LEAD INFORMATION SECURITY ENGINEER (Remote, US)
Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments, and communities.
At Lumen, you’ll work on infrastructure customers rely on today and build for what’s next, where performance, security, and resilience matter.
This is a high accountability environment where bold ideas drive real innovation for our customers, partners, and industry. The work is challenging, expectations are clear, and trust is built into how we operate. If you’re ready to take ownership, deliver meaningful impact, and help shape the future of AI‑ready connectivity, join us today.
The Role
Cybersecurity Incident Response Team (CIRT) Engineers at Lumen are on the front lines of protecting the systems that power global connectivity. In this role, you’ll respond to and mitigate cybersecurity threats while proactively identifying risks and strengthening our defenses.
At Lumen, this work goes beyond incident response, it’s an opportunity to solve complex problems, influence how we defend at scale, and help shape the future of our security capabilities. You’ll collaborate with internal teams and partners to drive innovation, improve detection, and anticipate emerging threats in a fast-paced, high-accountability environment.
If you’re motivated by challenging work, continuous learning, and the chance to make a real impact, this role offers the flexibility, trust, and support to help you grow while contributing to meaningful outcomes across our infrastructure and services.
Location
This is a remote opportunity open to candidates located anywhere in the U.S..
The Main Responsibilities
- Respond to, remediate, and document information security incidents not limited to dashboard (Advanced Threat Appliance & SIEM) alerts, tickets, emails, or phone calls.
- Actively hunt the enterprise for insecure, suspicious, or malicious activity.
- Review data that is processed within the SIEM to find incident evidence and suspicious events as well as out of scope events.
- Verify and validate security notifications from both internal and external sources.
- Identify and resolve incidents that are not defined by (or deviate from) an existing incident response guide.
- Assist with significant incidents as needed or assigned, including outside of normal business hours.
- Provide feedback for development and consistency of automated threat detection mechanisms.
- Update and maintain response guides for accuracy.
- Support Security projects to improve Cyber Defense Team or Lumen's security posture.
- Participate in on-call support for incident response needs
- Demonstrate effective communication skills, both verbal and written
What We Look For in a Candidate
- Bachelor’s in Computer Science, Engineering, or related field (or equivalent experience)
- Strong understanding of security fundamentals: host/network hardening, networking protocols, intrusion techniques, and risk management
- Analytical/problem-solving skills across networking, operating systems, and malware analysis
- Relevant certifications (or willingness to obtain): Security+, CEH, OSCP, GCIH, CISSP, GPEN, GWAPT, GISEC, CISM, or CISA
- U.S.-based and able to obtain government suitability
- Strong communication skills; able to present technical concepts to both technical and non-technical audiences
- Experience with cloud security (AWS, Azure, GCP)
- Broad knowledge of current and emerging technologies
- Preferred Qualifications:
- 6+ years in incident response, forensics, risk assessments, application or network security
- Experience in network/firewall engineering, design, and implementation
- Familiarity with security tools (SIEM, IDS/IPS, endpoint protection)
- Experience monitoring threats and performing initial triage
- Microsoft or UNIX/Linux administration
-
This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.
Compare flights and hotels →Get remote developer jobs like this by email
10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.
Similar for you
Get 10 hand-picked remote jobs like this one in your inbox every morning. One email a day, matched to what you browse. No spam, one-click unsubscribe.
No thanks — continue to the application ↗