LEAD INFORMATION SECURITY ENGINEER (Remote, US)

🏢 CenturyLink · all 105 jobs
📍 United States
💰 USD 105,786 - 155,152 / annual
📅 Posted Sep 18, 2026 · via Himalayas
🏷 Information Security Engineering, Cybersecurity, Incident Response, Security Operations, Network Security, Lead Information Security Engineer +6 more
Apply on original site ↗

Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments, and communities.

At Lumen, you’ll work on infrastructure customers rely on today and build for what’s next, where performance, security, and resilience matter.

This is a high accountability environment where bold ideas drive real innovation for our customers, partners, and industry. The work is challenging, expectations are clear, and trust is built into how we operate. If you’re ready to take ownership, deliver meaningful impact, and help shape the future of AI‑ready connectivity, join us today.

The Role

Cybersecurity Incident Response Team (CIRT) Engineers at Lumen are on the front lines of protecting the systems that power global connectivity. In this role, you’ll respond to and mitigate cybersecurity threats while proactively identifying risks and strengthening our defenses.

At Lumen, this work goes beyond incident response, it’s an opportunity to solve complex problems, influence how we defend at scale, and help shape the future of our security capabilities. You’ll collaborate with internal teams and partners to drive innovation, improve detection, and anticipate emerging threats in a fast-paced, high-accountability environment.
If you’re motivated by challenging work, continuous learning, and the chance to make a real impact, this role offers the flexibility, trust, and support to help you grow while contributing to meaningful outcomes across our infrastructure and services.

Location

This is a remote opportunity open to candidates located anywhere in the U.S..

The Main Responsibilities

- Respond to, remediate, and document information security incidents not limited to dashboard (Advanced Threat Appliance & SIEM) alerts, tickets, emails, or phone calls.

- Actively hunt the enterprise for insecure, suspicious, or malicious activity.

- Review data that is processed within the SIEM to find incident evidence and suspicious events as well as out of scope events.

- Verify and validate security notifications from both internal and external sources.

- Identify and resolve incidents that are not defined by (or deviate from) an existing incident response guide.

- Assist with significant incidents as needed or assigned, including outside of normal business hours.

- Provide feedback for development and consistency of automated threat detection mechanisms.

- Update and maintain response guides for accuracy.

- Support Security projects to improve Cyber Defense Team or Lumen's security posture.

- Participate in on-call support for incident response needs

- Demonstrate effective communication skills, both verbal and written

What We Look For in a Candidate

- Bachelor’s in Computer Science, Engineering, or related field (or equivalent experience)

- Strong understanding of security fundamentals: host/network hardening, networking protocols, intrusion techniques, and risk management

- Analytical/problem-solving skills across networking, operating systems, and malware analysis

- Relevant certifications (or willingness to obtain): Security+, CEH, OSCP, GCIH, CISSP, GPEN, GWAPT, GISEC, CISM, or CISA

- U.S.-based and able to obtain government suitability

- Strong communication skills; able to present technical concepts to both technical and non-technical audiences

- Experience with cloud security (AWS, Azure, GCP)

- Broad knowledge of current and emerging technologies

- Preferred Qualifications:

- 6+ years in incident response, forensics, risk assessments, application or network security

- Experience in network/firewall engineering, design, and implementation

- Familiarity with security tools (SIEM, IDS/IPS, endpoint protection)

- Experience monitoring threats and performing initial triage

- Microsoft or UNIX/Linux administration

-

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Want more like this? Browse every live remote developer role.All remote developer jobs →
Get new developer jobs by email
Daily email, only when there's something new. One click to stop.

Get remote developer jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you