Principal DT Security Engineer - Operational Technology

Amtrak

Northern (KY)

Hybrid

USD 125,000 - 161,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health, Dental, Vision Insurance
401K with Employer Match
Generous Paid Time Off

Job summary

Amtrak is seeking a Senior Principal Cybersecurity Engineer to secure enterprise networks, OT/ICS, and critical infrastructure. You will lead security architecture design, implement controls, and drive resilience across IT and OT environments, collaborating with engineering, operations, and cybersecurity teams.

This role supports SAFe Agile practices, aligns with NIST and CIS controls, and guides threat detection, incident readiness, and risk management across rail transportation systems.

Qualifications

  • 7+ years of relevant work experience.
  • Experience securing enterprise network technologies (firewalls, IDS/IPS, VPNs, segmentation, proxies, wireless).
  • Experience with OT/ICS/SCADA environments and critical infrastructure.
  • Experience with SAFe, Agile delivery frameworks.
  • Familiarity with NIST CSF, NIST 800-53, NIST 800-82, CIS Controls, MITRE ATT&CK.
  • Experience risk assessments, security architecture reviews, and vulnerability management.

Responsibilities

  • Lead design, implementation, and management of cybersecurity controls for enterprise networks and critical infrastructure.
  • Evaluate security technologies and architectural solutions to strengthen posture.
  • Develop security architectures for network, cloud, data center, remote access, wireless, and OT/ICS.
  • Improve network visibility, threat detection, and security monitoring capabilities.
  • Collaborate with OT/ICS teams to enhance cyber resilience and incident readiness.

Skills

Cybersecurity leadership
OT security
SAFe Agile
Risk assessment
Network security
Communication

Education

Bachelor’s Degree or equivalent

Tools

Firewalls
IDS/IPS
VPNs
SCADA security
Cloud security

Job description

Select how often (in days) to receive an alert:

Principal DT Security Engineer - Operational Technology

Date: Aug 31, 2026

Location: US

Company: Amtrak

Your success is a train ride away!

As we move America's workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.

Are you ready to join our team?

Our values of ‘Do the Right Thing, Excel Together and Put Customers First’ are at the heart of what matters most to us, and our Core Capabilities, ‘Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security’ are what every employee needs to know and do to be most impactful at Amtrak. By living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.

Job Summary

The Sr Principal Cybersecurity Engineer serves as a senior technical engineer within the Enterprise Network & Critical Infrastructure Security (ENCIS) organization and is responsible for securing Amtrak's enterprise networks, critical infrastructure, and operational technology (OT) environments. This role provides advanced cybersecurity engineering expertise across IT and OT domains, ensuring the confidentiality, integrity, availability, and resilience of systems supporting business operations and rail transportation services.

The position leads the design, implementation, and continuous improvement of security architectures, controls, and technologies that protect enterprise infrastructure and critical operational assets. The Sr Principal Cybersecurity Engineer collaborates closely with infrastructure, network, engineering, operations, and cybersecurity teams to identify risks, implement safeguards, and reduce cyber threats across interconnected environments.

This role participates in and supports SAFe Agile practices, providing cybersecurity leadership across Agile Release Trains (ARTs), contributing to Program Increment (PI) planning, and ensuring security requirements are integrated into technology initiatives throughout the system lifecycle.

