Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Lead Threat Analyst (Black Lotus Labs)

$132.23k - $176.31k
Full-time

Lumen

Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments, and communities.

At Lumen, you’ll work on infrastructure customers rely on today and build for what’s next, where performance, security, and resilience matter.

This is a high accountability environment where bold ideas drive real innovation for our customers, partners, and industry. The work is challenging, expectations are clear, and trust is built into how we operate. If you’re ready to take ownership, deliver meaningful impact, and help shape the future of AI‑ready connectivity, join us today.

The Role

Black Lotus Labs has an opening for a Senior Lead Security Engineer that will leverage Lumen’s unique visibility to hunt, investigate, and scale discovery of evolving malicious threats, provide mission-relevant intelligence, and support mitigations on large networks. Our global visibility into one of the world’s largest and most interconnected IP backbones, combined with our computing cluster and analytic platforms, presents exciting opportunities to integrate machine learning, graph analytics, automation, and approved AI-enabled tools as we find new ways to hunt for threats across the internet. Black Lotus Labs has detected and disrupted key evolving threats at an internet scale for years.

This position will work alongside Black Lotus Labs advanced security researchers, data engineers, malware reverse engineers, data scientists, and our customers to tackle evolving threats accelerated by technologies like our Hadoop ecosystem (HBase, HDFS, Spark, Kafka, AirFlow), Elasticsearch and Redis clusters, Docker using Docker Swarm, malware environment, a network of honeypots, and modern AI-assisted research and development capabilities.

This is a close-knit, experienced, amazingly smart team that you can be a part of and help build out.

This position requires an active TS/SCI security clearance w/ CI Poly.

Location

This is a remote position with office visits in Herndon, VA approximately 2 times per month.

The Main Responsibilities

  • Research latest threat attacker tools, techniques, and procedures (TTPs) with a goal of automating detection.
  • Work with cyber operators, when requested, to conduct in-depth investigations on cyber threat activity and provide mitigation guidance.
  • Automate investigations through Python scripting and data analysis using visualization in Jupyter Notebooks and Grafana
  • Build and maintain trust relationships with other intelligence teams, law enforcement, and other outside groups.
  • Support customer RFIs on incidents and emerging threats.
  • Use approved AI-enabled tools to accelerate research, coding, data exploration, documentation, and knowledge discovery while validating outputs through independent analytical judgment.
  • Develop repeatable workflows that combine analyst expertise, automation, and AI-assisted capabilities to improve investigative efficiency and analytical quality.

What We Look For in a Candidate

  • Candidates must effectively communicate complex domain-specific concepts, ensuring clarity for both technical and non-technical audiences.
  • Familiarity with adversary capabilities, infrastructure, and techniques that can be applied in collaboration with supporting teams and partners to discover, track, and defend against the adversaries aggression towards customer networks.
  • Experience using OSINT methods for investigation, including discovering novel threats in malware repositories.
  • Scripting experience with Python and familiarity with distributed computing.
  • Extensive experience hunting threat actors and developing algorithms and techniques to identify new threats from large data sets.
  • Deep knowledge of network-based threats and identifying behaviors without attack payloads.
  • Strong analytical thinking and ability to quickly pick up new methods, tools and programming languages.
  • User-level experience in a Unix-based environment.
  • Familiarity with extracting data through SQL.
  • Strong writing skills to assist in sharing our knowledge with the public.
  • Demonstrable knowledge of several of the following areas: cybersecurity concepts, network protocols, firewalls, IDS/IPS systems, cyber threat hunting, malware analysis tools and techniques, cyber threat intelligence, common threat actor TTPs, application security concepts, cloud security fundamentals.
  • Ability to rapidly develop proficiency in unfamiliar technical domains through foundational analytical skills, self-directed learning, and effective use of AI-assisted research and problem-solving tools.
  • Ability to use AI-enabled tools responsibly to augment technical research, analysis, coding, documentation, and report development while maintaining professional skepticism and analytical rigor.
  • Ability to evaluate, challenge, and validate AI-generated outputs before using them in customer-facing analysis, findings, or recommendations.

Well experienced candidates may also have the following skills:

  • Previous work experience with Department of Defense (DoD), Intelligence Community, or other government agencies (e.g., DHS, DOE, VA, etc.)
  • Experience with Spark and distributed computing
  • Experience developing automation and analysis in Python-based environments.
  • Ability to work with others in providing direction and assisting in learning new topics.
  • Experience using generative AI, AI-assisted coding, retrieval-augmented analysis, or agent-based workflows in cyber research, threat hunting, or intelligence production.

Preferred :

  • Proficient in analyzing NetFlow data to identify unusual patterns and potential security threats.
  • Interest in conducting trend analysis to uncover patterns and emerging threats, enabling proactive defense strategies.
  • Demonstrated ability to responsibly leverage AI-enabled tools within a regulated or mission-focused environment while maintaining data protection requirements, analytical integrity, and human accountability for findings and recommendations

Compensation

This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors.

Location Based Pay Ranges

$132,232 - $176,310 in these states: AL AR AZ FL GA IA ID IN KS KY LA ME MO MS MT ND NE NM OH OK PA SC SD TN UT VT WI WV WY $138,844 - $185,124 in these states: CO HI MI MN NC NH NV OR RI $145,456 - $193,940 in these states: AK CA CT DC DE IL MA MD NJ NY TX VA WA

Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. We're able to answer any additional questions you may have about our bonus structure (short-term incentives, long-term incentives and/or sales compensation) as you move through the selection process.

Learn more about Lumen's:

LI-Remote

What to Expect Next

Requisition #: 343089

Life at Lumen

Life at Lumen is human and connected, even in a fast moving, AI‑focused organization. We set clear expectations and trust people to meet them. With real support and shared accountability, teams collaborate better, move faster, and deliver meaningful outcomes.

Our Lumen 8 behaviors guide how we interact, make decisions, and work together, shaping a culture built to perform and win.

To learn more about Life at Lumen and how we live the Lumen 8, please visit:

Background Screening

If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. For more information on these checks, please refer to the Post Offer section of our FAQ page . Job-related concerns identified during the background screening may disqualify you from the new position or your current role. Background results will be evaluated on a case-by-case basis.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Equal Employment Opportunities

We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training.

Privacy Notice

Lumen is committed to protecting the privacy and security of personal information collected during the recruitment and hiring process. Our Applicant Privacy Notice explains how we collect, use, disclose, and protect applicant information, as well as how individuals may request access to or deletion of their personal data.

To review Lumen’s Global Employment Applicant and Talent Community Privacy Notice, please visit:

Disclaimer

The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions.

In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.

Please be advised that Lumen does not require any form of payment from job applicants during the recruitment process. All legitimate job openings will be posted on our official website or communicated through official company email addresses. If you encounter any job offers that request payment in exchange for employment at Lumen, they are not for employment with us, but may relate to another company with a similar name.

Vacancy posted 4 hours ago
Similar jobs that could be interesting for youBased on the Senior Lead Threat Analyst (Black Lotus Labs) in Annandale, VA vacancy
  • $105.79k - $141.05k

     ...us today. The Role Black Lotus Labs has an opening for a Lead Information Security Engineer who will support threat hunting, investigation, and...  ...with cyber operators and senior researchers, when requested...  ...repeatable workflows that combine analyst expertise, automation, and... 
    Suggested
    Full time
    Temporary work
    Work experience placement
    Remote work
    Work from home

    Lumen

    Annandale, VA
    3 days ago
  • Anduril Industries is a defense tech company seeking a Senior SecOps Analyst to monitor and respond to threats across endpoints, cloud, and SaaS. You’ll develop...  ...detection signatures, participate in threat modeling, and lead incident response as needed. As part of the... 
    Senior

    Slope

    Washington DC
    1 day ago
  •  ...Koniag Government Services company, seeks a Senior Security Operations Center Analyst to support SBA’s enterprise security operations...  ...Washington, DC. The role emphasizes expert threat detection, incident analysis, and leading response efforts within a federal government... 
    Senior

    Koniag Services, Inc.

    Washington DC
    4 days ago
  • CALIBRE Systems, Inc. is seeking a Senior Information Security Analyst to support a DoD client with enterprise cybersecurity for a large program...  ..., VA and an active Secret clearance. The position leads RMF/eMASS, threat detection, vulnerability management, incident... 
    Senior

    CALIBRE

    Washington DC
    2 days ago
  • $77k - $99k

    GeoSearch in Fairfax, VA is seeking a Geospatial Analyst III to work hands-on with spatial data, analysis, and Esri technologies to support...  ...pay range of $77K to $99K annually, with opportunities to lead GIS projects and mentor junior staff. #J-18808-Ljbffr GeoSearch
    Senior
    Work at office
    Local area

    Geosearch

    Fairfax, VA
    4 days ago
  • Leidos is seeking a Senior-Level Supply Chain Risk Management Analyst to provide advanced technical and analytical support to the FAA’s CI SCRM program. This...  ...leader within a small team. You will translate threat data into risk scores, develop executive dashboards for... 
    Senior
    Contract work

    Via Logic LLC

    Washington DC
    2 days ago
  •  ...Joint Venture LLC is seeking a proactive IR Analyst based in Washington, DC, to monitor,...  ...contain, and recover from sophisticated threats targeting TikTok's US operations. You will...  ...incident analysis. Responsibilities include leading technical response actions, performing... 

    TikTok USDS Joint Venture

    Washington DC
    3 days ago
  • $131.3k - $237.35k

    Leidos Inc is seeking a Senior Incident Response Analyst to join their team in Arlington, Virginia. The role involves coordinating incident response efforts, analyzing cyber threats, and developing security protocols for the Department of Homeland Security's CISA Program... 
    Senior

    Leidos

    Arlington, VA
    5 days ago
  • Terrestris Global Solutions in Washington, DC is seeking a Senior Security Operations Analyst to monitor and respond to cybersecurity threats. The candidate will analyze security events, manage incident response, and support the National Indian Gaming Commission's cybersecurity... 
    Senior

    Terrestris Global Solutions

    Washington DC
    5 days ago
  • $100k - $120k

    SkyePoint Decisions, Inc. is seeking a Mobile Threat Analyst in Arlington, VA, to support the Diplomatic Security Cyber Mission. The role involves conducting forensic examinations of mobile devices and analyzing malicious behavior within applications. Candidates should... 
    Senior
    Flexible hours

    SkyePoint Decisions

    Arlington, VA
    3 days ago
  • LexisNexis Risk Solutions is seeking a Senior Investigative Analyst to support a dedicated federal government customer. You will conduct open-source investigations, evaluate threats, and provide real-time intelligence updates. The role requires joining a multidisciplinary... 
    Senior

    LexisNexis Risk Solutions

    Washington DC
    5 days ago
  • American University in Washington, DC, seeks a Senior Police Investigator to lead complex investigations, supervise junior officers, and coordinate multi...  ...AVP of University Police Services, this role emphasizes threat assessments, crime analysis, and compliance with the... 
    Senior
    Full time

    American University

    Washington DC
    1 day ago
  • Peraton is seeking a Mobile Threat Analyst based in Arlington, VA. The role involves conducting forensic examinations of mobile devices, analyzing mobile applications for threats, and assessing cybersecurity environments to bolster U.S. missions globally. Candidates should... 
    Senior
    Full time

    Peraton

    Arlington, VA
    5 days ago
  • $104k - $166k

    Peraton in Arlington, VA is seeking a Mobile Threat Analyst to conduct forensic examinations of mobile devices and analyze mobile applications for threats. The ideal candidate will have a Bachelor’s degree and relevant experience, possess cybersecurity certifications,... 
    Senior

    Peraton

    Arlington, VA
    1 day ago
  • A defense contractor is seeking a Senior All-Source Analyst (Production / Janus/Hard Target) to support USCYBERCOM J2 in the National Capital Region...  ...with a bachelor's degree, alongside knowledge in cyber threat analysis and the ability to work independently. The position... 
    Senior
    For contractors

    Kinsley Power Systems

    Alexandria, VA
    4 days ago
  • Blue Rose Consulting Group, Inc. is seeking candidates for a role focused on SIEM administration and threat monitoring. Applicants should have over 3 years of relevant experience and be familiar with OSINT monitoring and digital forensics. The position requires at least... 
    Senior
    Contract work

    Blue Rose Consulting Group

    Washington DC
    1 day ago
  • cFocus Software Incorporated is seeking a Cyber Threat Intelligence & Threat Hunting Lead to oversee CTI, detection engineering, and proactive threat hunting operations supporting enterprise cyber defense missions. The Lead will drive development of intelligence-driven... 
    Senior

    cFocus Software Incorporated

    Washington DC
    4 days ago
  •  ...Defense Group, LLC in Arlington, VA, is seeking a mid-level OSINT analyst to review packages for submission requirements and provide...  ...corrections and status inquiries. The role involves producing Threat Information Reports and all-source research to inform defense intelligence... 
    Senior

    Patriot Defense Group, LLC

    Arlington, VA
    2 days ago
  • Anduril Industries is seeking a Senior SecOps Analyst to monitor and respond to threats across endpoints, cloud infrastructure, and SaaS. You will lead detection development, runbooks, and automation efforts while serving as incident commander for critical events. You will... 
    Senior

    Anduril-1

    Washington DC
    3 days ago
  • Anduril Industries is seeking a Senior SecOps Analyst to monitor, detect, and respond to threats across endpoints, cloud, and networks. You’ll lead incident responses and drive detection improvements with engineering teams. You will conduct threat hunting, model threats... 
    Senior

    Anduril Industries

    Washington DC
    2 days ago
  • $156.5k - $191.2k

     ...Title: Threat Analyst - Senior Belong. Connect. Grow. with KBR! KBR's National Security Solutions team provides high-end engineering and...  ...contract award KBR is seeking a Threat Analyst - Senior to lead advanced analysis and assessment of potential threats to... 
    Senior
    Full time
    Contract work
    Temporary work
    Local area
    Relocation package

    KBR

    Springfield, VA
    25 days ago
  • Peraton is seeking a Cyber Threat Briefer for Global Threat Analysis (GTA) in Rosslyn, VA. The role centers on developing and delivering...  ...regional threats, track adversaries, and present findings to senior leadership in clear, actionable terms. This is an on‑site, full‑... 
    Senior
    Full time

    Peraton

    Arlington, VA
    2 days ago
  • $125k - $140k

     ...and personal lives.Position OverviewQinetiQ US is looking for a Senior Analyst / Portfolio Manager to work in Falls Church, VA. This position...  ...reviews, reports, briefs, etc).Collaborate with government labs, the Services, academia, and industry as required to ensure successful... 
    Senior
    Work experience placement
    Work at office

    QinetiQ

    Falls Church, VA
    2 days ago
  • Celestar, a B&A Company, is seeking a Counterintelligence (CI) Senior Analyst to support the Defense Advanced Research Projects Agency (...  ...rewarding and impactful opportunity. Responsibilities include leading and mentoring CI Analysts, planning analytical projects, researching... 
    Senior

    Kinsley Power Systems

    Arlington, VA
    4 days ago
  • $140k - $190k

    Celestar Corporation seeks a Counterintelligence (CI) Senior Analyst to support the DARPA Program Security Services (PSS) program in Arlington, VA. The role requires active TS/SCI clearance, leadership of CI analysts, and deep experience in intelligence protection and... 
    Senior

    Celestar Holdings Corporation

    Arlington, VA
    4 days ago
  • Systems Planning & Analysis in Arlington, VA, is seeking a Sr. Operations Research Analyst to support joint missile defense simulation and analysis at the Pentagon. This role includes leading a team in high-profile, classified environments to provide insightful... 
    Senior

    Systems Planning & Analysis

    Arlington, VA
    4 days ago
  • Systems Planning & Analysis is seeking a technology-based Wargame Analyst in Alexandria, VA. You will lead the design and execution of complex wargames for government clients, providing strategic insights and contributing to critical decision-making. The ideal candidate... 
    Senior

    Systems Planning & Analysis

    Alexandria, VA
    3 days ago
  • Systems Planning and Analysis, Inc. seeks a Program Analyst Lead to provide onsite support for DARPA in Arlington, VA. The role requires...  ...risks, coordinate meetings, and draft critical briefings for senior leadership. Responsibilities include monitoring progress, assisting... 
    Senior

    Systems Planning and Analysis, Inc.

    Arlington, VA
    4 days ago
  • Tactica Solutions LLC in Fort Belvoir, VA seeks a Program Analyst III to lead manpower studies and force management initiatives for INSCOM, G-3 FM, ensuring operational effectiveness of Echelon Above Corps units through structured analysis and coordinated staff work. You... 
    Senior

    Galapagos Federal Systems

    Fort Belvoir, VA
    5 days ago
  • A leading IT services company in Washington, DC is seeking two Senior/Intermediate Analysts (Team Leads) to manage FOIA requests and Privacy compliance. Responsibilities include acting as On-Site Supervisors, reviewing requests, ensuring timely completion of tasks, and... 
    Senior

    Constellation West

    Washington DC
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Lead Threat Analyst (Black Lotus Labs). Be the first to apply!