Lead Threat Analyst (Black Lotus Labs)
$105.79k - $141.05kLumen
Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments, and communities.
At Lumen, you’ll work on infrastructure customers rely on today and build for what’s next, where performance, security, and resilience matter.
This is a high accountability environment where bold ideas drive real innovation for our customers, partners, and industry. The work is challenging, expectations are clear, and trust is built into how we operate. If you’re ready to take ownership, deliver meaningful impact, and help shape the future of AI‑ready connectivity, join us today.
The Role
Black Lotus Labs has an opening for a Lead Information Security Engineer who will support threat hunting, investigation, and discovery of evolving malicious activity using Lumen’s unique network visibility, analytic platforms, and approved AI-enabled tools. Our global visibility into one of the world’s largest and most interconnected IP backbones, combined with our computing cluster and analytic platforms, presents exciting opportunities to apply machine learning, graph analytics, automation, and AI-enabled tools to help identify threats across the internet. Black Lotus Labs has detected and disrupted key evolving threats at an internet scale for years.
This position will work alongside Black Lotus Labs advanced security researchers, data engineers, malware reverse engineers, data scientists, and our customers to support investigations into evolving threats using technologies like our Hadoop ecosystem (HBase, HDFS, Spark, Kafka, AirFlow), Elasticsearch and Redis clusters, Docker using Docker Swarm, malware environment, a network of honeypots, and modern AI-assisted research and development capabilities.
This is a close-knit, experienced, amazingly smart team that you can be a part of and help build out. This is a remote/work-from-home opening with requirements for in person collaboration at the customer site as needed in Annapolis Junction, Maryland.
This position requires an active TS/SCI security clearance w/ CI Poly.
Location
This is a remote postion open to candidates based anywhere in the US.
The Main Responsibilities
- Research attacker tools, techniques, and procedures (TTPs) and contribute to analytic approaches that support automated detection.
- Work with cyber operators and senior researchers, when requested, to support investigations into cyber threat activity and assist with mitigation guidance.
- Support automation of investigations through Python scripting, data analysis, and visualization in Jupyter Notebooks and Grafana.
- Build and maintain collaborative relationships with internal intelligence teams, law enforcement, and outside groups.
- Support customer RFIs on incidents and emerging threats with guidance from senior team members as needed.
- Use approved AI-enabled tools to assist with research, coding, data exploration, documentation, and knowledge discovery while validating outputs through sound analytical judgment.
- Contribute to repeatable workflows that combine analyst expertise, automation, and AI-assisted capabilities to improve investigative efficiency and analytical quality.
What We Look For in a Candidate
- Candidates must effectively communicate complex domain-specific concepts, ensuring clarity for both technical and non-technical audiences.
- Familiarity with adversary capabilities, infrastructure, and techniques, with the ability to apply that knowledge in collaboration with supporting teams and partners.
- Experience using OSINT methods for investigation, including discovering novel threats in malware repositories.
- Scripting experience with Python and familiarity with large-scale or distributed data analysis concepts.
- Experience supporting cyber threat hunting, security investigations, or analysis of suspicious activity using structured data sets.
- Familiarity with network-based threats and identifying suspicious behaviors from network telemetry.
- Strong analytical thinking and ability to quickly pick up new methods, tools and programming languages.
- Willingness to learn new cyber threat research tradecraft and apply unfamiliar data sources, investigative methods, analytic tools, and AI-assisted workflows to mission-focused problems.
- User-level experience in a Unix-based environment.
- Familiarity with extracting data through SQL.
- Strong writing skills to assist in documenting findings and sharing knowledge with technical and non-technical audiences.
- Demonstrable knowledge of several of the following areas: cybersecurity concepts, network protocols, firewalls, IDS/IPS systems, cyber threat hunting, malware analysis concepts, cyber threat intelligence, common threat actor TTPs, application security concepts, or cloud security fundamentals.
- Ability to develop proficiency in unfamiliar technical domains through foundational analytical skills, self-directed learning, and effective use of AI-assisted research and problem-solving tools.
- Ability to use AI-enabled tools responsibly to support technical research, analysis, coding, documentation, and report development while maintaining professional skepticism and analytical rigor.
- Ability to review and validate AI-generated outputs before using them in analysis, findings, or recommendations.
Candidates may also have the following preferred skills or experience:
- Previous work experience with Department of Defense (DoD), Intelligence Community, or other government agencies is preferred.
- Hands-on experience with Spark, distributed computing, or large-scale data analysis platforms is preferred.
- Experience developing automation and analysis in Python-based environments.
- Ability to collaborate with peers and senior team members while developing expertise in new technical topics.
- Exposure to generative AI, AI-assisted coding, retrieval-augmented analysis, or agent-based workflows in cyber research, threat hunting, or intelligence production is preferred.
Preferred:
- Familiarity with analyzing NetFlow data to identify unusual patterns and potential security threats.
- Interest in conducting trend analysis to uncover patterns and emerging threats, enabling proactive defense strategies.
- Demonstrated curiosity and sound judgment when using AI-enabled tools in mission-focused environments while maintaining data protection requirements, analytical integrity, and human accountability for findings and recommendations.
