[Remote] Black Lotus Labs Threat Researcher - APT Research Job Details | Lumen Technologies
Auto ImportNote: The job is a remote job and is open to candidates in USA. Lumen is a trusted network and connectivity provider supporting secure, high-performance infrastructure for enterprises, governments, and communities. The Threat Researcher will track advanced persistent threat actors, conduct threat hunting, and transform large-scale telemetry into actionable intelligence. The role also focuses on building AI-assisted workflows, automating detection and intelligence production, and communicating strategic threat insights to customers and stakeholders.
Responsibilities
- Leverage global datasets (e.g., netflow, malware and passive DNS,) to track malicious cyber actors, their infrastructure, and campaigns. Build repeatable AI-assisted and automation-driven methods to accelerate detection, prioritization, and intelligence production
- Use technical knowledge of adversary capabilities, infrastructure, malware, and network behavior to define, develop, and implement techniques for tracking sophisticated adversaries and delivering actionable threat intelligence to Lumen customers
- Lead and enhance threat hunting operations by engaging with research, engineering, data science, and customer-facing teams; building strong partnerships; exploring new data sources; and collaborate with team members in AI-assisted workflow generation, automation design, and complex analytic problem solving
- Identify malicious activity in large-scale network, endpoint, DNS, routing, and enrichment data, and scale detection through Python-based automation and data pipelines
- Establish AI powered analytical workflows to automate and scale detections of adversary activity and tradecraft
- Provide actionable analysis and strategic insights into emerging threats, vulnerabilities, adversary infrastructure, and automation-derived findings, translating complex technical information into clear intelligence for executive leadership, customers, and external stakeholders
Skills
- Proven experience in threat analysis and in-depth technical security research, with a track record of identifying and tracking nation-state malicious infrastructure activity with an emphasis on network traffic analysis
- Fluency in advanced threat hunting methodologies, attacker tactics, techniques, and procedures (TTPs), and the ability to derive actionable threat hunts, detections, and intelligence requirements from complex data sets
- Experience with large-scale data analysis platforms with tools such as PySpark
- Experience with telemetry collection and analysis, including OSINT, proprietary endpoint and network data, DNS and routing data, TTP-based threat hunting, and/or threat hunt tooling that improves cross-organization visibility and supports public-private or multi-company collaboration
- Proven communication and presentation skills, including the ability to clearly and concisely convey complex technical findings, automation-derived insights, and intelligence judgments to technical, executive, customer, and partner audiences
- Proficiency in malware reverse engineering and incident response
- Software development experience with Docker, distributed data technologies such as Hadoop or Spark, cloud AI services, vector databases, workflow orchestration, and machine learning frameworks such as TensorFlow or PyTorch
- Experience with agentic AI or workflow frameworks such as MCP-based architectures
- Active TS/SCI
Benefits
- Remote position
- Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing.
Company Overview
Company H1B Sponsorship