Lumen Technologies is self-described as a global company of 40,000+ professionals empowering businesses, government, and communities to “produce amazing things.” Driven by the
SR LEAD INFORMATION SECURITY AUDITOR
Location
United States
Posted
14 days ago
Salary
$105.8K - $155.2K / year
Seniority
Lead
No structured requirement data.
Job Description
SR LEAD INFORMATION SECURITY AUDITOR
Lumen Technologies
Role Description The Cybersecurity Assurance Analyst (Audit) is an experienced member of the Information Security Compliance and Audit team with responsibilities for coordinating and executing a variety of compliance audit controls to ensure compliance with Information Security Policy, industry standards, and various compliance standards. - Monitors, tests, and coordinates audit and compliance activities related to one or more specific compliance programs/standards. - Coordinates external audit activities on a periodic basis. - Supports multiple compliance programs. - Facilitates working with internal customers of a wide variety of audiences. - Possesses excellent organizational skills to ensure that the necessary documentation is retained for review by other organizations as appropriate. Qualifications - Bachelor's degree with 6+ years of experience or Master's degree with 4+ years of experience. - 2-3 years practical experience with controls validation and compliance testing of CMMC audits, SSAE 16, AT-101 (SOC 1 / SOC 2), PCI, ISO, HIPAA, Privacy, NACHA, or SOX IT General Computer Controls auditing or similar audit experience. - Professional/technical certifications such as CISA, CISSP, GSEC, or CISM or willingness to pursue. Requirements - Work independently and as an experienced member of a team to manage the execution of multiple security controls validations simultaneously with specific deadlines. - Manage the assigned compliance program to successful completion each year. - Manage scope and project timelines and assist in managing the project budget. - Manage day-to-day vendor relationships and assist with vendor evaluations (or Requests for Proposals) as needed. - Suggest improvements to the compliance and audit control processes. - Document execution of information security controls and any findings identified during the control validation cycle. - Consult with control owners such as system administrators, database administrators, application owners and others on developing complete and repeatable control processes including control documentation such as procedures, control evidence, narratives, control matrices, metrics reports, etc. - Develop an understanding of each compliance standard and the validation requirements to satisfy the standards, including any policies, rules and regulations or laws governing the area reviewed. - Consult with internal clients on information security topics, providing guidance on compliance with corporate policy, standards, procedures, and industry best practices. - Communicate potential control gaps to management along with suggested remediation. - Educate and train process owners on compliance obligations. - Monitor and respond to customer and sales requests for information on various compliance initiatives. - Identify control deficiencies and/or process inefficiencies and develop process improvements. - Maintain and monitor progress of remediation steps on identified control deficiencies. Benefits - Comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. - Bonus structure (short-term incentives, long-term incentives and/or sales compensation).
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Staff Security Engineer, IAM
GitLabBuild software faster. The One DevOps Platform enables your entire org to collaborate around your code. We're hiring.
• Design comprehensive identity and AI access solutions that scale with our business growth, from AI agent governance frameworks to privileged access workflows that eliminate standing access through just-in-time provisioning • Lead identity and access engineering for our enterprise AI platforms including administration, SSO and SCIM integration, audit logging, data controls, and policy enforcement for Claude (web, Claude Code, Cowork) and adjacent tools • Codify our identity platforms in Terraform, leading the migration of Okta, Lumos, and our NHI platform from click-ops to peer-reviewed infrastructure-as-code, with a focus on global critical policies • Refactor our authentication framework to implement advanced conditional access controls such as device trust, location-based policies, risk-based step-up authentication, and behavioral analytics across our entire SaaS ecosystem • Pioneer non-human identity governance by designing monitoring and management solutions for service accounts, API keys, certificates, AI agents, and MCP integrations, and leading deployment, integration, and operationalization of our NHI platform across the SaaS estate • Drive cross-functional initiatives with Security, IT, Engineering, Enterprise AI, and the Office of the CIO to extract requirements from ambiguous business needs and translate them into actionable technical specifications • Mentor senior and intermediate engineers on technical implementation and strategic thinking, helping them develop expertise in modern identity and AI security practices
• Build and maintain strong relationships with AWS account teams, technical teams, and partner contacts to drive co-sell and joint GTM opportunities • Enable AWS teams to prospect and sell with Upwind, representing our solutions effectively to their customers • Train and support Upwind’s sales organization on working with AWS for co-sell, marketplace, and partner programs • Track and report on co-sell activity, joint pipeline, and partner-influenced deals, providing actionable insights to leadership • Collaborate with internal sales, marketing, and solutions engineering teams to execute joint campaigns, co-branded programs, and GTM initiatives • Support AWS Marketplace activities, including private offers, deal registration, and partner funding programs • Manage a large number of contacts and programs, ensuring organized and timely follow-up
Security Engineer
ECS Tech IncAll candidates must meet the following criteria: Must be a US Citizen, no dual Citizenships. Must be able to secure a Public trust clearance. Must be able to work across multiple programs across the Federal and DOD space. The core values that ECS looks for in an engagement manager include: Teamwork, Respect, Accountability, Integrity, and Leadership.
Role Description The Security Engineer is responsible for supporting the engineering, implementation, and optimization of the security technologies, telemetry integrations, detection content, and automation capabilities that enable effective enterprise security monitoring and incident response operations. This role works closely with the SOC analysts, enterprise IT teams, and platform owners to ensure the reliability, scalability, and operational effectiveness of enterprise security monitoring capabilities. The Security Engineer will contribute to the continuous improvement of SOC technologies, detection engineering, and automation initiatives that strengthen the organization’s cybersecurity posture. - Security Platform Administration: Support the operation, maintenance, and optimization of SOC security platforms including SIEM, EDR, and related monitoring technologies. - Security Telemetry Integration: Configure and maintain telemetry integrations to ensure enterprise visibility across infrastructure, cloud, identity, and endpoint platforms. - Detection Engineering: Develop, tune, and maintain detection rules, alerts, and correlation logic to improve threat detection capabilities and reduce false positives. - SIEM Data Management: Monitor SIEM performance, data ingestion pipelines, and log normalization processes to ensure reliable and accurate data collection. - Security Automation Support: Implement and maintain automation and orchestration workflows to improve SOC operational efficiency and investigation response times. - Investigation Support: Provide technical support and expertise to SOC analysts during security investigations, threat hunting, and incident response activities. - Platform Integration: Collaborate with enterprise IT, cloud, and infrastructure teams to onboard new systems and services into the SOC monitoring environment. - Operational Monitoring: Monitor the health, reliability, and performance of security monitoring infrastructure and telemetry pipelines. - Technical Documentation: Maintain documentation related to detection logic, engineering procedures, telemetry integrations, and SOC platform configurations. - Continuous Improvement: Identify opportunities to enhance monitoring coverage, improve detection quality, and optimize engineering workflows within the SOC. Qualifications - Experience: Minimum of 3–5 years of cybersecurity or security engineering experience supporting enterprise security operations environments. - Security Engineering Experience: Hands-on experience supporting enterprise security monitoring technologies including SIEM, EDR, and log management platforms. - Detection Engineering Knowledge: Experience creating, tuning, and maintaining detection content and alerting logic. - Security Telemetry Experience: Familiarity with log collection, normalization, and telemetry integration across enterprise environments. - Security Automation Experience: Experience implementing or supporting automation workflows within SOC or incident response operations. - Enterprise Security Knowledge: Strong understanding of enterprise infrastructure, cloud environments, identity systems, and network security monitoring. - Security Framework Knowledge: Familiarity with cybersecurity frameworks such as NIST Cybersecurity Framework, CIS Critical Security Controls, and ISO 27001. Requirements - Able and willing to obtain a US Security Clearance. - On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capability. Physical Demands - While performing the duties of this job, the employee is regularly required to sit at a desk and use a computer for extended periods. - The position is generally sedentary but may require walking or standing for brief periods of time. - Employee may occasionally be required to move, carry, push, pull and/or lift objects up to 10 pounds. Work Environment - Job is performed in an office place setting. - The noise level in the work environment is generally very low with minimal background noise. - Comfortable climate control and adequate lighting.
