Lead Analyst, Information Security

Lowe's Companies, Inc.•Mooresville, NC
•Onsite

About The Position

The Lead Analyst is responsible for leading the end-to-end management of cybersecurity incidents, ensuring rapid containment, effective coordination, clear executive communication, and timely recovery. The role serves as the central point of coordination during major security incidents and works across Security Operations, Threat Intelligence, Digital Forensics, Infrastructure, Cloud, Application Security, Legal, Privacy, Communications, and business teams.

Requirements

  • 7-10+ years of experience in cybersecurity, with significant experience in Security Operations, Incident Response, DFIR, Threat Management, or Cyber Crisis Management.
  • Strong understanding of SIEM, SOAR, EDR/XDR, IAM, network security, cloud security, threat intelligence, and vulnerability management.
  • Experience managing high-severity, enterprise-scale security incidents involving multiple technical and business teams.
  • Strong knowledge of incident response frameworks such as NIST, SANS, and MITRE ATT&CK.
  • Working knowledge of cloud environments such as AWS, Azure, or GCP.
  • Excellent crisis leadership, stakeholder management, decision-making, and communication skills.
  • Ability to translate complex technical findings into clear business-risk and executive-level communications.
  • Strong documentation, analytical, and problem-solving capabilities.
  • Ability to operate effectively under pressure and manage multiple priorities during critical incidents.

Nice To Haves

  • CISSP, GCIH, GCFA, GCFE, CISM, Security+, or equivalent incident response/security certifications.

Responsibilities

  • Lead and coordinate response to high-severity cybersecurity incidents, including ransomware, account compromise, data exposure, cloud incidents, malware, insider threats, and third-party or supply-chain events.
  • Own the security incident management lifecycle from identification, triage, containment, eradication, and recovery through post-incident review.
  • Establish incident severity, business impact, escalation paths, response priorities, and appropriate stakeholder engagement.
  • Act as the Incident Commander for major cybersecurity incidents and coordinate technical and business response teams.
  • Maintain clear timelines, decision logs, action items, evidence, and incident documentation throughout an event.
  • Provide concise, timely executive-level incident reporting and briefings to senior leadership, including business impact and risk, incident severity and scope, response and containment status, key decisions or support required, recovery outlook, and material changes throughout the incident lifecycle.
  • Coordinate with Legal, Privacy, Risk, HR, Communications, and other teams when incidents have regulatory, customer, associate, or reputational implications.
  • Facilitate incident war rooms and bridge calls and maintain disciplined command-and-control practices.
  • Ensure appropriate handoffs between SOC analysts, threat hunters, DFIR, engineering, infrastructure, identity, cloud, and application teams.
  • Lead post-incident reviews and root-cause discussions and track corrective actions through closure. Deliver executive post-incident summaries covering root cause, business impact, lessons learned, residual risk, remediation priorities, and accountable action owners.
  • Identify recurring incident patterns and recommend improvements to security controls, detection capabilities, processes, and automation.
  • Develop and maintain incident response plans, playbooks, escalation matrices, communication templates, and tabletop exercises.
  • Track operational metrics such as MTTD, MTTA, MTTC, MTTR, incident severity, recurrence, SLA adherence, and corrective-action closure.
  • Support regulatory, audit, cyber insurance, and compliance requirements related to incident response.
  • Drive continuous improvement through automation, orchestration, AI-enabled investigation, and incident enrichment where appropriate.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service