Director, Investigations and Innovation
About the role
This Director-level role in Global Security Services leads and matures Lumen’s Investigations and Innovation program.
Responsibilities
Run a world-class digital investigations and forensics capability staffed by certified professionals.
Lead complex intrusion, insider-threat, and incident investigations across all Lumen environments.
Ensure forensically sound evidence acquisition, preservation, chain of custody, and data recovery.
Deliver clear, defensible findings and metrics to stakeholders.
Provide expert investigations and legal support: e-discovery, legal hold, and response to subpoenas and demands.
Serve as trusted liaison to Legal, HR, and external law enforcement.
Maintain evidentiary standards for legal, regulatory, and litigation proceedings.
Research, pilot, and prove emerging security technologies — AI/ML security, automation, and next-gen tooling — where bold ideas drive real innovation.
Incubate new detection, threat-hunting, and defensive capabilities into repeatable programs.
Partner with Security Engineering and the Cyber Fusion Center to operationalize innovations at scale.
Mature a program of hypothesis-driven threat hunts.
Ingest new and emerging threats, including 0-day vulnerabilities.
Pivot rapidly based on real and hypothetical threat-actor activity.
Run Adversarial Cyber Emulation (ACE) engagements against Lumen’s incident response teams.
Lead Purple Team exercises in collaboration with incident response.
Conduct penetration tests of targeted applications by risk or compliance.
Choose the right security technology with Security Architecture.
Cover Detection & Response across Endpoint, Network, and AI.
Configure the Lumen security stack for cross-platform cohesion.
Tune the log-ingest and SIEM platform so responders can 'defend Lumen.'
Establish investigative processes, standards, and evidentiary rigor.
Develop a training and certification framework so the team can build, learn, and lead.
Drive tooling requirements and assess existing technologies.
Hire, develop, and grow team members with flexibility, care, and opportunity.
Lead Manager and Sr. Manager personnel; identify, develop, and delegate assigned projects.
Continually realign services with business and product needs, where every voice guides our future.
Advance the growing security operations organization — we win together.
Build strong relationships with colleagues, peers, clients, and vendors.
Requirements
Knowledgeable on the following platforms: Security platforms: Crowdstrike, Palo Alto, Tenable, Proofpoint, Extrahop, Splunk, Microsoft, RADIUS, and emerging AI.
Forensics platforms: Cellebrite, Magnet AXIOM, EnCase / FTK, Nuix, and e-discovery tooling.
Relevant security or forensics certifications.
Security clearance may be required.
Qualifications
Required: Bachelor’s degree in a related field plus 7 years relevant experience, or equivalent.
Preferred: 10+ years in security, investigations, or operations.
Skills
Knowledgeable on the following platforms: Security platforms: Crowdstrike, Palo Alto, Tenable, Proofpoint, Extrahop, Splunk, Microsoft, RADIUS, and emerging AI.
Forensics platforms: Cellebrite, Magnet AXIOM, EnCase / FTK, Nuix, and e-discovery tooling.
Benefits
Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing.
Pay
The information provided reflects the anticipated base salary range for this position based on current national data. Individual pay is based on skills, experience, and other relevant factors.
Schedule
This is a remote position open to candidates based anywhere in the US.