Lowe’s

Sr Analyst, Information Security

Lowe’s$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science, Cybersecurity or related field, or equivalent work experience.
  • 4 years of experience in information security.
  • Intermediate understanding of security and network concepts, including both Windows and Unix security.
  • 6+ years of hands-on offensive security experience is preferred, particularly in enterprise environments.
  • Strong understanding of operational security (OPSEC) for red team operations.

Responsibilities

  • Plan and execute authorized red team operations across various technology environments.
  • Conduct realistic initial-access scenarios aligned with rules of engagement.
  • Design and operate C2 infrastructure for red team operations.
  • Maintain strong operational security practices throughout engagement processes.
  • Develop and test offensive tooling and automation in controlled environments.
  • Partner with detection and response teams to enhance visibility and response capabilities.
  • Translate findings into clear technical reports and prioritized remediation recommendations.

Benefits

  • Opportunities for professional development and mentorship in offensive security.
  • Access to cutting-edge technology and tools in cybersecurity.
  • Engagement in a collaborative red and purple team environment.
  • Flexible work arrangements that promote work-life balance.
Full Job Description


Job Description Summary

The Offensive Security Team is seeking a highly skilled Red Team Operator to help plan and execute authorized, threat-informed offensive security operations across Lowe's enterprise, cloud, identity, endpoint, and retail technology environments. This role will focus on realistic adversary emulation, initial access, C2 infrastructure, operational security, endpoint telemetry, evasion research, Active Directory, cloud identity, and offensive tooling.

The ideal candidate is a disciplined offensive security professional who can safely emulate modern adversary behavior, identify meaningful attack paths, and translate findings into actionable improvements for detection engineering, security operations, incident response, infrastructure, cloud, and identity teams. This role requires strong technical depth, sound judgment, clear communication, and the ability to operate ethically and professionally in sensitive environments.

This position will play a key role in strengthening Lowe's ability to prevent, detect, respond to, and recover from advanced cyber threats while helping improve the company's overall security posture through red team operations, purple team collaboration, control validation, and executive-ready reporting.

Key Responsibilities
  • Plan, scope, and execute authorized red team and adversary emulation operations across enterprise, cloud, identity, endpoint, application, and retail technology environments.
  • Conduct realistic initial-access scenarios aligned to approved rules of engagement, including external attack surface testing, phishing simulation, identity abuse, public-facing application exploitation, SaaS/cloud footholds, and other authorized access paths.
  • Design, deploy, operate, and safely decommission C2 infrastructure used during approved red team operations.
  • Maintain strong operational security practices across tooling, infrastructure, logging exposure, operator behavior, payload safety, engagement deconfliction, and post-operation cleanup.
  • Develop, modify, test, and review offensive tooling, payloads, automation, and tradecraft in controlled and authorized environments.
  • Conduct endpoint telemetry and evasion research to understand how security controls detect, block, or miss adversary behavior.
  • Identify and validate attack paths involving Active Directory, ADCS, Kerberos, privileged access, trust relationships, Microsoft Entra ID, cloud IAM, SaaS platforms, and endpoint controls.
  • Partner with Detection Engineering, SOC, Threat Hunting, and Incident Response teams to improve visibility, alerting, response playbooks, and control effectiveness.
  • Translate red team findings into clear technical reports, executive summaries, attack narratives, detection gaps, and prioritized remediation recommendations.
  • Map adversary behaviors, findings, and emulation plans to common frameworks such as MITRE ATT&CK.
  • Support purple team exercises that validate detection logic, response workflows, and defensive control improvements.
  • Stay current on adversary tradecraft, offensive security research, cloud and identity attack paths, endpoint security capabilities, and emerging defensive technologies.
  • Mentor other offensive security team members and contribute to the development of repeatable methodologies, lab environments, tooling standards, and operational processes.


Required Qualifications

  • Bachelor's Degree in Computer Science, CIS, Engineering, Business Administration, Cybersecurity, or related field (or equivalent work or military experience in a related field)
  • 4 years of experience in information security
  • Intermediate understanding of fundamental security and network concepts (Windows and Unix security: OS lockdown; logging and monitoring; application security; user access; perimeter protection principles, network communication rules; intrusion detection and analysis methods; etc.).


