Principal Information Security Engineer

Company Name: CenturyLink

Location: Remote, US

Job Duration: 2024-12-06 to 2025-01-05

Overview

About Lumen

Lumen connects the world. We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture and company from the people up – committed to teamwork, trust and transparency. People power progress.

Lumen’s commitment to workplace inclusion and employee support shines bright. We’ve made the Newsweek 2024 Greatest Workplaces for Diversity list and achieved a perfect score of 100 on the Human Rights Campaign Corporate Equality Index (CEI) for the fifth consecutive year. Plus, we’re the top employer in the communications and telecom industry, ranking 12th overall across all industries in The American Opportunity Index.

We’re looking for top-tier talent and offer the flexibility you need to thrive and deliver lasting impact. Join us as we digitally connect the world and shape the future.

The Role

Black Lotus Labs has an opening for a Principal Information Security Engineer. The Black Lotus Labs team utilizes our unique visibility to hunt advanced threats and discover new malicious activities facing our customers. Our unique data sets present exciting opportunities to utilize Machine Learning and Graph analytic techniques as we find new ways to hunt for threats.
 

 

The Main Responsibilities

  • Lead technical delivery of threat intelligence services on Black Lotus Labs Federal Programs as well as manage a small team of technical staff also delivering on Black Lotus Labs customer engagements, addressing current challenges and anticipating future threat visibility and defense needs. 
  • Serve as touch point and team lead for multiple Black Lotus Labs customer engagements to include managing contract deliverables and assessing scope, as well as developing and delivering on growth strategies. 
  • Oversee teams’ collection, analysis, production, and dissemination of actionable cyber threat intelligence.
  • Ensure project delivery and program growth by coordinating with stakeholders across Lumen including with finance, contracts, PMO, legal, and engineering. 
  • Serve as a people leader for a small group of direct reports.
  • This position provides opportunities to mentor junior analysts, enhance team skillsets, and stay abreast of the latest cyber threat trends.
  • Individually on client work and as a team lead: 
  • Provide timely and actionable intelligence to support customer intelligence requirements.
  • Research latest threat attacker tools, techniques and procedures (TTPs) with a goal of automating detection on behalf of customers. 
  • Leverage global datasets (netflow, malware, passive DNS, etc) to track malicious cyber actors, their infrastructure and campaigns.
  • Collaborate with a global team of threat intelligence analysts to analyze and develop coverage for emerging threats.
  • Contribute to the development of tactical solutions to support triage and deep-dive analysis of malicious artifacts surfaced by internal and external partners.

What We Look For in a Candidate

  • Experience leading a team in a dynamic, client-driven environment, addressing current challenges and anticipating future threat visibility and defense needs. Develop strategy and mentor team members. 
  • Skilled in translating customer requirements into research and project deliveries as per contracts. Possesses deep technical expertise in adversary capabilities, infrastructure, and techniques to develop methods for detecting and tracking current threats and predicting future attacks.
  • Experience prototyping capabilities in customer environments, taking feedback to tailor the delivery, and scoping capability into future work products. 
  • Collaboration across disciplines to scope, define, and deliver customer-facing work. 
  • Experience using OSINT methods for investigation, including discovering novel threats in malware repositories.
  • Scripting experience with Python and familiarity with distributed computing.
  • Extensive experience hunting threat actors and developing algorithms and techniques to identify new threats from large data sets.
  • Deep knowledge of network-based threats and identifying behaviors without attack payloads.
  • TS/SCI w/ Poly clearance
     

 

Legal Statements

In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.

Compensation

<div ccp_infra_copy_id=”8ad12d87-144f-4440-b4c3-26c6e36a4681″ ccp_infra_timestamp=”1732577793716″ ccp_infra_user_hash=”3171210372″ ccp_infra_version=”3″ data-ccp-timestamp=”1732577793716″> 
The starting salary for this role differs based on the employee’s primary work location. Employees typically do not start at the top of the range, though compensation depends on each individual’s qualifications.

Location Based Pay Ranges

$128,310 – $171,080 in these states: AR  ID  KY  LA  ME  MS  NE  SC  SD 
$135,060 – $180,080 in these states: AL  AZ  FL  GA  IA  IN  KS  MO  MT  ND  NM  OH  OK  PA  TN  UT  VT  WI  WV  WY 
$141,820 – $189,090 in these states: CO  HI  MI  MN  NC  NH  NV  OR  RI 
$148,570 – $198,090 in these states: AK  CA  CT  DC  DE  IL  MA  MD  NJ  NY  TX  VA  WA 

As with the pay range variety that’s based on the region of a country, specific offers are determined by various factors such as experience, education, skills, certifications and other business needs.

Requisition #: 336020

Background Screening

If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. For more information on these checks, please refer to the Post Offer section of our FAQ page. Job-related concerns identified during the background screening may disqualify you from the new position or your current role. Background results will be evaluated on a case-by-case basis.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Equal Employment Opportunities

We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training.

Disclaimer

The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions.