Director, Information Security

Lowe's Companies Inc
  • Charlotte, NC
    2 days ago

    Job Description

    Innovate in Charlotte

    Thank you for dedicating your time and talent to Lowe's. We want to give you more opportunities to learn and grow, so if you find a position you're interested in below, we encourage you to apply!

    The Director, Security Operations is a senior cybersecurity leader accountable for the strategy, leadership, and operational effectiveness of enterprise security operations. The role oversees the people, technologies, processes, and partnerships responsible for detecting, investigating, responding to, and recovering from cybersecurity threats across corporate technology, stores, digital/e-commerce, cloud, supply chain, enterprise applications, networks, endpoints, and other critical assets. The Director advances 24x7 monitoring, threat detection, incident response, threat intelligence, and security automation while developing a high-performing, geographically distributed organization and partnering across Cybersecurity, Technology, Risk, Legal, Privacy, and business.

    Key Responsibilities

    Security Operations Leadership

    • Provide strategic and operational leadership for the enterprise SOC and establish its vision, operating model, priorities, roadmap, procedures, escalation paths, and accountability.
    • Ensure effective 24x7 monitoring and response across critical environments; continuously assess SOC maturity and improve people, process, technology, and automation.

    Threat Detection & Response

    • Lead security monitoring, detection, investigation, containment, response, and recovery; continuously improve detection engineering, correlation, use cases, alerting, and threat hunting.
    • Prioritize events based on business risk and improve visibility across endpoints, networks, cloud, applications, and identities.
    • Advance automation and orchestration to reduce repetitive work, accelerate response, and enable analysts to focus on higher-value investigations.

    Cybersecurity Incident Management

    • Provide senior leadership and escalation during significant cyber incidents; ensure effective investigation, containment, remediation, documentation, recovery, and stakeholder communication.
    • Coordinate major incidents with Technology, Legal, Privacy, Risk, Communications, and business leaders; lead post-incident reviews and convert lessons learned into measurable improvements.
    • Participate in exercises and simulations that strengthen organizational readiness for major cybersecurity events.

    Threat Intelligence & Emerging Threats

    • Maintain awareness of the evolving threat landscape and incorporate intelligence into monitoring, detection engineering, vulnerability prioritization, and incident response.
    • Monitor attack techniques, vulnerabilities, industry trends, and threats relevant to retail and large enterprises; translate technical threats into business risk and actionable recommendations.

    Technology & Security Capabilities

    • Provide strategic direction for SIEM, SOAR, EDR/XDR, network detection, cloud monitoring, threat intelligence, case management, and related security platforms.
    • Partner with architecture and engineering to ensure security technologies deliver appropriate visibility, scalability, resiliency, and integration.
    • Evaluate AI, machine learning, automation, and emerging technologies to improve detection coverage, response speed, analyst effectiveness, and operational resilience.

    Offensive Security

    • Lead the enterprise Offensive Security program, including penetration testing, red teaming, adversary emulation, purple-team exercises, attack-path analysis, and validation of security controls across applications, infrastructure, cloud, identity, and digital environments.
    • Establish a risk-based testing strategy aligned to threat intelligence and critical business services; prioritize findings by exploitability and business impact and track remediation through retesting.
    • Connect offensive testing with detection engineering, threat hunting, vulnerability management, application security, and engineering so attack insights continuously improve prevention, detection, and response.

    Risk, Governance & Compliance

    • Ensure Security Operations supports applicable legal, regulatory, audit, and company requirements; maintain procedures, playbooks, documentation, and evidence.
    • Partner with Cybersecurity Risk, Governance, and Compliance to address control gaps and protect the confidentiality, integrity, and availability of company information and technology assets, including regulated/payment environments where applicable.

    Metrics & Executive Communication

    • Establish meaningful metrics and OKRs covering detection, incident volume/severity, response performance, automation, resilience, maturity, and risk reduction.
    • Provide concise reporting to senior Cybersecurity, Technology, and business leadership; translate complex technical issues into business impact, risk, and recommended actions.
    • Use operational data and threat intelligence to identify trends and influence cybersecurity priorities and investments.

    Enterprise Partnership, Vendors & Financial Management

    • Build strong partnerships across Security Engineering, Infrastructure, Cloud, Architecture, Engineering, Digital, Product, Risk, Legal, Privacy, and business functions; balance security requirements with business needs and resilience.
    • Oversee strategic security vendors, managed security service providers, and technology partners; establish performance expectations and evaluate new services and partnerships.
    • Manage departmental budgets, resource planning, investment priorities, and forecasting.

    People Leadership

    • Build, lead, coach, and retain a high-performing organization of cybersecurity managers, analysts, engineers, and security professionals, including geographically distributed teams and partners.
    • Establish performance expectations, coaching, development, succession planning, accountability, collaboration, continuous learning, innovation, and operational excellence.
    • Connect the team's work to protecting customers, associates, company operations, and the enterprise.

    Qualifications

    Minimum Qualifications

    • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, Business, or related field, or equivalent education and professional experience.
    • 10+ years of progressive cybersecurity, information security, technology, or related experience, including significant security operations, monitoring, incident response, or threat detection experience.
    • 5+ years leading cybersecurity or technical teams with direct people-management responsibility; experience supporting enterprise-scale SOC capabilities and significant cybersecurity incidents.
    • Strong understanding of SIEM, EDR/XDR, network security, cloud security, identity, threat intelligence, security automation, and complex cloud/on-premises environments.
    • Demonstrated ability to communicate cybersecurity risks and recommendations to senior leaders, with strong leadership, stakeholder management, problem-solving, and decision-making skills.

    Preferred Qualifications

    • Master's degree in a relevant technical or business discipline; experience leading large-scale, highly distributed and/or global 24x7 security operations.
    • Experience in retail, e-commerce, financial services, critical infrastructure, or another high-volume/high-availability environment; cloud security operations and regulated/PCI environments.
    • Experience with security automation, orchestration, AI/ML, major incident response, NIST Cybersecurity Framework, MITRE ATT&CK, and related frameworks.
    • Relevant certifications such as CISSP, CISM, GIAC, CRISC, CISA, or equivalent.

    Leadership Profile

    The successful candidate will operate effectively at executive, strategic, and operational levels-leading through high-pressure cybersecurity events while building the long-term strategy, talent, technology, and capabilities required for modern enterprise Security Operations. The leader will translate complex cyber issues into business terms, challenge existing approaches when appropriate, build strong partnerships, and continuously improve the organization's ability to detect threats earlier, respond faster, reduce business risk, and protect customers, associates, operations, and the enterprise.

    About Lowe's

    Lowe's Companies, Inc. (NYSE: LOW) is a FORTUNE 100 home improvement company with total fiscal year 2025 sales of more than $86 billion. Lowe's employs approximately 300,000 associates and operates over 1,750 home improvement stores, 540 branches and 120 distribution centers. Lowe's is a core value S&P 500 equity stock and a dividend aristocrat. Based in Mooresville, N.C., Lowe's supports the communities it serves through programs focused on creating safe, affordable housing, improving community spaces, helping to develop the next generation of skilled trade experts and providing disaster relief to communities in need. For more information, visit Lowes.com.

    Lowe's is an equal opportunity employer and administers all personnel practices without regard to race, color, religious creed, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law.

    Numbers & Facts

    LocationCharlotte, NC

    Skills

    • Affordable Housingunmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Automationunmatched
    • Budget Managementunmatched
    • Business Intelligenceunmatched
    • Business Servicesunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Case Managementunmatched
    • Cloud Applicationsunmatched
    • Cloud Architectureunmatched
    • Cloud Computingunmatched
    • Coachingunmatched
    • Communication Skillsunmatched
    • Community Supportunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Improvementunmatched
    • Distribution Servicesunmatched
    • Documentationunmatched
    • Emerging Technologyunmatched
    • Enterprise Applicationsunmatched
    • Enterprise Protectionunmatched
    • Establish Prioritiesunmatched
    • Financeunmatched
    • Financial Managementunmatched
    • Financial Servicesunmatched
    • Forecastingunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • Geneticsunmatched
    • High Availabilityunmatched
    • Huntingunmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Industry/Trade Analysisunmatched
    • Information Assetsunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Legalunmatched
    • Machine Learningunmatched
    • Medical Conditionsunmatched
    • Metricsunmatched
    • Militaryunmatched
    • Network Securityunmatched
    • Operational Auditunmatched
    • Operational Strategyunmatched
    • Operational Supportunmatched
    • Operations Processesunmatched
    • Organizational Development/Managementunmatched
    • Organizational Skillsunmatched
    • PCIunmatched
    • Penetration Testingunmatched
    • Performance Analysisunmatched
    • Problem Solving Skillsunmatched
    • Process Improvementunmatched
    • Protective Servicesunmatched
    • Regulationsunmatched
    • Reporting Skillsunmatched
    • Retailunmatched
    • Riskunmatched
    • Risk Managementunmatched
    • Salesunmatched
    • Security Analysisunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Software Engineeringunmatched
    • Strategic Planningunmatched
    • Succession Planningunmatched
    • Supply Chain Management Softwareunmatched
    • Systems Engineeringunmatched
    • Technical Deliveryunmatched
    • Test Strategyunmatched
    • Testingunmatched
    • Trend Analysisunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Use Casesunmatched
    • Vendor/Supplier Planningunmatched
    • eCommerceunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder