Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Incident Response Analyst - 90397446

$124.6k - $161.35k
Full-time

Amtrak

Your success is a train ride away!

As we move America’s workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.

Are you ready to join our team?

Our values of ‘Do the Right Thing, Excel Together and Put Customers First’ are at the heart of what matters most to us, and our Core Capabilities, ‘Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security’ are what every employee needs to know and do to be most impactful at Amtrak. By living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.

The Principal Cyber Threat Incident Response Analyst will play a critical role within the Amtrak Cyber Fusion Center. In this role, you will support a digital forensic cyber incident response team to effectively respond to and recover from cybersecurity incidents. You will serve as a subject matter expert responsible for coordinating and executing incident response activities across the organization, lead complex investigations involving suspected and confirmed cybersecurity incidents, execute the cyber incident response plan, response playbooks, and partner closely with information security leadership, business stakeholders, and cross-functional teams to ensure timely resolution of security incidents.

ESSENTIAL FUNCTIONS:

  • As a Principal Cyber Threat Incident Response Analyst, you will provide industry-leading cyber incident response supporting the Cyber Fusion Center mission to effectively detect and respond to threats and reduce the overall impact of business risk before, during, and after an incident
  • You will be able to resolve security incidents quickly, effectively and at scale with complete incident response including investigation, containment to support effective remediation, and crisis management
  • In this role, you will technically navigate critical and high-profile incidents, performing digital forensic and incident response analysis with support from threat hunting, and malware triage analysts
  • Support Amtrak-wide cyber incident response engagements, examine cloud, endpoint, and network-based sources of evidence
  • Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) that can be applied to current and future investigations
  • Conduct both IT and OT Network analysis and forensics
  • Conduct Malware and Malicious Code Reverse Engineering, Malware Analysis, Memory Analysis, Fileless Malware Analysis and Nation state actor malware investigations
  • Build scripts, tools, or methodologies to enhance Amtrak’s incident investigation processes
  • Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations
  • Support Cyber Incident Exercises, Tabletops, and Cyber Incident Management Response Team with business leaders, stakeholders, and cross-functional teams.
  • Support Crisis Management, Emergency Management, Incident Response, Legal and OIG teams to conduct and coordinate on Cyber Incident Response Activities.
  • Regularly participate in tabletop exercises designed to identify gaps, improve skills, enhance communication, and engage with stakeholders.
  • Review technical reports from vulnerability and penetration testing assessments, as well as results from tabletop exercise to identify potential future incidents.
  • Develop, refine, recommend, and maintain playbooks, policies, and procedures to ensure alignment to industry best practices

MINIMUM QUALIFICATIONS:

  • Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity, or related technical field; or equivalent combination of education, training and/or 7-10 years relevant experience is required.
  • Basic knowledge of privacy, data protection, and compliance requirements related to incident response and breach notification, including PCI DSS, HIPAA, GDPR, CCPA, and other applicable regulatory frameworks is preferred.
  • Experience in one or a combination of the following areas can be used to satisfy education and experience requirements:
    • Incident Response
    • Vulnerability Management
    • Digital Forensics
    • Malware and Malicious Code Reverse Engineering
    • Malware Analysis
    • Memory Analysis
    • Fileless Malware Analysis
    • Nation state actor malware investigations
    • Network or Cloud Security
    • Penetration Testing
  • One incident response centric certification
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Response and Industrial Defense (GRID)
    • GIAC Battlefield Forensics and Acquisition (GBFA)
    • GIAC Certified Forensic Examiner (GCFE)
    • GIAC Advanced Smartphone Forensics
    • GIAC Certified Forensic Analyst (GCFA)
    • GIAC Network Forensic Analyst (GNFA)
    • GIAC Reverse Engineering Malware (GREM)
    • EC-Council Certified Incident Handler (E|CIH)
    • eLearnSecurity Incident Handling & Response Professional (IHRP)
    • SEI Computer Security Incident Handler (CSIH)
    • NICCS Certified Incident Handler Engineer (CIHE)
  • In depth understanding of threats, vulnerabilities and principals of incident response and chain of custody.
  • Hands on experience with forensics tools and log correlation.
  • Ability to think like an attacker and hunt within the security tool stack.
  • Ability to incorporate the MITRE ATT&CK Framework in everyday processes.

PREFERRED QUALIFICATIONS:

  • Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity or equivalent technical field plus 10+ years of relevant work experience.
  • Knowledge of privacy, data protection, and breach notification regulations and standards, including PCI DSS, HIPAA, GDPR, CCPA, and/or similar regulatory frameworks.
  • Two or more incident response centric certifications
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Response and Industrial Defense (GRID)
    • GIAC Battlefield Forensics and Acquisition (GBFA)
    • GIAC Certified Forensic Examiner (GCFE)
    • GIAC Advanced Smartphone Forensics
    • GIAC Certified Forensic Analyst (GCFA)
    • GIAC Network Forensic Analyst (GNFA)
    • GIAC Reverse Engineering Malware (GREM)
    • EC-Council Certified Incident Handler (E|CIH)
    • eLearnSecurity Incident Handling & Response Professional (IHRP)
    • SEI Computer Security Incident Handler (CSIH)
    • NICCS Certified Incident Handler Engineer (CIHE)

KNOWLEDGE, SKILLS and ABILITIES:

  • Excellent written and oral communication skills to facilitate communication across all levels of the organization.
  • In depth understanding of threats, vulnerabilities and principals of incident response and chain of custody.
  • Hands on experience with forensics tools and log correlation.
  • Must possess excellent customer service, strong communication and interpersonal skills, work well with others in an integrated team environment, and must be self-motivated.
  • Must possess a high degree of integrity and trustworthiness.
  • Must have a deep understanding of computer intrusion activities, incident response techniques, tools, and procedures.
  • Ability to think like an attacker and hunt within the security tool stack.
  • Advanced proficiency with analysis and characterization of cyber0attacks (Kill Chain, MITRE ATT&CK)
  • Ability to incorporate the MITRE ATT&CK Framework in everyday processes.

The salary/hourly range is $124,600.00 – $161,352.00. Pay is based on several factors including but not limited to education, work experience, certifications, etc. Depending on an employee’s assigned worksite or location, Amtrak may consider a geo-pay differential to be applied to the employee’s base salary. Amtrak may offer additional incentive and pay programs to recognize and reward our employees, including a short-term incentive bonus based upon factors such as individual and company performance that is commensurate with the level of the position.

Health and Wellbeing Financial and Retirement Work and Family Life Support
Health, Dental, and Vision Insurance 401K with Employer Match Generous Paid Time Off
Wellness Programs Railroad Retirement Benefits Paid Caregiving Days and Backup Care
Health Savings Account Public Service Student Loan Forgiveness Fertility and Family Building Benefits
No-cost Personal Health Advocate Student Loan Assistance Adoption and Surrogacy Assistance
Medical Plan Opt-out Credit Tuition and Education Reimbursement Paid Family Leave
Life Insurance Rail Pass Privileges
Short- and Long-term Disability Insurance Employee Assistance Program
No-cost Financial Advisor Sessions Commuter and Flexible Spending Accounts

Learn more about our benefits offerings here.

Requisition ID: 167030

Work Arrangement: 02-Remote Optional Click here for more information about work arrangements at Amtrak.
Relocation Offered: No
Travel Requirements: Up to 25%

You power our progress through your performance.

We want your work at Amtrak to be more than a job. We want your career at Amtrak to be a fulfilling experience where you find challenging work, rewarding opportunities, respect among colleagues, and attractive compensation. Amtrak maintains a culture that values high performance and recognizes individual employee contributions.


Amtrak is committed to a safe workplace free of drugs and alcohol. All Amtrak positions requires a pre-employment background check that includes prior employment verification, a criminal history check and a pre-employment drug screen.

Candidates who test positive for marijuana will be disqualified, regardless of any state or local statute, ordinance, regulation, or other law that legalizes or decriminalizes the use or possession of marijuana, whether for medical, recreational, or other use. Amtrak's pre-employment drug testing program is administered in accordance with DOT regulations and applicable law.


In accordance with DOT regulations (49 CFR § 40.25), Amtrak is required to obtain prior drug and alcohol testing records for applicants/employees intending to perform safety-sensitive duties for covered Department of Transportation positions. If an applicant/employee refuses to provide written consent for Amtrak to obtain these records, the individual will not be permitted to perform safety-sensitive functions.

In accordance with federal law governing security checks of covered individuals for providers of public transportation (Title 6 U.S.C. §1143), Amtrak is required to screen applicants for any permanent or interim disqualifying criminal offenses.


Note that any education requirement listed above may be deemed satisfied if you have an equivalent combination of education, training and experience.


Amtrak is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race/color, to include traits historically associated with race, including but not limited to, hair texture and hairstyles such as braids, locks and twists, religion, sex (including pregnancy, childbirth and related conditions, such as lactation), national origin/ethnicity, disability (intellectual, mental and physical), veteran status, marital status, ancestry, sexual orientation, gender identity and gender expression, genetic information, citizenship or any other personal characteristics protected by law.

Vacancy posted 21 days ago
Similar jobs that could be interesting for youBased on the Principal Incident Response Analyst - 90397446 in Remote vacancy
  • $121.5k - $224.9k

     ...competitive benefits including a fresh perspective on workplace flexibility. Position Purpose: Executes enterprise-wide Incident Response Plan and recommends enhancements to improve security. Partners with business units to accomplish enterprise-wide remediation... 
    Principal
    Full time
    Part time
    Work at office
    Remote work
    Flexible hours

    Centene

    Illinois
    1 day ago
  •  ...collaborative culture that embraces recognition and professional development.The Sr. Project Analyst, eDiscovery Cyber Services supports the day-to-day delivery of cyber incident response, data breach and sensitive data matters. Working closely with Project Managers and... 
    Suggested
    Full time
    For contractors
    Work at office
    Remote work
    Worldwide
    Flexible hours

    Norton Rose Fulbright

    Houston, TX
    1 day ago
  •  ...in the United States. You will be at the forefront of identifying and investigating security incidents, and contributing to the continuous improvement of our incident response capabilities. This role requires a strong technical background, participation in on-call rotations... 
    Suggested
    Permanent employment
    Full time
    Contract work
    Work at office
    Local area
    Remote work
    2 days per week

    DocuSign

    San Francisco, CA
    3 days ago
  • $190.8k - $249.1k

     ...country where we have a legal entity. We are looking for an Incident Responder with robust technical skills, expertise in threat...  ...solid background in incident management. As a Senior Incident Response Analyst you'll be watching over our corporate environment and cloud... 
    Suggested
    Work experience placement
    Work at office
    Local area
    Remote work

    Atlassian

    Brooklyn, NY
    21 hours ago
  •  ..., you change lives.Bosch Cyber Defense has an open position for a passionate, skilled, and experienced cyber forensic and incident response analyst to work as part of the cyber defense team in Pittsburgh, PA, USA. This is a unique opportunity to become part of a global... 
    Suggested
    Remote work

    Robert Bosch

    Pittsburgh, PA
    21 hours ago
  • $130.9k - $196.3k

     ...families. Pay Range: $130,900.00 - $196,300.00 Security incidents demand more than monitoring. They require fast investigation...  ...drive remediation through closure. As a Senior Incident Response Analyst , you will help protect WGU’s systems and data by leading... 
    Full time
    Work at office
    Flexible hours

    Jobleads-US

    Raleigh, NC
    1 day ago
  • $131.3k - $237.35k

     ...programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC) Support... 
    Local area
    Immediate start
    Remote work
    Flexible hours

    Jobleads-US

    Arlington, VA
    2 days ago
  • $120k - $135k

     ...been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission‑critical government program. As part of the Security Operations Center, you will... 
    Permanent employment
    Contract work
    Remote work
    2 days per week

    tetraddigitalintegrityllc

    Arlington, VA
    1 day ago
  •  ...message the job poster from V Group Inc. Recruiting for NY - MTA, VITA, State of NC, SC, MI, MS, TN at V Group Job Title: Incident Response & Forensics Analyst Duration: 6+ Months Location: Remote with Occasional visit to NYC Position Type: Contract Interview Type: In-person... 
    Contract work
    Work at office
    Local area
    Remote work

    V Group

    New York, NY
    1 day ago
  •  ...Incident Response Analyst (Task 4 – Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro Area) Employment Type: Full-Time Clearance: Public Trust (or eligibility to obtain) We are seeking an experienced Incident Response... 
    Full time
    Contract work
    Remote work
    Monday to Friday

    Cyber Synergy

    Washington DC
    3 days ago
  •  ...leading AI research labs to build the next generation of security-focused AI systems — and we need real incident responders to help get it right. As an Incident Response Analyst, you'll work with realistic security incident data to evaluate and improve how AI interprets... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr Corp.

    Seattle, WA
    4 days ago
  •  ...A cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management for federal contracts. The role includes event triage, incident investigations, and close coordination with federal cybersecurity teams. Ideal candidates will have experience... 
    Remote work

    Cyber Synergy

    Washington DC
    4 days ago
  • $168k - $243k

    Collaborate with internal and customer teams to investigate and contain incidents.Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.Lead complex client-facing investigations and examine cloud, endpoint... 
    Principal
    Remote work

    Google

    Sacramento, CA
    3 days ago
  •  ...University of Rochester is seeking a security operations professional to support day-to-day information security incident response and triage. You will verify and document events, escalating incidents as needed and provide first- and second-level responses for security... 
    Remote job

    Jobleads-US

    New York, NY
    1 day ago
  •  ...excited to work at the forefront of AI-driven security on a global scale, this is the place to do it. Job Description Responsible for daily incident management of customer incidents Perform incident response and forensic analysis of compromised systems, identify... 
    Full time
    Worldwide

    Check Point Software Technologies

    Remote
    7 days ago
  • $108.2k - $162.4k

     ...technically complex and constantly changing. The IT Security Analyst II uses their knowledge of current security methods and standards...  ...Infrastructure and business teams. This role has a strong incident response and security operations focus, with opportunities to apply... 
    Full time
    Work at office
    Flexible hours
    Afternoon shift

    Western Governors University

    Salt Lake City, UT
    1 day ago
  • Qualifications At least 2 years of incident response experience Experience with Crowdstrike and Web Application Firewall (WAF) Proficient with at least one scripting language (Python, Java, PowerShell, Bash) Cloud experience is a plus Responsibilities Address cybersecurity... 
    Remote work
    Visa sponsorship

    Breeze End Technology, LLC

    Alexandria, VA
    3 days ago
  • $125k

    Overview Information Security Engineer (Incident Response Analyst) role within the IT Security Ops team. The analyst will identify, analyze, and respond to security incidents to protect organizational assets and ensure continuity of operations. Key Responsibilities Assist... 
    Remote work

    Prestige Staffing

    Yonkers, NY
    3 days ago
  • $125 - $175 per hour

     ...Position: Cybersecurity Practitioner: Paid Expert Interviews (SOC, Incident Response, Detection, AppSec) Type: Contract Compensation: $1...  .... Qualifications Must-Have Experience as a SOC analyst, incident responder, or digital forensics investigator.... 
    Hourly pay
    Contract work
    Summer work
    Remote work

    Mercor

    Chicago, IL
    6 days ago
  • $125 - $175 per hour

     ...: Cybersecurity Practitioner: Paid Expert Interviews (SOC, Incident Response, Detection, AppSec) Type: Contract Compensation: $...  ...recent experience in enterprise security roles such as SOC analysts, incident responders, or security engineers. Experience with... 
    Hourly pay
    Contract work
    Summer work
    Remote work

    Mercor

    Miami, FL
    6 days ago
  • $140k - $170k

     ...& cyber investigations space, your responsibilities as an Associate Principal may include (but are not limited to...  ...breach detection, threat analysis, incident response and malware analysis;Performing...  ...responder, network forensic analyst or malware analyst;Experience leading... 
    Principal
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    CRA International

    Boston, MA
    3 days ago
  •  ...Who we are looking for Current or recent hands-on practitioners in enterprise security, for example: SOC analysts and SOC leads (tier 2 and above) Incident responders and digital forensics investigators Detection engineers and threat hunters Application security or... 
    Hourly pay
    Live in
    Remote work

    Mercor Inc

    United States
    4 days ago
  • $141k - $229k

     ...About This Role:Forrester Research is seeking a Principal Analyst to lead Forrester’s technology resilience and data...  ...: site reliability engineering (SRE), National Incident Management System (NIMS), the National Response Framework (NRF), availability zones, ISO 22301,... 
    Principal
    For contractors
    Remote work

    Forrester Research

    Atlanta, GA
    3 days ago
  • $100k - $160k

     ...contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job....  ...Responsibilities We are seeking a Cybersecurity Incident Response & Threat Detection Analyst. REQUIRED QUALIFICATIONS Experience Five (5... 
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Monday to Friday
    Weekend work
    Day shift
    Afternoon shift

    TekSynap

    Columbus, OH
    6 days ago
  • $85k - $123k

     ...research to determine the risk to the organization and take appropriate actions based upon that analysis. Responsibilities include rapidly responding to potential incidents and events to minimize risk exposure and ensure the confidentiality, integrity, and availability of... 
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG Bank, Ltd.

    Tempe, AZ
    a month ago
  •  ...Job Description Job Description Incident Response Analyst / Engineer Experience: 5+ years required this is currently a 3–6 month requirement. Work Arrangement: Remote, Hybrid, or Onsite – candidates comfortable with any of these arrangements can be considered... 
    Remote work

    Accrescent Group

    Roanoke, TX
    17 days ago
  • $168k - $243k

     ...Principal Analyst, Mandiant Threat Intelligence Services corporate_fare Google place North Carolina...  ...supporting monitoring, detection, and response capabilities. ~ Experience evaluating...  ...raw intelligence from sensors, incident response engagements, and other sources... 
    Principal
    Remote work

    Jobleads-US

    North Carolina
    3 days ago
  • $85k - $123k

     ...sites four days per week and work remotely one day. A member of our recruitment team will provide more details. The analyst for Incident Response Planning and Operations is responsible for cyber security wargaming and incident readiness program. While the focus is the... 
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Home office
    1 day per week

    MUFG Bank, Ltd.

    Jersey City, NJ
    a month ago
  • $72k - $129k

     ...investigating, hunting and managing all incidents. Collectively, the teams strive to protect...  ...through proactive identification, response, and mitigation of potential threats that...  ...re looking for...The Incident Management Analyst role is a position providing an opportunity... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Work from home
    Shift work
    Night shift
    Weekend work
    3 days per week

    Verizon

    Tampa, FL
    1 day ago
  •  ...Description : We are seeking a skilled and proactive IT Incident & Service Management Analyst to support application incident escalations, trend...  ...'s Digital IT department is strongly preferred. Responsibilities: Manage and respond to application incident escalations... 
    Remote work

    Katalyst Healthcares & Life Sciences

    Morristown, NJ
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Incident Response Analyst - 90397446. Be the first to apply!