Director, DT Threat Detection & Engineering- 90284261 - null

Amtrak

United States

On-site

USD 179,000 - 232,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health, Dental, Vision Insurance
401K with employer match
Generous PTO
Wellness programs
Railroad retirement benefits
No-cost benefits and support

Job summary

Amtrak is seeking a senior security leader to drive threat detection engineering, automation, and defense capabilities. You will oversee detections across SIEM, EDR/XDR, cloud and network, aligning to MITRE ATT&CK and working with CTI, threat hunting, and red team functions to operationalize intelligence.

You will mentor engineers, define roadmaps, and manage programs to improve detection coverage, automation maturity, and incident response effectiveness at scale.

Qualifications

  • Minimum 11 years of cybersecurity experience with operations, detection engineering, threat intelligence, hunting, incident response, automation, or cyber defense.
  • Experience leading technical cybersecurity teams and managing complex security engineering initiatives.
  • Proficiency with software development methodologies, DevSecOps, and CI/CD pipelines.
  • Experience with GitHub, source control management, and automated deployment frameworks.
  • Knowledge of cloud platforms, APIs, automation frameworks, and enterprise integrations.

Responsibilities

  • Lead threat detection engineering across SIEM, EDR/XDR, cloud, network, and identity security platforms.
  • Develop and implement threat detection strategy aligned to MITRE ATT&CK and TTPs.
  • Oversee SOAR workflows and security automation to reduce MTTR and improve efficiency.
  • Collaborate with CTI, Threat Hunting, Incident Response, and Penetration Testing teams to operationalize intelligence.
  • Ensure scalable, maintainable solutions aligned with enterprise architecture and standards.

Skills

Team leadership
Cybersecurity experience
DevSecOps
CI/CD pipelines
GitHub
Cloud platforms
APIs & automation
Cyber defense engineering

Education

Bachelor’s degree or equivalent

Tools

GitHub

Job description

Your success is a train ride away! As we move America’s workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.

Your success is a train ride away! As we move America’s workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.

Are you ready to join our team? Our values of ‘Do the Right Thing, Excel Together and Put Customers First’ are at the heart of what matters most to us, and our Core Capabilities, ‘Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security’ are what every employee needs to know and do to be most impactful at Amtrak. By living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.

Job Summary

Play a critical role in leading and advancing the organization’s threat detection and cyber defense engineering capabilities. Responsible for overseeing the development, implementation, and continuous improvement of cyber threat detections, security automation, and defensive engineering solutions that support the Security Operations Center (SOC), Cyber Threat Intelligence (CTI), Threat Hunting, and Penetration Testing teams. Lead a team of detection engineers and cybersecurity developers responsible for building and maintaining scalable detection content across multiple security platforms, developing SOAR automations, integrating threat intelligence into security controls, and creating innovative cyber defense capabilities. Drive the organization’s ability to rapidly detect, investigate, and respond to evolving cyber threats while advancing operational efficiency through automation and engineering excellence.

Essential Functions
Strategic Leadership & Program Management
  • Develop and execute the strategic vision for Threat Detection & Engineering aligned with cybersecurity objectives and emerging threats.
  • Establish and maintain a threat detection strategy leveraging threat intelligence, threat hunting, penetration testing, and incident response findings.
  • Lead, mentor, and develop teams of detection engineers, automation engineers, and cyber defense developers while fostering innovation and operational excellence.
  • Define roadmaps, performance metrics, and maturity goals to improve detection coverage, automation, and engineering capabilities.
  • Manage staffing, budgeting, workforce planning, and performance management.
Threat Detection Engineering
  • Oversee the design, implementation, and lifecycle management of threat detections across SIEM, EDR/XDR, cloud, network, and identity security platforms.
  • Ensure detections are aligned to MITRE ATT&CK and relevant threat actor TTPs.
  • Drive continuous tuning to improve detection fidelity, reduce false positives, and enhance analyst effectiveness.
  • Partner with CTI, Threat Hunting, Incident Response, and Penetration Testing teams to transform intelligence and findings into actionable detections.
Security Automation & Engineering
  • Lead development of SOAR workflows, automated response capabilities, and orchestration solutions to improve operational efficiency and reduce MTTD/MTTR.
  • Oversee development of security tools, integrations, APIs, and engineering solutions that enhance detection, investigation, response, and reporting.
  • Ensure solutions are scalable, maintainable, and aligned with enterprise architecture and cybersecurity standards.
Operational Collaboration
  • Partner with SOC leadership to ensure detection and automation capabilities support monitoring and incident response needs.
  • Collaborate with Cyber Threat Intelligence, Threat Hunting, and Red Team/Penetration Testing functions to operationalize intelligence, validate detection effectiveness, identify gaps, and strengthen defenses.
Risk Management & Governance
  • Assess detection coverage, identify control gaps, and prioritize engineering efforts to mitigate cyber risk to critical systems and data.
  • Ensure compliance with regulatory requirements, industry standards, cybersecurity frameworks, and organizational policies.
  • Develop metrics, reporting, and executive communications that provide visibility into detection effectiveness, automation maturity, operational performance, and risk reduction.
Minimum Qualifications
  • Bachelor’s Degree or equivalent combination of education, training, and/or relevant experience.
  • Plus 11 years of relevant cybersecurity experience, including security operations, detection engineering, threat intelligence, threat hunting, incident response, security automation, or cyber defense engineering.
  • Experience leading technical cybersecurity teams and managing complex security engineering initiatives
  • Proficiency with software development methodologies, DevSecOps, and CI/CD pipelines
  • Experience with GitHub, source control management, and automated deployment frameworks.[GC1.1]
  • Knowledge of cloud platforms, APIs, automation frameworks, and enterprise integrations.
Preferred Qualifications
  • Bachelor’s Degree or equivalent combination of education, training, and/or relevant experience.
  • Plus 13 years of relevant cybersecurity experience.
  • Experience leading enterprise-scale Threat Detection Engineering, Security Operations, Security Automation, or Cyber Defense programs.
  • Relevant industry certifications such as CISSP, GIAC (GCDA, GCTI, GMON, GCFA, or similar), CCSP, or related cybersecurity certifications.
  • Experience implementing MITRE ATT&CK-based detection programs and SOAR/SIEM platforms in complex enterprise environments.
  • Experience supporting enterprise-scale cyber data lake or security data pipeline architectures.
  • Knowledge of cloud-native security platforms and large-scale security analytics environments.
Knowledge, Skills, And Abilities
  • Proven ability to lead and mentor high-performing teams of detection engineers, security automation engineers, and cybersecurity developers.
  • Foster a culture of innovation, accountability, collaboration, and continuous improvement.
  • Provide technical leadership and career development opportunities for engineering teams.
  • Deep understanding of cybersecurity operations, threat detection methodologies, threat intelligence, incident response, threat hunting, and adversary tactics, techniques, and procedures (TTPs).
  • Strong technical expertise across SIEM, SOAR, EDR/XDR, cloud security, network security monitoring, log analytics, security orchestration, and automation platforms.
  • Demonstrated ability to design, build, and optimize threat detections across diverse technology environments and security tools.
  • Experience operationalizing intelligence-driven and behavior-based detection strategies aligned to frameworks such as MITRE ATT&CK.
  • Knowledge of software development practices, scripting languages, APIs, automation frameworks, and cybersecurity engineering methodologies.
  • Ability to establish measurable performance indicators and drive continuous improvement in detection quality, coverage, and operational efficiency.
  • Strong analytical and problem-solving skills with the ability to assess complex threats and develop effective defensive engineering solutions.
  • Understanding of regulatory requirements, cybersecurity frameworks, and industry standards, including NIST Cybersecurity Framework, NIST 800-53, ISO 27001, and related guidance.
  • Exceptional communication and stakeholder management skills with the ability to translate complex technical concepts into meaningful business outcomes for executive and non-technical audiences.
  • Strategic mindset with the ability to anticipate emerging threats, evolving attack techniques, and future cybersecurity trends while developing proactive defense capabilities.

The salary/hourly range is $179,300.00 – $232,416.00. Pay is based on several factors including but not limited to education, work experience, certifications, etc. Depending on an employee’s assigned worksite or location, Amtrak may consider a geo-pay differential to be applied to the employee’s base salary. Amtrak may offer additional incentive and pay programs to recognize and reward our employees, including a short-term incentive bonus based upon factors such as individual and company performance that is commensurate with the level of the position.

Health and Wellbeing Financial and Retirement Work and Family Life Support
  • Health, Dental, and Vision Insurance 401K with Employer Match Generous Paid Time Off
  • Wellness Programs Railroad Retirement Benefits Paid Caregiving Days and Backup Care
  • Health Savings Account Public Service Student Loan Forgiveness Fertility and Family Building Benefits
  • No-cost Personal Health Advocate Student Loan Assistance Adoption and Surrogacy Assistance
  • Medical Plan Opt-out Credit Tuition and Education Reimbursement Paid Family Leave
  • Life Insurance Rail Pass Privileges
  • Short- and Long-term Disability Insurance Employee Assistance Program
  • No-cost Financial Advisor Sessions Commuter and Flexible Spending Accounts

Learn More About Our Benefits Offerings Here.