Preferred Qualifications

  • 6+ years of hands-on offensive security experience, including at least 4+ years conducting full-scope red team or adversary emulation operations in enterprise environments. Equivalent demonstrated capability may substitute for strict year requirements.
  • Demonstrated experience planning and executing authorized initial-access operations across one or more of the following: phishing simulation, external attack surface exploitation, public-facing application exploitation, identity abuse, SaaS/cloud footholds, or trusted third-party/supply-chain-style scenarios.
  • Strong understanding of OPSEC for red team operations, including infrastructure separation, engagement deconfliction, logging discipline, payload safety, operator attribution control, burn procedures, and clear rules of engagement.
  • Advanced experience with C2 infrastructure design and operations, including staging, redirector concepts, operator workflows, infrastructure lifecycle management, detection exposure reduction, and post-engagement teardown.
  • Hands-on experience with endpoint security telemetry and evasion research in authorized lab or enterprise testing environments, including the ability to reason about EDR/AV behavior, security logs, SIEM visibility, and detection opportunities without relying only on public tools.
  • Technical ability to develop, modify, or review offensive tooling using at least one scripting language such as Python or PowerShell and at least one systems or compiled language such as C, C++, C#, Go, or Rust.
  • Experience with payload, implant, or agent development in authorized environments, including safe execution controls, error handling, logging awareness, operator control, and post-operation cleanup.
  • Deep understanding of Windows enterprise attack paths, including Active Directory, Kerberos, ADCS, delegation, trusts, privileged access, endpoint hardening, and identity-based lateral movement.
  • Working knowledge of cloud and SaaS attack paths, especially Microsoft Entra ID/Azure, Google Cloud, Google Workspace, OAuth/application consent, IAM misconfiguration, service accounts, and cloud logging.
  • Ability to map operations to MITRE ATT&CK and produce actionable outputs for blue teams, including detection gaps, control weaknesses, attack-path narratives, and remediation recommendations. MITRE specifically describes ATT&CK as a common language and framework for red teams to emulate specific threats and plan operations.•
  • Excellent written and verbal communication skills, with the ability to brief technical operators, SOC analysts, engineering teams, and leadership

About Lowe’s

Lowe's Careers

Joining Lowe's means becoming part of a team that is committed to fostering an environment of growth, innovation, and leadership. As one of the leading home improvement companies, Lowe's offers unparalleled job opportunities and a culture that values diversity and professional development. Work You'll Do At Lowe's, your work will directly impact our mission to help people love where they live. Whether you're involved in the direct sales process, product development, or customer service, your role will contribute to our industry-leading standards. Transform Your Career Leverage your skills and drive in a position that empowers you to lead projects and initiatives that redefine the retail experience. Lowe's is at the forefront of the industry, combining retail, technology, and customer service to create unique experiences for consumers. Join a team of dedicated professionals who are there to support your career aspirations and help you grow both personally and professionally. With over 300,000 team members, Lowe's is a place where you can cultivate a career filled with innovation and opportunities. Lowe's Professional Growth and Opportunities We are committed to the professional growth of every team member. Lowe's offers a variety of career paths and opportunities for advancement, including leadership roles in numerous departments. Whether you're seeking a part-time position or a full-time career, Lowe's provides the training and resources needed to advance and excel. Internship Programs Start your career with Lowe's through our dynamic internship programs. These opportunities provide hands-on experience and a chance to engage in meaningful work that impacts our business. Interns at Lowe's gain invaluable skills, work alongside experienced professionals, and are considered for full-time positions upon successful completion of the program. Benefits and Culture Lowe's is dedicated to maintaining a culture that promotes diversity and inclusion. We offer a comprehensive benefits package that supports the health, well-being, and financial security of our employees and their families. Benefits include health insurance, retirement plans, and employee discounts, among others. Networking and Innovation Stay connected and ahead in your career through Lowe's commitment to innovation and networking. Our team members have access to cutting-edge technology and are encouraged to think outside the box to solve challenges. Networking within the company is supported through various groups and initiatives, fostering connections that can lead to career advancement. Join Our Team Explore the job opportunities at Lowe's that match your skills and interests. We are always looking for passionate, curious, and solution-driven team players. Start your journey with Lowe's today and be part of a company that values hard work and dedication. Stay Up to Date Keep informed with the latest in career tips, company news, and industry insights—all from the people who work at Lowe's. Our careers blog provides valuable content that can help you navigate your professional journey. Job Alert Emails Customize your subscription to receive job alerts and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Lowe's. SEARCH LOWE'S JOBS At Lowe's, your career is in your hands. Build it with us and be part of a team that is changing the future of retail.
Learn more about Lowe’s
Size
200,000 employees
Market Cap
$120.3 billion
Industry
Net Income
$5.8 billion
Founded
1946
5 Year Trend
+8.2%
Revenue
$89.5 billion
NASDAQ

Similar Jobs

More Jobs at Lowe’s

More Information Technology Jobs

Find similar Sr Analyst, Information Security jobs: