Analyst, Information Security (Disaster Recovery)

Lowe's Companies, Inc.

Charlotte (NC)

On-site

USD 75,000 - 143,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lowe's Companies, Inc. seeks an Information Security and IT Resilience professional in Charlotte to lead DR planning, resilience activities, and governance across systems. You will coordinate cross‑team efforts, analyze incidents, and drive improvements to recovery capabilities and runbooks.

The role emphasizes automation, metrics, and collaboration with application, infrastructure, and cloud teams to ensure robust recoverability for critical business services.

Qualifications

  • Bachelor’s degree or equivalent years of experience in IT or cybersecurity.
  • Experience supporting technology operations, production environments, incident management, or reliability engineering.
  • Experience working across application, infrastructure, platform, cloud, networking, or other technology teams to understand dependencies.
  • Experience using data, metrics, tooling, or automation to support technology operations and continuous improvement.
  • 2 years of experience in an IT domain (infrastructure, information security, or technology operations).

Responsibilities

  • Support planning, coordination, execution, and evaluation of Disaster Recovery exercises across applications, infrastructure, platforms, and critical technology services.
  • Develop and maintain recovery plans and runbooks documenting procedures, dependencies, roles, and validation criteria.
  • Support resilience assurance and validation activities against objectives and requirements.
  • Build technology dependency intelligence across applications, infrastructure, data, and third‑party services.
  • Support automation for dependency discovery, mapping, and recovery planning to scale DR programs.
  • Analyze incidents and recovery exercises to identify gaps and remediation opportunities.
  • Collect and report recovery and resilience metrics and remediation progress.
  • Partner with technology teams to ensure recovery capabilities stay aligned with changes.
  • Drive continuous improvement of DR and IT Operational Resilience processes and tooling.
  • Develop working knowledge across domains to understand end-to-end recoverability.

Skills

Disaster Recovery planning
Resilience engineering
Automation tooling
Cross-functional collaboration
Data-driven decision making

Education

Bachelor's degree in computer science, CIS, engineering, cybersecurity, or related field
Equivalent years of experience in lieu of education

Tools

Automation tooling

Job description

The primary purpose of this role is to lead the implementation and ongoing delivery of information security tools and processes. This includes responsibility for creating, executing, and improving processes and procedures with limited direct guidance from more senior level security associates.

This role solves complex problems while creating and optimizing processes and often takes a lead role in implementing new services and technologies.

This role requires a strong understanding of most tools and processes supported by the team, including many of the key integration points with other parts of technology, works mostly independently, and provides coaching and direction to more junior level associates.

When focused on Identity & Access Management (IAM), this role delivers timely, accurate, and controlled system access for the company's global workforce. This includes creating and maintaining processes, tools, controls, and governance mechanisms such as roles, reports, metrics, and issue resolution services.

When focused on Security Architecture, this role is dedicated to the evaluation and enhancement of robust security solutions and frameworks. This includes developing and maintaining comprehensive security architectures, ensuring alignment with industry standards and best practices.

When focused on Security Threat & Vulnerability, this role executes processes focused on vulnerability identification or remediation. This includes information security and risk activities such as oversight of vulnerability assessments and remediation programs serving both internal and external stakeholders.

When focused on Security Governance, Risk, and Compliance (GRC), this role completes activities that help drive awareness and adherence to information security policies and standards.

Key Responsibilities
  • Support the planning, coordination, execution, and evaluation of Disaster Recovery (DR) exercises across applications, infrastructure, platforms, and critical technology services, including documenting results, identifying recovery gaps, and tracking remediation activities.
  • Partner with application, infrastructure, platform, and operations teams to develop and maintain actionable recovery plans and runbooks that document recovery procedures, dependencies, recovery requirements, roles, and validation criteria.
  • Support resilience assurance and validation activities by evaluating demonstrated recovery capabilities against established recovery objectives, resiliency standards, and documented business and technology requirements.
  • Build and maintain technology dependency intelligence across applications, infrastructure, platforms, data, and third‑party services to improve understanding of upstream and downstream relationships that may affect recovery.
  • Support the development and adoption of automation for dependency discovery and mapping, recovery planning, testing, evidence collection, measurement, and reporting to improve the scale and efficiency of the DR program.
  • Analyze incidents, operational events, recovery exercises, and other sources of reliability intelligence to identify resilience gaps, recurring failure patterns, and opportunities for targeted recovery validation or remediation.
  • Collect, analyze, and report recovery and resilience metrics, including recovery exercise performance, demonstrated recovery times, identified gaps, remediation progress, and other indicators of technology recovery readiness.
  • Partner with technology teams to validate that recovery strategies and documented capabilities remain aligned with changes to application architecture, infrastructure, dependencies, and operational environments.
  • Support continuous improvement of DR and IT Operational Resilience processes, procedures, tooling, testing methodologies, and recovery standards based on exercise results, operational events, technology changes, and lessons learned.
  • Develop working knowledge across applications, infrastructure, cloud, networking, platforms, and other technology domains to understand how interconnected technology services support critical business capabilities and influence end-to-end recoverability.
Required Qualifications
  • Bachelor’s degree in computer science, computer information systems (CIS), engineering, business administration, cybersecurity, or related field or equivalent years of experience in lieu of education requirement, if applicable.
  • Experience supporting technology operations, production environments, incident management, reliability engineering, application support, infrastructure operations, or related technology functions.
  • Experience working across application, infrastructure, platform, cloud, networking, or other technology teams to understand system dependencies and operational requirements.
  • Experience using data, metrics, tooling, or automation to support technology operations, testing, reporting, dependency analysis, or continuous improvement activities.
  • 2 years of experience in an IT domain (infrastructure, information security, other technology operations or management).
Preferred Qualifications
  • Experience coordinating or participating in technology recovery exercises, operational testing, incident response, problem management, or other technology readiness and validation activities.
  • Experience analyzing technology incidents, operational issues, or test results to identify gaps, document findings, and support corrective or remediation activities.
  • Experience developing or maintaining technical documentation such as recovery plans, operational procedures, runbooks, dependency maps, test plans, or similar technology artifacts.
  • IT experience in the retail industry.
  • Experience conducting information security risk assessments of vendors and vendor software (specific to Security Governance, Risk & Compliance role).
  • CISSP Certified Information Systems Security Professional
About Lowe’s

Lowe's Companies, Inc. (NYSE: LOW) is a FORTUNE 100 home improvement company with total fiscal 2025 sales of more than $86 billion. Lowe's employs approximately 300,000 associates and operates over 1,750 home improvement stores, 540 branches and 120 distribution centers. Based in Mooresville, N.C., Lowe's supports the communities it serves through programs focused on creating safe, affordable housing, improving community spaces, helping to develop the next generation of skilled trade experts and providing disaster relief to communities in need. For more information, visit Lowes.com.

Lowe's is an equal opportunity employer and administers all personnel practices without regard to race, color, religious creed, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law.

Pay Range: $75,300.00 - $143,100.00 annually Starting rate of pay may vary based on factors including, but not limited to, position offered, location, education, training, and/or experience. For information regarding our benefit programs and eligibility, please visit https://talent.lowes.com/us/en/benefits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Technology Operations Analyst - Nights
Lead Technology Operations Analyst - Nights

Lowe's Companies, Inc. • Winston-Salem (NC)

On-site
USD 81,400 - 154,700
Lead Engineer – Enterprise Workforce Access Management, Information Security
Lead Engineer – Enterprise Workforce Access Management, Information Security

Lowe's Companies, Inc. • Charlotte (NC)

On-site
USD 111,600 - 212,000
Sr Manager, Infrastructure Engineering
Sr Manager, Infrastructure Engineering

Lowe's Companies, Inc. • Charlotte (NC)

On-site
USD 130,000 - 247,000
Lowe's Security Specialist
Lowe's Security Specialist

Lowe's Companies, Inc. • Charlotte (NC)

On-site
USD 32,000 - 48,000
Sr Engineer, Information Security
Sr Engineer, Information Security

Lowe's Companies, Inc. • Charlotte (NC)

On-site
USD 95,000 - 181,000
Lead Technology Program Manager
Lead Technology Program Manager

Lowe's Companies, Inc. • Charlotte (NC)

On-site
USD 102,000 - 194,000
401k match
Discounted ESPP
Tuition-Free Education
+2
Supply Chain Asset Protection & Safety Manager
Supply Chain Asset Protection & Safety Manager

Lowe's Companies, Inc. • Pottsville

On-site
USD 101,100 - 168,900
SC Security Specialist - Night
SC Security Specialist - Night

Lowe's Companies, Inc. • Connecticut

On-site
USD 23,000 - 38,000
Health, Dental and Vision insurance
401(k) Retirement account with company
Paid time off and holidays
+1
SC Security Specialist - Night
SC Security Specialist - Night

Lowe's Companies, Inc. • Town of Florida (NY)

On-site
USD 22,000 - 37,000
Analyst-Digital Engagement
Analyst-Digital Engagement

Lowe's Companies, Inc. • Mooresville (NC)

On-site
USD 62,000 - 103,000
401k with up to 4.25% match
Discounted Employee Stock Purchase Pan
Tuition-Free Education
+2