Requisition ID: 167051

Work Arrangement: 02-Remote Optional

Relocation Offered: No

Travel Requirements: Up to 25%

You power our progress through your performance.

We want your work at Amtrak to be more than a job. We want your career at Amtrak to be a fulfilling experience where you find challenging work, rewarding opportunities, respect among colleagues, and attractive compensation. Amtrak maintains a culture that values high performance and recognizes individual employee contributions.

Amtrak is committed to a safe workplace free of drugs and alcohol. All Amtrak positions requires a pre-employment background check that includes prior employment verification, a criminal history check and a pre-employment drug screen.

Candidates who test positive for marijuana will be disqualified, regardless of any state or local statute, ordinance, regulation, or other law that legalizes or decriminalizes the use or possession of marijuana, whether for medical, recreational, or other use. Amtrak’s pre-employment drug testing program is administered in accordance with DOT regulations and applicable law.

In accordance with DOT regulations (49 CFR

  • 40.25

In accordance with federal law governing security checks of covered individuals for providers of public transportation (Title 6 U.S.C.

  • 1143

Note that any education requirement listed above may be deemed satisfied if you have an equivalent combination of education, training and experience.

Amtrak is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race/color, to include traits historically associated with race, including but not limited to, hair texture and hairstyles such as braids, locks and twists, religion, sex (including pregnancy, childbirth and related conditions, such as lactation), national origin/ethnicity, disability (intellectual, mental and physical), veteran status, marital status, ancestry, sexual orientation, gender identity and gender expression, genetic information, citizenship or any other personal characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, DT Threat Detection & Engineering- 90284261 - null
Director, DT Threat Detection & Engineering- 90284261 - null

Amtrak • Northern (KY)

Hybrid
USD 179,000 - 232,000
Health Insurance
Dental Insurance
Vision Insurance
+3
Sr Mgr Digital Technology - Physical Security Systems
Sr Mgr Digital Technology - Physical Security Systems

Amtrak • Wilmington (DE)

On-site
USD 149,000 - 194,000
Health, Dental, Vision
401K with employer match
Rail Pass Privileges
Principal Incident Response Analyst - 90397446 - null
Principal Incident Response Analyst - 90397446 - null

Amtrak • United States

Hybrid
USD 125,000 - 161,000
Health and Wellbeing
401K with Employer Match
Paid Time Off
+1
Sr Principal DT Security Engineer - 90343213 - Remote
Sr Principal DT Security Engineer - 90343213 - Remote

Amtrak • United States

Hybrid
USD 149,000 - 194,000
Health and wellbeing programs
401K with employer match
Paid time off
+2
Lead Network Engineer - Washington DC, Phila, Wilmington, Chicago
Lead Network Engineer - Washington DC, Phila, Wilmington, Chicago

Amtrak • Wilmington (DE)

On-site
USD 104,000 - 134,000
Health and Wellbeing
401K with Employer Match
Paid Time Off
+2
Dir DT Sys Design & Dev Client Device - 90000791 - null
Dir DT Sys Design & Dev Client Device - 90000791 - null

Amtrak • United States

Hybrid
USD 179,000 - 232,000
Health Insurance
401K with employer match
Generous PTO
+2
Lead Enterprise Fraud Risk Analyst - 90411601 - Washington
Lead Enterprise Fraud Risk Analyst - 90411601 - Washington

Amtrak • Washington, Northern (KY)

Hybrid
USD 94,000 - 122,000
Sr Technologist - 90279592 - Philadelphia
Sr Technologist - 90279592 - Philadelphia

Amtrak • Philadelphia, Northern (KY)

Hybrid
USD 79,000 - 102,000
Health, Dental, Vision Insurance
401K with employer match
Paid Time Off
Fall 2026/Spring 2027 - Cybesecurity Engineering Intern - 90413073 - Washington
Fall 2026/Spring 2027 - Cybesecurity Engineering Intern - 90413073 - Washington

Amtrak • Washington

On-site
USD 25,000 - 48,000
Rail pass privileges
1 PTO day per academic year
Asst Division Engineer - 90413463 - Boston Job Details | Amtrak
Asst Division Engineer - 90413463 - Boston Job Details | Amtrak

Amtrak • Boston (MA)

On-site
USD 125,000 - 161,000
Health and Wellbeing
401K with Employer Match
Generous Paid Time Off
+2