Full-Time

Information Security Engineer

Black Lotus Labs Threat Researcher, Crimeware

Posted on 8/29/2025

CenturyLink

CenturyLink

10,001+ employees

Global telecommunications and IT services provider

Compensation Overview

$129.6k - $190.1k/yr

+ Bonus Structure

Remote in USA

Remote

Candidates must be based in the US.

Category
IT & Security (1)
Required Skills
Python
Data Analysis
Requirements
  • Fluency in the ransomware attack chain, adversary TTPs, and detection techniques with an emphasis on detections of adversary infrastructure using network telemetry.
  • Proven experience in threat hunting and in-depth technical security research, demonstrating a strong track record of successfully identifying, tracking, and disrupting cybercriminal threat actors.
  • Deep understanding of advanced threat hunting methodologies, attacker tactics, techniques, and procedures (TTPs), and the ability to derive actionable threat hunts from complex data sets.
  • Demonstrated experience building prototype threat hunting solutions and large data analysis tools with Python (or other equivalent languages) on distributed computing frameworks.
  • Proven experience initiating and coordinating technical projects focused on telemetry collection, TTP based threat hunting, or developing threat hunt tools that have cross-organization impact on threat visibility, including leading private-public partnerships and multi-company collaborations.
  • Exceptional communication and presentation skills, including the ability to clearly and concisely convey complex technical information to both technical and non-technical audiences, ranging from executives and board members to conference attendees and internal stakeholders.
  • Experience developing threat research thought leadership such as blogs and presenting at industry conferences and in the media.
  • Highly organized with the ability to manage multiple tasks, prioritize effectively, and triage competing demands in a fast-paced environment.
  • Proven ability to lead and manage complex technical projects, effectively driving them to successful completion.
Responsibilities
  • Conduct threat research across technical data sets, fusing Black Lotus Labs telemetry with third party data sets, to automate detection of the latest threat attacker tools, techniques and procedures (TTPs) with a goal of automating detection.
  • Use industry-leading technical knowledge of adversary capabilities and infrastructure and define, develop, and implement techniques to lead the team in tracking sophisticated adversaries, delivering actionable threat intelligence data to Lumen customers.
  • Serve as Threat Research Subject Matter Expert, offering guidance and support to the Black Lotus Labs team on threat hunting activities, such as identifying knowledge gaps, troubleshooting technical challenges, developing solutions, and mentoring team members in overcoming obstacles. Set priorities for what threats to analyze to maximize team’s impact.
  • Lead and enhance threat hunting operations by actively engaging with other research teams, building strong partnerships to achieve shared goals, exploring new data sources, and mentoring team members in executing workflows and solving complex challenges.
  • Provide expert analysis and strategic insights on emerging threats and vulnerabilities, translating complex technical information into actionable intelligence for executive leadership and external stakeholders.
  • Spearhead thought leadership initiatives by leading Black Lotus Lab’s voice at security conferences and internal executive briefings.
Desired Qualifications
  • Proficiency in malware reverse engineering and incident response.
  • 5+ years of experience leading teams of technical threat discovery professionals.
  • Software development experience in Docker and big data technologies like Hadoop, Spark, and Tensor Flow.

CenturyLink, now known as Lumen Technologies, provides telecommunications and IT services for businesses and government. It offers voice communications and network services such as VoIP, SIP Trunking, hosted VoIP, SD-WAN, MPLS, and IPVPN, along with cloud and IT solutions like Big Data as a Service, IoT, and cloud management across hybrid, private, and public clouds. It differentiates itself by offering a broad, integrated portfolio that combines traditional communications with modern network and cloud services at scale, backed by global data centers and infrastructure. Its goal is to help customers communicate, connect, and digitally transform through secure, scalable, and manageable network and cloud solutions.

Company Size

10,001+

Company Stage

IPO

Headquarters

Monroe, Louisiana

Founded

1930

Simplify Jobs

Simplify's Take

What believers are saying

  • Sold ILEC business in 20 states to Brightspeed for $7.5B in October 2023, focusing on enterprises.
  • Divested EMEA operations to Colt for $1.8B in November 2023, streamlining core clients.
  • Higher-margin security, cloud, IP, UC services generated $4.5B revenue in 2023.

What critics are saying

  • Tycko & Zavareei lawsuit over Quantum Fiber 'Price for Life' false ads erodes trust now.
  • 940 Mbps fiber speeds lag Verizon Fios 2.3 Gbps and AT&T 5 Gbps, losing SMB share.
  • Legacy copper reliance forces FCC-mandated fiber migrations without rival scale by 2028.

What makes CenturyLink unique

  • Lumen Platform integrates global fiber, edge cloud, and security for 4th Industrial Revolution apps.
  • Quantum Fiber delivers high-speed fiber services to residents and SMBs via CenturyLink brand.
  • 450,000 route miles fiber network supports enterprise high-performance networking worldwide.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Life Insurance

Remote Work Options

Flexible Work Hours

Performance Bonus

Company News

Business Wire
Apr 2nd, 2024
1Stwest Ma Names Bryan Taylor As A New Managing Director

EVERGREEN, Colo.--(BUSINESS WIRE)--1stWest Mergers and Acquisitions announced today that it has named Bryan Taylor as a new Managing Director. Bryan will focus on Telecom, Cloud Technology, Cybersecurity, IT Services, and AI, sectors where Bryan has 25 years of experience as an accomplished deal execution leader in buy and sell transactions.Previously, Bryan worked as a financial analyst for Century Telephone Enterprises (a.k.a. CenturyLink and Lumen). After an initial six years mastering the telecom sector, Bryan joined CenturyLink’s M&A team to facilitate carve-out acquisitions of access lines. Over 22 years on CenturyLink’s M&A team, Bryan participated in acquisitions and divestitures with more than $80 billion in deal value, during which Bryan led the transformative acquisitions of Qwest and Embarq. Moving into data centers and managed services, Bryan led the acquisition of Savvis

Business Wire
Apr 2nd, 2024
1Stwest Ma Names Derek Koecher As A New Senior Advisor

EVERGREEN, Colo.--(BUSINESS WIRE)--1stWest Mergers and Acquisitions announced today that it has named Derek Koecher as a new Senior Advisor. Derek will bring his decades of M&A expertise to help guide 1stWest M&A’s clients through complex carve-outs, buy and sell transactions, growth strategies, and negotiation of transaction compensation for founders and executive teams.With a distinguished background in leadership roles at Fortune 100 companies such as Verizon (NYSE:VZ) and CenturyLink, Derek has facilitated over $100 billion in deal value across a wide spectrum of transactions. His journey began as a risk manager for a startup wireless communications company, before he advanced to pivotal roles in international telecom. Among his accomplishments, Derek played a key role in raising the largest VC-backed deal in Latin America as well as transformative acquisitions, including the sale of CenturyLink data centers, carveouts in towers, SaaS providers, and cyber security. Derek's recent focus on AI, Language Model (LM), mobility, fiber, and SaaS springs from his deep-rooted understanding of media, technology, and telecom.“Derek is among the most sought-after advisors for transactions in the hottest M&A sectors today, from telecom and SaaS to AI,” said Ted Rieple, 1stWest M&A’s Managing Partner. “Derek brings a sterling reputation to our firm, earned from his decades of service to many of the most well-known corporations in North American

StreamTV Insider
Jan 24th, 2024
Rayburn: CDN spotlight - Qwilt and Cirion partner on LATAM CDN coverage, Lumen shuts down CDN

In 2017, Level 3 was acquired by CenturyLink, and in 2020, CenturyLink changed its name to Lumen.

Blue Horizon Lines
Jan 16th, 2024
Technology Definition & Which Means

CenturyLink is regularly expanding its Fiber Gigabit Internet network that can deliver Internet speeds up to 940 Mbps.

Afroz Ahmad
Jan 3rd, 2024
8 Best Modem Router Combos for CenturyLink - Fast and Reliable Connectivity for Your Home

8 best Modem Router combos for CenturyLink - fast and reliable connectivity for your home.

INACTIVE