Compensation
This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors.
Location Based Pay Ranges
$105,786 - $141,047 in these states: AL AR AZ FL GA IA ID IN KS KY LA ME MO MS MT ND NE NM OH OK PA SC SD TN UT VT WI WV WY $111,074 - $148,099 in these states: CO HI MI MN NC NH NV OR RI $116,364 - $155,152 in these states: AK CA CT DC DE IL MA MD NJ NY TX VA WA
Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. We're able to answer any additional questions you may have about our bonus structure (short-term incentives, long-term incentives and/or sales compensation) as you move through the selection process.
Learn more about Lumen's: Benefits
LI-Remote
Requisition #: 342922
Life at Lumen
Life at Lumen is human and connected, even in a fast moving, AI‑focused organization. We set clear expectations and trust people to meet them. With real support and shared accountability, teams collaborate better, move faster, and deliver meaningful outcomes.
Our Lumen 8 behaviors guide how we interact, make decisions, and work together, shaping a culture built to perform and win.
To learn more about Life at Lumen and how we live the Lumen 8, please visit:
Background Screening
If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. For more information on these checks, please refer to the Post Offer section of our FAQ page . Job-related concerns identified during the background screening may disqualify you from the new position or your current role. Background results will be evaluated on a case-by-case basis.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Equal Employment Opportunities
We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training.
Privacy Notice
Lumen is committed to protecting the privacy and security of personal information collected during the recruitment and hiring process. Our Applicant Privacy Notice explains how we collect, use, disclose, and protect applicant information, as well as how individuals may request access to or deletion of their personal data.
To review Lumen’s Global Employment Applicant and Talent Community Privacy Notice, please visit:
Disclaimer
The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions.
In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Please be advised that Lumen does not require any form of payment from job applicants during the recruitment process. All legitimate job openings will be posted on our official website or communicated through official company email addresses. If you encounter any job offers that request payment in exchange for employment at Lumen, they are not for employment with us, but may relate to another company with a similar name.
- Concentric is seeking a Senior Intelligence Analyst for its Corporate team, offering remote work from... ..., and designing monitoring plans to identify threats to executives and organizations. The successful candidate will lead intelligence processes, collaborate across teams...SuggestedRemote job
$140k - $185k
Circle (NYSE: CRCL) is one of the world’s leading internet financial platform companies,... ...Circle is looking for a Lead KYC Utility Analyst, to join its Compliance Operations team and... ...investigations and continuous monitoring of various threat vectors across the KYC landscape.What you...SuggestedRemote workFlexible hours$115k - $225k
ABOUT MORGAN STANLEYMorgan Stanley is a leading global financial services firm providing a wide range of investment banking, securities... ...scalable technology products.ABOUT THE ROLEThe Lead Business Analyst is a high-impact individual contributor with potential management...SuggestedTemporary workWork at officeLocal areaRemote workWorldwide3 days per week- ...including performance environment. Expertise in troubleshooting defects, checking the logs/error, APIs performance, latency, etc. Leading the defect triage bridge, representing business critical applications, knowledge of function flows. Tools – Splunk, Monitoring Dashboard...Suggested
- EY in the United States is seeking a Threat & Risk Analyst to lead strategic and tactical threat intelligence efforts in partnership with Global Security and Regional Security teams, focusing on the Americas. The role collects, assesses and reports intelligence to help...Suggested
- Lead Analyst - Applied Marketing Analytics Full-time Annik is a global data and analytics solutions company helping businesses leverage their data assets to deliver tangible business value. We work with businesses across the globe and industries to help them achieve success...Full timeVisa sponsorshipWork visa
$80k - $90k
...experience to a new industry, join our team as we help shape a brighter way forward. What this job involves We are looking for a Deal Analyst Team Lead to join our Brokerage Operations team and serve as a team lead. This person will operate as a player coach, managing a team of...Daily paidWork experience placementWork at officeLocal area- Blue Origin is seeking a Lead Fluids Analyst to support the TVS development for the MK2 Crewed Lander in NASA's Artemis & HLS programs. You will generate thermo-fluids models of cryogenic propellants and collaborate with NASA and National Team partners to advance in-space...
- SSA Marine in Seattle is seeking a Senior HRIS Analyst to design and optimize HRIS solutions across various modules. This role involves partnering with multiple teams including HR, Payroll, and Finance to ensure the systems are scalable and compliant. The ideal candidate...
$145.19k - $203.26k
Blue Origin LLC is seeking a Sr. Structural Analyst to lead the structural analysis for their Lunar Permanence business unit, focused on Blue Moon landers. Responsibilities include developing finite element models and conducting structural assessments to ensure mission...- Blue Origin is seeking a Lead Fluids Analyst to support the Thermodynamic Vent System on the MK2 Crewed Lander for NASA's Artemis and HLS programs. You will oversee thermo-fluids modeling and verification from concept through build, test, and on-console operation, collaborating...
- Blue Origin is hiring a Senior Structural Analyst to lead advanced structural analyses for the New Glenn second stage. You will develop and validate analytical models, perform FEM and hand calculations, and guide junior analysts to ensure safe, weight-optimized designs....
