Kafka, AirFlow), Elasticsearch and Redis clusters, Docker using Docker Swarm, malware environment, a network of honeypots, and modern AI‑assisted research and development capabilities. This is a close‑knit, experienced, amazingly smart team that you can be a part of and help build out. This is a remote/work‑from‑home opening with requirements for in person collaboration at the customer site as needed in Annapolis Junction, Maryland. This position requires an active TS/SCI security clearance w/ CI Poly. Location This is a hybrid position with customer travel in the MD area approximately 1 to 2 times per week. The Main Responsibilities Research attacker tools, techniques, and procedures (TTPs) and contribute to analytic approaches that support automated detection. Work with cyber operators and senior researchers, when requested, to support investigations into cyber threat activity and assist with mitigation guidance. Support automation of investigations through Python scripting, data analysis, and visualization in Jupyter Notebooks and Grafana. Build and maintain collaborative relationships with internal intelligence teams, law enforcement, and outside groups. Support customer RFIs on incidents and emerging threats with guidance from senior team members as needed. Use approved AI‑enabled tools to assist with research, coding, data exploration, documentation, and knowledge discovery while validating outputs through sound analytical judgment. Contribute to repeatable workflows that combine analyst expertise, automation, and AI‑assisted capabilities to improve investigative efficiency and analytical quality. What We Look For In a Candidate Candidates must effectively communicate complex domain‑specific concepts, ensuring clarity for both technical and non‑technical audiences. Familiarity with adversary capabilities, infrastructure, and techniques, with the ability to apply that knowledge in collaboration with supporting teams and partners. Experience using OSINT methods for investigation, including discovering novel threats in malware repositories. Scripting experience with Python and familiarity with large‑scale or distributed data analysis concepts. Experience supporting cyber threat hunting, security investigations, or analysis of suspicious activity using structured data sets. Familiarity with network‑based threats and identifying suspicious behaviors from network telemetry. Strong analytical thinking and ability to quickly pick up new methods, tools and programming languages. Willingness to learn new cyber threat research tradecraft and apply unfamiliar data sources, investigative methods, analytic tools, and AI‑assisted workflows to mission‑focused problems. User‑level experience in a Unix‑based environment. Familiarity with extracting data through SQL. Strong writing skills to assist in documenting findings and sharing knowledge with technical and non‑technical audiences. Demonstrable knowledge of several of the following areas: cybersecurity concepts, network protocols, firewalls, IDS/IPS systems, cyber threat hunting, malware analysis concepts, cyber threat intelligence, common threat actor TTPs, application security concepts, or cloud security fundamentals. Ability to develop proficiency in unfamiliar technical domains through foundational analytical skills, self‑directed learning, and effective use of AI‑assisted research and problem‑solving tools. Ability to use AI‑enabled tools responsibly to support technical research, analysis, coding, documentation, and report development while maintaining professional skepticism and analytical rigor. Ability to review and validate AI‑generated outputs before using them in analysis, findings, or recommendations. Candidates may also have the following preferred skills or experience Previous work experience with Department of Defense (DoD), Intelligence Community, or other government agencies is preferred. Hands‑on experience with Spark, distributed computing, or large‑scale data analysis platforms is preferred. Experience developing automation and analysis in Python‑based environments. Ability to collaborate with peers and senior team members while developing expertise in new technical topics. Exposure to generative AI, AI‑assisted coding, retrieval‑augmented analysis, or agent‑based workflows in cyber research, threat hunting, or intelligence production is preferred. Preferred Familiarity with analyzing NetFlow data to identify unusual patterns and potential security threats. Interest in conducting trend analysis to uncover patterns and emerging threats, enabling proactive defense strategies. Demonstrated curiosity and sound judgment when using AI‑enabled tools in mission‑focused environments while maintaining data protection requirements, analytical integrity, and human accountability for findings and recommendations. Compensation This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors. Location Based Pay Ranges
- 105,786 - $141,047 in these states: AL AR AZ FL GA IA ID IN KS KY LA ME MO MS MT ND NE NM OH OK PA SC SD TN UT VT WI WV WY
- 111,074 - $148,099 in these states: CO HI MI MN NC NH NV OR RI
- 116,364 - $155,152 in these states: AK CA CT DC DE IL MA MD NJ NY TX VA WA
- Lumen Technologies is seeking a Lead Information Security Engineer to advance threat hunting and investigations using our AI-enabled tools and large-scale data platforms. You will work with Black Lotus Labs researchers, data engineers, and security professionals to identify...SuggestedRemote job
$80k - $85k
...deploy globally as a TXP & AXC-GO team member.Understanding of lab processes and workflow for device exploitation efforts.Knowledge... ...global IED devices and Tactics, Techniques, and Procedures (TTP) threat.Experience must include electronic printed circuit board (PCB) assembly...SuggestedFor contractorsWork experience placementRemote work$100k - $110k
...Training.ResponsibilitiesAs a Senior WTI Analyst with AMERICAN SYSTEMS you will have the opportunity... ...closely with the electronic exploitation Lab to create and assign device profiles.#TXP... ...Tactics, Techniques and Procedures (TTP) threat.Experience with collaborating with...SuggestedFor contractorsWork experience placementWork at officeLocal area$160k - $175k
...and science and technology. SPA has a need for an experienced analyst to help lead a long-term study that assesses the vulnerabilities of... ...individual with a demonstrated record of success in assessing threats and vulnerabilities from unmanned systems and developing operational...SuggestedImmediate startFlexible hours- A defense contractor is seeking a Senior All-Source Analyst (Production / Janus/Hard Target) to support USCYBERCOM J2 in the National... ...+ years with a bachelor's degree, alongside knowledge in cyber threat analysis and the ability to work independently. The position offers...SuggestedFor contractors
$150k - $165k
...Job Description Job Description Position Title: Threat Intelligence Lead Location: Camp Springs, MD Employment Type: Full‑Time Salary Range: $150,000 - $165,000 Clearance Requirement: Ability to obtain and maintain Top Secret / SCI Position Overview...Full timeImmediate startFlexible hours- ...Bachelor Degree and 10 years of experience serving as a Business Analyst supporting large scale technology initiatives Min 5 years of... ...be local to the DMV area The Gist… The Business Analyst Lead serves as the primary liaison between business stakeholders, program...Local area
- Information International Associates, Inc. is seeking a Cyber Threat Intelligence (CTI) Lead in Alexandria, VA. This role involves providing technical support to a 24x7 cyber program with responsibilities including the development of CTI analysis and incident response....
- Ventus Solutions (VES) is looking for a Senior Technical Program Analyst in Alexandria, VA. The role involves providing essential technical support to manage the program, liaising with senior government officials, and ensuring compliance with federal standards. The ideal...
- Systems Planning and Analysis, Inc. seeks an experienced analyst to lead a long-term study on the vulnerabilities of U.S. submarines during surfaced operations and to develop robust operational and technical countermeasures. You will coordinate with Navy staff, the IC,...
- Systems Planning & Analysis is seeking a technology-based Wargame Analyst in Alexandria, VA. You will lead the design and execution of complex wargames for government clients, providing strategic insights and contributing to critical decision-making. The ideal candidate...
- BryceTech is seeking an Experimentation Analyst to lead a team conducting DoD experimentation activities for CWMD software capabilities. Based in Alexandria, VA with a hybrid on-site/remote schedule and occasional travel, you will partner with government and industry to...Remote work
- Booz Allen Hamilton is seeking an All-Source Analyst to conduct defense-industries analysis on foreign programs, infrastructure, and capabilities supporting a country’s military. You will produce strategic analyses and briefs for senior policymakers, applying IC/Combatant...
- Radiance Technologies, located in Alexandria, Virginia, is seeking a Signals Intelligence (SIGINT) Analyst to support the U.S. Army Tactical Exploitation of National Capabilities (TENCAP) program. The role includes providing assessments and evaluations on performance and...
$130k - $180k
...and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Lead Cyber Threat Intelligence Analyst Location: Onsite – Government-controlled secure facility Terms: Full-time Salary: $130-$180k DOE...Full timeWork experience placementFlexible hoursShift work- A veteran-owned consulting firm based in Northern Virginia is seeking a Mentor-Protégé Program Analyst to support a federal small business office. The role involves program oversight, stakeholder coordination, and budget tracking. Ideal candidates will have 5-7 years of...Work at office
- Systems Planning and Analysis, Inc. (SPA) is looking for a Wargame Analyst in Alexandria, VA, to lead the design and execution of complex wargames and workshops for government clients. The role requires 7+ years of experience and a Bachelor's degree in a relevant field...
$145k - $160k
...Transparency, and Excellence form the foundation for everything we do. Explore further at Roles and Responsibilities This Lead Salesforce Business Analyst will work to help analyze, define, and document requirements to translate customer needs into Salesforce technology...Contract workWork experience placementWork at officeFlexible hours- Arenatechnologies is seeking a Configuration Management Analyst in Alexandria, Virginia. You will provide crucial configuration management expertise to support Navy and DoD programs, ensuring technical baselines are maintained effectively. Ideal candidates will have a Bachelor...
$115.2k - $155k
...STINGRAI Tech Advisor (Operations Research Analyst 4) - 29231 Location: Fort Washington, MD,... ..., we define how every employee grows, leads, and contributes—regardless of role. It sets... ...mission partners stay ahead of evolving threats by delivering the intelligence,...Full timeWork experience placementWork at officeLocal areaRemote workWorldwide- ...success across complex defense environments. The role produces CONOPS, roadmaps, TTPs, and strategic plans, while integrating policy, threat projections, and intelligence Estimates to ensure plans align with doctrine and requirements. #J-18808-Ljbffr Huntington Ingalls...
- Huntington Ingalls Industries (HII) is seeking a Data Analyst for the STINGRAI program in Fort Washington, MD. The role focuses on delivering... ..., mitigate supply chain risks, and strengthen defenses against threats to IT systems. Top Secret clearance is required and experience...
- Systems Planning and Analysis, Inc. (SPA) seeks an experienced analyst to lead a long-term Navy-focused study on submarine vulnerabilities during surfaced operations and to develop countermeasures. The role requires deep analysis and collaboration with Navy staff, the Intelligence...
- ...acquisition, and science and technology.SPA is seeking a Program Analyst to support NAVSEA's Naval Special Warfare Program Office.... ...and future systems definitions and designs based on projected threats and new technologies, utilizing client systems. Assists the Program...Full timeContract workWork at officeFlexible hours
$103.8k - $218.1k
...Continental US* * *The Opportunity:CACI is seeking a Spectrum Analyst to support Joint Interagency Task Force 401 (JIATF 401). The Spectrum... ...to identify, characterize, and assess electromagnetic threats, optimize spectrum utilization, and provide decision support for...Contract workWork experience placementWork at officeFlexible hours$87.1k - $157.45k
Leidos' Digital sector has frequent opportunities available for SOC Analysts to join our team in Alexandria, VA. We recruit for these... ...organization.Demonstrated understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an...Full timeWork experience placementAll shiftsShift work$130k - $150k
...Support, Engineering & Analysis, and Training.ResponsibilitiesAs an Analyst, Technology Protection, you will have the opportunity to do the... ...Status/Veteran StatusJob SummaryCategory: Security / Intel / Threat AnalysisPosition Type: Full-TimeRemote: NoClearance Required:...For contractors- ...deliver, and sustain new technologiesAnalysis of vulnerabilities and threats to undersea platforms and systemsQuantitative analysis and... ...and their missionsSPA has an immediate need for for a Program Analyst for upcoming support to the Program Executive Office (PEO) for...Full timeContract workFor contractorsCasual workWork at officeImmediate startRemote workFlexible hours
- DescriptionSAIC is hiring a Senior CFIUS-Export Control Analyst to lead our team of qualified, diverse, and highly motivated individuals supporting... ..., influence, cyber penetration, and other exploitation threats to the US technology and manufacturing industrial basesReview...Work at officeLocal area
- Lead Identity and Access Management (IAM) Engineer Job ID 25287 Location Toll Brothers - Fort Washington, Pennsylvania 19034 United States... ...repeatable access management processes. Security Operations & Threat Detection Integrate IAM capabilities with security monitoring,...Full timeWork at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Threat Analyst (Black Lotus Labs). Be the first to apply!
- design analyst Fort Washington, MD
- health program analyst Fort Washington, MD
- recruiting analyst Fort Washington, MD
- hospitality analyst Fort Washington, MD
- manufacturing analyst Fort Washington, MD
- crime analyst Fort Washington, MD
- technology analyst Fort Washington, MD
- defense analyst Fort Washington, MD
- customer experience analyst Fort Washington, MD
- program analyst Fort Washington, MD


