About this role
Lead Analyst, Information Security
100 W. Worthington Avenue
Location Lowe's Charlotte Technology Hub 3505
Category Technology
Job Id JR-02656088
Job Type Full time
Department Information Security Operations
Pay Range: $111,600.00 - $212,000.00 annually
JOB DESCRIPTION
Innovate in Charlotte
Thank you for dedicating your time and talent to Lowe’s. We want to give you more opportunities to learn and grow, so if you find a position you’re interested in below, we encourage you to apply!
The Lead Analyst is responsible for leading the end-to-end management of cybersecurity incidents, ensuring rapid containment, effective coordination, clear executive communication, and timely recovery. The role serves as the central point of coordination during major security incidents and works across Security Operations, Threat Intelligence, Digital Forensics, Infrastructure, Cloud, Application Security, Legal, Privacy, Communications, and business teams.
Key Responsibilities
-
Lead and coordinate response to high-severity cybersecurity incidents, including ransomware, account compromise, data exposure, cloud incidents, malware, insider threats, and third-party or supply-chain events.
-
Own the security incident management lifecycle from identification, triage, containment, eradication, and recovery through post-incident review.
-
Establish incident severity, business impact, escalation paths, response priorities, and appropriate stakeholder engagement.
-
Act as the Incident Commander for major cybersecurity incidents and coordinate technical and business response teams.
-
Maintain clear timelines, decision logs, action items, evidence, and incident documentation throughout an event.
-
Provide concise, timely executive-level incident reporting and briefings to senior leadership, including business impact and risk, incident severity and scope, response and containment status, key decisions or support required, recovery outlook, and material changes throughout the incident lifecycle.
-
Coordinate with Legal, Privacy, Risk, HR, Communications, and other teams when incidents have regulatory, customer, associate, or reputational implications.
-
Facilitate incident war rooms and bridge calls and maintain disciplined command-and-control practices.
-
Ensure appropriate handoffs between SOC analysts, threat hunters, DFIR, engineering, infrastructure, identity, cloud, and application teams.
-
Lead post-incident reviews and root-cause discussions and track corrective actions through closure. Deliver executive post-incident summaries covering root cause, business impact, lessons learned, residual risk, remediation priorities, and accountable action owners.
-
Identify recurring incident patterns and recommend improvements to security controls, detection capabilities, processes, and automation.
-
Develop and maintain incident response plans, playbooks, escalation matrices, communication templates, and tabletop exercises.
-
Track operational metrics such as MTTD, MTTA, MTTC, MTTR, incident severity, recurrence, SLA adherence, and corrective-action closure.
-
Support regulatory, audit, cyber insurance, and compliance requirements related to incident response.
-
Drive continuous improvement through automation, orchestration, AI-enabled investigation, and incident enrichment where appropriate.
-
Required Qualifications
-
7-10+ years of experience in cybersecurity, with significant experience in Security Operations, Incident Response, DFIR, Threat Management, or Cyber Crisis Management.
-
Strong understanding of SIEM, SOAR, EDR/XDR, IAM, network security, cloud security, threat intelligence, and vulnerability management.
-
Experience managing high-severity, enterprise-scale security incidents involving multiple technical and business teams.
-
Strong knowledge of incident response frameworks such as NIST, SANS, and MITRE ATT&CK.
-
Working knowledge of cloud environments such as AWS, Azure, or GCP.
-
Excellent crisis leadership, stakeholder management, decision-making, and communication skills.
-
Ability to translate complex technical findings into clear business-risk and executive-level communications.
-
Strong documentation, analytical, and problem-solving capabilities.
-
Ability to operate effectively under pressure and manage multiple priorities during critical incidents.
-
Preferred Certifications
-
CISSP, GCIH, GCFA, GCFE, CISM, Security+, or equivalent incident response/security certifications.
-
Key Success Measures
-
Success in this role would typically be demonstrated through reduced incident response and recovery times, consistent execution of major-incident procedures, effective executive communication, high-quality post-incident reviews, timely closure of remediation actions, improved incident readiness, and measurable reduction in repeat incidents.
-
Key Partners
-
Security Engineering, SOC, DFIR, Threat Intelligence, Threat Hunting, IAM, Cloud Security, Application Security, Infrastructure, Legal, Privacy, Risk, HR, and Corporate Communications.
-
Enterprise / Retail Environment Considerations
-
For a large retail enterprise environment, the role should emphasize 24x7 incident coordination, third-party and supply-chain incidents, payment and e-commerce environments, customer data protection, cloud incidents, and executive crisis management.
-
About Lowe’s
-
Lowe’s Companies, Inc. is a FORTUNE 100 home improvement company with total fiscal year 2025 sales of more than $86 billion. Lowe’s employs approximately 300,000 associates and operates over 1,750 home improvement stores, 540 branches and 120 distribution centers. Lowe’s is a core value S&P 500 equity stock and a dividend aristocrat. Based in Mooresville, N.C., Lowe’s supports the communities it serves through programs focused on creating safe, affordable housing, improving community spaces, helping to develop the next generation of skilled trade experts and providing disaster relief to communities in need. For more information, visit Lowes.com.
-
Lowe’s is an equal opportunity employer and administers all personnel practices without regard to race, color, religious creed, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law.
-
Save Job
-
Curiosity wanted. Innovation required.
-
We are a curious team.
-
It’s curious to think of innovation and stability co-existing. But we pair a 100-year track record of success with a hunger to do things differently. Everyone is in the work — tackling complex problems where your impact can build back or build up the communities we serve.
-
We fill our halls with curious minds from all walks of life. Our differences make us stronger, which is why our leaders build cultures of recognition and inclusion. You are heard, and your curiosities are celebrated and championed here.
-
And we have built a space where the curious can move freely. Up in title, up in skills, to the side with teams, or back to try something completely new. We help you find your path — because when you win, we all win.
-
Grow Your Tech Career at Lowe's
-
Your work is recognized
-
When pursuing your goals, knowing your company has your back is essential. We give you the resources and benefits you need to work and live.
-
Paid Time Off
-
We offer paid time off for vacation, holidays, sick leave, and volunteer time. Depending on the position and tenure, most full-time associates start with around 10-15 days of combined time off.
-
Financial Well-Being
-
We ensure your hard work is well compensated with a competitive salary and bonus opportunities. We also invest in your financial future by providing access to our Employee Stock Purchase Plan with a 15% discount, and a 401(k) retirement account with a company match up to 4.25% if you contribute 6% if your pay.
-
Paid Parental Leave
-
All full-time salaried or hourly associates receive up to 10 weeks of paid maternity leave and 4 weeks of paid parental leave, plus access to dependent care resources, including adoption assistance.
-
Comprehensive Insurance
-
All regular full-time and part-time associates enjoy access to affordable insurance plans, mental health care, and Employee Assistance Programs.
-
Our Mission Statement
-
Solving problems & fulfilling dreams for the home
-
That’s why building a strong culture is important to us - once you join the flock, we have many ways for you to get involved and bring your “whole self” to your role.
-
Browse jobs
-
Lowe's offers scale and depth. But, unlike other large compani