$150k - $225k
Structures & Mechanisms Lead Cowboy Space Corp. is building the infrastructure to power and connect the orbital economy. Our satellites operate in Low Earth Orbit to collect sunlight and enable a new class of capabilities—from powering on-orbit compute, to transmitting...Permanent employmentWork at officeLocal areaRelocation package- Blue Origin in Washington state is seeking a senior structural analyst to lead advanced structural analyses for aerospace components and systems in the New Glenn program. You will apply hand calculations and FEM to evaluate environments, optimize weight, and help ensure...
- Liquidhub Inc is looking for a Lead Analyst - Applied Marketing Analytics in Bellevue, Washington. The successful candidate will strong experience in business analytics and SQL to generate actionable insights, supporting marketing teams through data-driven decision making...
$147.9k - $200.1k
...that enable our customers, businesses, and the world to become more sustainable. The Industry Relations team is seeking a Senior Lead, Analyst Relations (AR) to own the AR program for Amazon Sustainability, working cross-functionally with AWS, Devices, Operations, Retail...WorldwideFlexible hours- Essnova Solutions, Inc. is seeking a Principal FOIA Analyst to ensure compliance with federal FOIA requirements in Washington, United States. This position involves processing FOIA requests, coordinating with legal counsel, and maintaining compliance with documentation...
- Carnival Corporation & plc is seeking a Senior Benefits Analyst to manage ADA interactive processes and all North American leave programs. You will act as the SME for accommodations, FMLA, PWFA, and local laws, coordinating with HR, Legal, payroll, and external vendors...Work at officeLocal area
- ...meeting project deliverables with excellence. Opportunity Projé has an exciting opportunity for a full-time Lead HealthRules Payer (HRP) Configuration Analyst. The Lead HRP Configuration Analyst will play an essential role in our clients’ HealthRules Payer Implementation...Full timeFlexible hours
- An established industry player is seeking a skilled Security Operations Center (SOC) Analyst to join their dynamic team. This role requires expertise in maintaining a highly available operational environment, strong analytical capabilities, and effective communication skills...
$150k - $180k
...what consumers represent good credit risks. Your job is to find both sides of the story and make changes actionable. As our Lead Data Analyst for Product Analytics, you'll own how we measure product performance across Updater's product lines — from our consumer Moving...Full timeTemporary workFlexible hoursDay shift- Shoreline Community College is seeking an HR Information System Analyst in Human Resources. The role leads HRIS initiatives, partners with HR, Payroll, Benefits, Finance, Operations, and IT to ensure scalable, compliant systems and actionable reporting. Strong analytic...Remote job
- .... Please go through the Job Description. Send me your updated resume and expected rate for the below position. Job Title: Lead Management Analyst Location: Seattle, WA Duration: 6 months The team is seeking a strong Lead Management support vendor focused on the enterprise...
$116k - $145k
Job Summary Lead Analyst - Technology Strategy, Planning & Risk Location: Chicago, California, New York, Washington Division: Ticketmaster NA Line Manager: Senior Director - Technology Strategy Contract Terms: Full Time The Team The Technology Strategy, Planning & Risk...Full timeContract workLocal areaFlexible hours- A prominent consulting firm in Seattle is looking for a Principal Business Analyst. This high-impact role involves working independently to develop tech solutions supporting business transformations. The ideal candidate will have strong domain knowledge in asset management...
$70 - $95 per hour
A nationwide IT consulting firm is looking for a senior Consultant - Threat Detection Engineer to lead insider threat analysis and privileged access assessments. You will investigate complex data environments, produce actionable recommendations, and work independently while...Remote jobHourly payTemporary work- Nordstrom is seeking a Data Analyst 3 to lead Store Operations analytics, owning data governance and a modern Looker reporting suite. You will collaborate with business, data, and tech partners across Nordstrom, applying AI tools to accelerate development and validate data...
- Palo Alto Networks in Seattle is seeking a security engineer to lead threat research and detection strategy for agentic AI systems. You will model the threat surface across the full agentic stack and translate research into production scanning capabilities, owning the services...
- University of Washington Heart Institute (Montlake) is seeking a Lab Supervisor for the ECG Lab. You will lead daily operations, oversee ECG procedures, and ensure high-quality patient care within the Montlake campus. The role requires experience as an ECG Technician 2,...
- A global talent acquisition firm seeks a Lead Management Analyst to support enterprise connectivity sales in Seattle. The role involves managing leads and drafting proposals based on existing templates. Required skills include strong experience with Microsoft sales systems...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Threat Analyst (Black Lotus Labs). Be the first to apply!
- review analyst Seattle, WA
- operational due diligence analyst Seattle, WA
- design analyst Seattle, WA
- health program analyst Seattle, WA
- recruiting analyst Seattle, WA
- corporate actions analyst Seattle, WA
- security operations center soc analyst Seattle, WA
- hospitality analyst Seattle, WA
- collection analyst Seattle, WA
- legislative analyst Seattle, WA


