Jobs Companies Lowe's Sr Analyst, Information Security

Über diese Sr Analyst, Information Security Stelle bei Lowe's

Lowe's · Vor Ort · Lowe's Charlotte Technology Hub 3505

Innovate in Charlotte

Thank you for dedicating your time and talent to Lowe’s.  We want to give you more opportunities to learn and grow, so if you find a position you’re interested in below, we encourage you to apply!

Job Description Summary
 
The Offensive Security Team is seeking a highly skilled Red Team Operator to help plan and execute authorized, threat-informed offensive security operations across Lowe’s enterprise, cloud, identity, endpoint, and retail technology environments. This role will focus on realistic adversary emulation, initial access, C2 infrastructure, operational security, endpoint telemetry, evasion research, Active Directory, cloud identity, and offensive tooling.

The ideal candidate is a disciplined offensive security professional who can safely emulate modern adversary behavior, identify meaningful attack paths, and translate findings into actionable improvements for detection engineering, security operations, incident response, infrastructure, cloud, and identity teams. This role requires strong technical depth, sound judgment, clear communication, and the ability to operate ethically and professionally in sensitive environments.

This position will play a key role in strengthening Lowe’s ability to prevent, detect, respond to, and recover from advanced cyber threats while helping improve the company’s overall security posture through red team operations, purple team collaboration, control validation, and executive-ready reporting.
 

Key Responsibilities

  • Plan, scope, and execute authorized red team and adversary emulation operations across enterprise, cloud, identity, endpoint, application, and retail technology environments.
  • Conduct realistic initial-access scenarios aligned to approved rules of engagement, including external attack surface testing, phishing simulation, identity abuse, public-facing application exploitation, SaaS/cloud footholds, and other authorized access paths.
  • Design, deploy, operate, and safely decommission C2 infrastructure used during approved red team operations.
  • Maintain strong operational security practices across tooling, infrastructure, logging exposure, operator behavior, payload safety, engagement deconfliction, and post-operation cleanup.
  • Develop, modify, test, and review offensive tooling, payloads, automation, and tradecraft in controlled and authorized environments.
  • Conduct endpoint telemetry and evasion research to understand how security controls detect, block, or miss adversary behavior.
  • Identify and validate attack paths involving Active Directory, ADCS, Kerberos, privileged access, trust relationships, Microsoft Entra ID, cloud IAM, SaaS platforms, and endpoint controls.
  • Partner with Detection Engineering, SOC, Threat Hunting, and Incident Response teams to improve visibility, alerting, response playbooks, and control effectiveness.
  • Translate red team findings into clear technical reports, executive summaries, attack narratives, detection gaps, and prioritized remediation recommendations.
  • Map adversary behaviors, findings, and emulation plans to common frameworks such as MITRE ATT&CK.
  • Support purple team exercises that validate detection logic, response workflows, and defensive control improvements.
  • Stay current on adversary tradecraft, offensive security research, cloud and identity attack paths, endpoint security capabilities, and emerging defensive technologies.
  • Mentor other offensive security team members and contribute to the development of repeatable methodologies, lab environments, tooling standards, and operational processes.


Required Qualifications

  • Bachelor's Degree in Computer Science, CIS, Engineering, Business Administration, Cybersecurity, or related field (or equivalent work or military experience in a related field)
  • 4 years of experience in information security
  • Intermediate understanding of fundamental security and network concepts (Windows and Unix security: OS lockdown; logging and monitoring; application security; user access; perimeter protection principles, network communication rules; intrusion detection and analysis methods; etc.).


Preferred Qualifications

  • 6+ years of hands-on offensive security experience, including at least 4+ years conducting full-scope red team or adversary emulation operations in enterprise environments. Equivalent demonstrated capability may substitute for strict year requirements.
  • Demonstrated experience planning and executing authorized initial-access operations across one or more of the following: phishing simulation, external attack surface exploitation, public-facing application exploitation, identity abuse, SaaS/cloud footholds, or trusted third-party/supply-chain-style scenarios.
  • Strong understanding of OPSEC for red team operations, including infrastructure separation, engagement deconfliction, logging discipline, payload safety, operator attribution control, burn procedures, and clear rules of engagement.
  • Advanced experience with C2 infrastructure design and operations, including staging, redirector concepts, operator workflows, infrastructure lifecycle management, detection exposure reduction, and post-engagement teardown.
  • Hands-on experience with endpoint security telemetry and evasion research in authorized lab or enterprise testing environments, including the ability to reason about EDR/AV behavior, security logs, SIEM visibility, and detection opportunities without relying only on public tools.
  • Technical ability to develop, modify, or review offensive tooling using at least one scripting language such as Python or PowerShell and at least one systems or compiled language such as C, C++, C#, Go, or Rust.
  • Experience with payload, implant, or agent development in authorized environments, including safe execution controls, error handling, logging awareness, operator control, and post-operation cleanup.
  • Deep understanding of Windows enterprise attack paths, including Active Directory, Kerberos, ADCS, delegation, trusts, privileged access, endpoint hardening, and identity-based lateral movement.
  • Working knowledge of cloud and SaaS attack paths, especially Microsoft Entra ID/Azure, Google Cloud, Google Workspace, OAuth/application consent, IAM misconfiguration, service accounts, and cloud logging.
  • Ability to map operations to MITRE ATT&CK and produce actionable outputs for blue teams, including detection gaps, control weaknesses, attack-path narratives, and remediation recommendations. MITRE specifically describes ATT&CK as a common language and framework for red teams to emulate specific threats and plan operations.· 
  • Excellent written and verbal communication skills, with the ability to brief technical operators, SOC analysts, engineering teams, and leadership
  • Experience in retail, e-commerce, supply chain, payment, fraud, or large distributed enterprise environments.
  • Prior SOC, detection engineering, incident response, or threat-hunting experience.
  • Malware analysis or reverse engineering experience.
  • Experience building adversary emulation plans based on real threat actors. MITRE’s adversary emulation resources are designed to model threat behavior and map actions to ATT&CK.
  • Familiarity with security tooling such as EDR, SIEM, SOAR, CSPM, CNAPP, vulnerability scanners, attack surface management platforms, and identity security platforms.
  • Relevant certifications such as OSEP, OSCE3, CRTO, CRTE, CRTL, GXPN, GREM, GPEN, OSCP, CARTP, CRTP, or cloud security certifications.

About Lowe’s

Lowe’s Companies, Inc. (NYSE: LOW) is a FORTUNE® 100 home improvement company with total fiscal 2025 sales of more than $86 billion. Lowe’s employs approximately 300,000 associates and operates over 1,750 home improvement stores, 540 branches and 120 distribution centers. Based in Mooresville, N.C., Lowe’s supports the communities it serves through programs focused on creating safe, affordable housing, improving community spaces, helping to develop the next generation of skilled trade experts and providing disaster relief to communities in need. For more information, visit Lowes.com.  

Lowe’s is an equal opportunity employer and administers all personnel practices without regard to race, color, religious creed, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law.

Bereit, sich bei Lowe's zu bewerben?
Bei Lowe's bewerben

Über Lowe's

We’re glad you’re interested in building your career with us. Lowe’s is dedicated to service, which begins with serving our associates. Lowe’s team members enjoy exceptional benefits and opportunities to grow their skills. Apply today and start your career on a strong foundation. Lowe’s Companies, Inc. (NYSE: LOW) is a FORTUNE® 35 home improvement company serving approximately 20 million customers weekly in the United States and Canada. With fiscal year 2020 sales of nearly $90 billion, Lowe’s and its related businesses operate or service more than 2,200 home improvement and hardware stores and employ over 300,000 associates. Based in Mooresville, N.C., Lowe’s supports the communities it ser

Alle Jobs bei Lowe's ansehen →

Ähnliche Jobs

LO
Retail Sales – Part Time (Bilingual Preferred)
Lowe's
⚡ Früh bewerben Columbus, GA (N Columbus) 0636 Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 21 Std.
LO
Merchandising ASM
Lowe's
⚡ Früh bewerben Erwin, NC 1777 Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
LO
Full Time - Sales Associate - Outside Lawn & Garden - Opening
Lowe's
⚡ Früh bewerben Franklin, WI 2554 Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
LO
Full Time - Sales Associate - Outside Lawn & Garden - Closing
Lowe's
⚡ Früh bewerben Franklin, WI 2554 Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
LO
Full Time - Fulfillment Associate - Opening
Lowe's
⚡ Früh bewerben Derby, KS 2504 Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
LO
Full Time - Merchandising Service Associate - Day
Lowe's
⚡ Früh bewerben Webster, NY 1581 Vor Ort $34,320–$35,776
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
LO
Full Time - Merchandising Service Associate - Day
Lowe's
⚡ Früh bewerben Strongsville, OH 2339 Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
LO
Full Time - Cashier - Day
Lowe's
⚡ Früh bewerben Statesville, NC 0458 Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
LO
Part Time - Fulfillment Associate - Flexible
Lowe's
⚡ Früh bewerben Webster, NY 1581 Vor Ort $34,320–$35,776
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Lowe's

Alle Jobs bei Lowe's ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos