Enter a job title or keyword

Lead Analyst, Information Security


Job Location:

Mooresville, NC - USA

Monthly Salary: Not provided by the employer
Posted: 2 October 2026 (Yesterday)
Application Deadline: 30 December 2026
Vacancies: 1 Vacancy

Job Summary

Innovate in Charlotte

Thank you for dedicating your time and talent to Lowes. We want to give you more opportunities to learn and grow so if you find a position youre interested in below we encourage you to apply!

The Lead Analyst is responsible for leading the end-to-end management of cybersecurity incidents ensuring rapid containment effective coordination clear executive communication and timely recovery. The role serves as the central point of coordination during major security incidents and works across Security Operations Threat Intelligence Digital Forensics Infrastructure Cloud Application Security Legal Privacy Communications and business teams.

Key Responsibilities

  • Lead and coordinate response to high-severity cybersecurity incidents including ransomware account compromise data exposure cloud incidents malware insider threats and third-party or supply-chain events.
  • Own the security incident management lifecycle from identification triage containment eradication and recovery through post-incident review.
  • Establish incident severity business impact escalation paths response priorities and appropriate stakeholder engagement.
  • Act as the Incident Commander for major cybersecurity incidents and coordinate technical and business response teams.
  • Maintain clear timelines decision logs action items evidence and incident documentation throughout an event.
  • Provide concise timely executive-level incident reporting and briefings to senior leadership including business impact and risk incident severity and scope response and containment status key decisions or support required recovery outlook and material changes throughout the incident lifecycle.
  • Coordinate with Legal Privacy Risk HR Communications and other teams when incidents have regulatory customer associate or reputational implications.
  • Facilitate incident war rooms and bridge calls and maintain disciplined command-and-control practices.
  • Ensure appropriate handoffs between SOC analysts threat hunters DFIR engineering infrastructure identity cloud and application teams.
  • Lead post-incident reviews and root-cause discussions and track corrective actions through closure. Deliver executive post-incident summaries covering root cause business impact lessons learned residual risk remediation priorities and accountable action owners.
  • Identify recurring incident patterns and recommend improvements to security controls detection capabilities processes and automation.
  • Develop and maintain incident response plans playbooks escalation matrices communication templates and tabletop exercises.
  • Track operational metrics such as MTTD MTTA MTTC MTTR incident severity recurrence SLA adherence and corrective-action closure.
  • Support regulatory audit cyber insurance and compliance requirements related to incident response.
  • Drive continuous improvement through automation orchestration AI-enabled investigation and incident enrichment where appropriate.

Required Qualifications

  • 7-10 years of experience in cybersecurity with significant experience in Security Operations Incident Response DFIR Threat Management or Cyber Crisis Management.
  • Strong understanding of SIEM SOAR EDR/XDR IAM network security cloud security threat intelligence and vulnerability management.
  • Experience managing high-severity enterprise-scale security incidents involving multiple technical and business teams.
  • Strong knowledge of incident response frameworks such as NIST SANS and MITRE ATT&CK.
  • Working knowledge of cloud environments such as AWS Azure or GCP.
  • Excellent crisis leadership stakeholder management decision-making and communication skills.
  • Ability to translate complex technical findings into clear business-risk and executive-level communications.
  • Strong documentation analytical and problem-solving capabilities.
  • Ability to operate effectively under pressure and manage multiple priorities during critical incidents.

Preferred Certifications

CISSP GCIH GCFA GCFE CISM Security or equivalent incident response/security certifications.

Key Success Measures

Success in this role would typically be demonstrated through reduced incident response and recovery times consistent execution of major-incident procedures effective executive communication high-quality post-incident reviews timely closure of remediation actions improved incident readiness and measurable reduction in repeat incidents.

Key Partners

Security Engineering SOC DFIR Threat Intelligence Threat Hunting IAM Cloud Security Application Security Infrastructure Legal Privacy Risk HR and Corporate Communications.

Enterprise / Retail Environment Considerations

For a large retail enterprise environment the role should emphasize 24x7 incident coordination third-party and supply-chain incidents payment and e-commerce environments customer data protection cloud incidents and executive crisis management.


About Lowes

Lowes Companies Inc. (NYSE: LOW) is a FORTUNE 100 home improvement company with total fiscal year 2025 sales of more than$86 billion. Lowes employs approximately 300000 associates and operates over 1750 home improvement stores 540 branches and 120 distribution centers. Lowes is a core value S&P 500 equity stock and a dividend aristocrat. Based inMooresville N.C. Lowes supports the communities it serves through programs focused on creating safe affordable housing improving community spaces helping to develop the next generation of skilled trade experts and providing disaster relief to communities in need. For more information visit.

Lowes is an equal opportunity employer and administers all personnel practices without regard to race color religious creed sex gender age ancestry national origin mental or physical disability or medical condition sexual orientation gender identity or expression marital status military or veteran status genetic information or any other category protected under federal state or local law.


Required Experience:

Senior IC


About Company

Company Logo

Discover the best Labor Day sales at Lowe’s. Shop deals on appliances, patio, grills, lawn and garden, and more in store or online at Lowes.com.

View Profile View Profile