Senior Security Engineer
ECS Tech IncAll candidates must meet the following criteria: Must be a US Citizen, no dual Citizenships. Must be able to secure a Public trust clearance. Must be able to work across multiple programs across the Federal and DOD space. The core values that ECS looks for in an engagement manager include: Teamwork, Respect, Accountability, Integrity, and Leadership.
Role Description The Senior Security Engineer is responsible for supporting the engineering, implementation, and optimization of the security technologies, telemetry integrations, detection content, and automation capabilities that enable effective enterprise security monitoring and incident response operations. This role works closely with the Security Engineering Manager, SOC analysts, enterprise IT teams, and platform owners to ensure the reliability, scalability, and operational effectiveness of enterprise security monitoring capabilities. The Senior Security Engineer will contribute to the continuous improvement of SOC technologies, detection engineering, and automation initiatives that strengthen the organization’s cybersecurity posture. Responsibilities - Security Platform Administration: Support the operation, maintenance, and optimization of SOC security platforms including SIEM, EDR, and related monitoring technologies. - Security Telemetry Integration: Configure and maintain telemetry integrations to ensure enterprise visibility across infrastructure, cloud, identity, and endpoint platforms. - Detection Engineering: Develop, tune, and maintain detection rules, alerts, and correlation logic to improve threat detection capabilities and reduce false positives. - SIEM Data Management: Monitor SIEM performance, data ingestion pipelines, and log normalization processes to ensure reliable and accurate data collection. - Security Automation Support: Implement and maintain automation and orchestration workflows to improve SOC operational efficiency and investigation response times. - Investigation Support: Provide technical support and expertise to SOC analysts during security investigations, threat hunting, and incident response activities. - Platform Integration: Collaborate with enterprise IT, cloud, and infrastructure teams to onboard new systems and services into the SOC monitoring environment. - Operational Monitoring: Monitor the health, reliability, and performance of security monitoring infrastructure and telemetry pipelines. - Technical Documentation: Maintain documentation related to detection logic, engineering procedures, telemetry integrations, and SOC platform configurations. - Continuous Improvement: Identify opportunities to enhance monitoring coverage, improve detection quality, and optimize engineering workflows within the SOC. Qualifications - Experience: Minimum of 5–8 years of cybersecurity or security engineering experience supporting enterprise security operations environments. - Security Engineering Experience: Hands-on experience supporting enterprise security monitoring technologies including SIEM, EDR, and log management platforms. - Detection Engineering Knowledge: Experience creating, tuning, and maintaining detection content and alerting logic. - Security Telemetry Experience: Familiarity with log collection, normalization, and telemetry integration across enterprise environments. - Security Automation Experience: Experience implementing or supporting automation workflows within SOC or incident response operations. - Enterprise Security Knowledge: Strong understanding of enterprise infrastructure, cloud environments, identity systems, and network security monitoring. - Security Framework Knowledge: Familiarity with cybersecurity frameworks such as NIST Cybersecurity Framework, CIS Critical Security Controls, and ISO 27001. Requirements - Able and willing to obtain a US Security Clearance. - On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capability. Physical Demands - While performing the duties of this job, the employee is regularly required to sit at a desk and use a computer for extended periods. - The position is generally sedentary but may require walking or standing for brief periods of time. - Employee may occasionally be required to move, carry, push, pull and/or lift objects up to 10 pounds. Work Environment - Job is performed in an office place setting. - The noise level in the work environment is generally very low with minimal background noise. - Comfortable climate control and adequate lighting.