Essential Functions
  • Lead the design, implementation, and management of cybersecurity controls supporting enterprise networks and critical infrastructure environments.
  • Evaluate and recommend security technologies, platforms, and architectural solutions that strengthen Amtrak's security posture.
  • Develop and maintain security architectures for network, cloud, data center, remote access, wireless, and OT/ICS environments.
  • Lead initiatives to improve network visibility, threat detection, and security monitoring capabilities.
  • Partner with Network Engineering teams to implement secure infrastructure and resiliency improvements.
  • Provide cybersecurity leadership and engineering support for Operational Technology (OT), Industrial Control Systems (ICS), SCADA, and other critical infrastructure environments.
  • Collaborate with operational stakeholders to improve cyber resilience, incident readiness, and business continuity capabilities.
  • Support compliance efforts aligned with NIST, TSA Security Directives, CIS Controls, and other applicable transportation and critical infrastructure security requirements.
  • Provide advanced technical support during cyber incidents affecting enterprise or operational environments.
  • Collaborate with threat intelligence, SOC, and infrastructure teams to improve detection and response capabilities.
  • Participate in SAFe Agile ceremonies including PI Planning, Sprint Reviews, System Demos, and ART events.
  • Partner with Product Managers, Product Owners, Release Train Engineers, Architects, and Engineering teams to integrate security requirements into initiatives.
  • Track and communicate cybersecurity risks, dependencies, and deliverables across technology programs.
  • Serve as a trusted advisor to business and technology stakeholders on cybersecurity strategy and risk management.
  • Drive continuous improvement initiatives that enhance operational efficiency, automation, and security effectiveness.
  • Support periodic assessments, audits, tabletop exercises, and recovery testing activities.
Minimum Qualifications
  • Bachelor’s Degree or equivalent combination of education, training and/or relevant experience.
  • Plus 7 years of relevant work experience.
  • Experience securing enterprise network technologies, including firewalls, IDS/IPS, VPNs, network segmentation, proxies, and wireless infrastructure.
  • Experience working with Operational Technology (OT), Industrial Control Systems (ICS), SCADA environments, or other critical infrastructure technologies.
  • Experience participating in SAFe Agile, Agile Scrum, or similar Agile delivery frameworks.
    Strong understanding of cybersecurity frameworks including NIST Cybersecurity Framework, NIST 800-53, NIST 800-82, CIS Controls, and MITRE ATT&CK.
  • Experience performing risk assessments, security architecture reviews, and vulnerability management activities.
  • Strong knowledge of TCP/IP networking, routing, switching, and network security principles.
  • Experience supporting incident response, threat hunting, or security operations functions.
  • Strong communication, documentation, and stakeholder management skills.
  • Ability to work effectively across technical and non-technical teams.
Preferred Qualifications
  • Bachelor’s Degree or equivalent combination of education, training and/or relevant experience.
  • Plus 9 years of relevant work experience.
  • One or more certifications: CISSP, GIAC, Security+, CCNP, CCSP, CEH, CISM, or SABSA
  • Direct experience within transportation, railroad, energy, manufacturing, utility, or industrial sectors.
  • Advanced expertise in OT/ICS security technologies and architectures.
  • Experience implementing Zero Trust architectures and network segmentation strategies.
  • Experience with cloud security technologies in Microsoft Azure and Amazon Web Services (AWS).
  • Experience with Microsoft Security technologies including Microsoft Defender, Sentinel, Entra ID, and related security platforms.
  • Familiarity with TSA Security Directives, NERC-CIP, IEC 62443, or similar critical infrastructure security standards.
  • SAFe Agilist (SA), SAFe Practitioner (SP), or other SAFe certifications.
  • Experience leading enterprise-scale cybersecurity transformation initiatives.
Knowledge, Skills, and Abilities
  • Excellent customer service, strong communication and interpersonal skills, work well with others in an integrated team environment, and must be self-motivated
  • Proficient in securing Windows and *nix operating systems, endpoint applications, networking protocols and devices
  • In-depth understanding of scripting in Python, Bash, Perl, PowerShell or other relevant language
  • Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the secure software development lifecycle (SLDC)
  • Experience with industry standard information security technologies
  • Experience performing technical risk and vulnerability assessments
  • Strong analytical skills with experience working in or supporting a Security Operations Center
Environmental Conditions/Physical Demands

The salary/hourly range is $124,600.00 - $161,352.00. Pay is based on several factors including but not limited to education, work experience, certifications, etc. Depending on an employee’s assigned worksite or location, Amtrak may consider a geo-pay differential to be applied to the employee’s base salary. Amtrak may offer additional incentive and pay programs to recognize and reward our employees, including a short-term incentive bonus based upon factors such as individual and company performance that is commensurate with the level of the position.

Health and Wellbeing Financial and Retirement Work and Family Life Support

Health, Dental, and Vision Insurance 401K with Employer Match Generous Paid Time Off

Wellness Programs Railroad Retirement Benefits Paid Caregiving Days and Backup Care

Health Savings Account Public Service Student Loan Forgiveness Fertility and Family Building Benefits

No-cost Personal Health Advocate Student Loan Assistance Adoption and Surrogacy Assistance

Medical Plan Opt-out Credit Tuition and Education Reimbursement Paid Family Leave

Life Insurance Rail Pass Privileges

Short- and Long-term Disability Insurance Employee Assistance Program

No-cost Financial Advisor Sessions Commuter and Flexible Spending Accounts

Learn more about our benefits offeringshere.

Requisition ID:167052

Work Arrangement:02-Remote Optional
Relocation Offered:No
Travel Requirements:Up to 25%

You power our progress through your performance.

We want your work at Amtrak to be more than a job. We want your career at Amtrak to be a fulfilling experience where you find challenging work, rewarding opportunities, respect among colleagues, and attractive compensation. Amtrak maintains a culture that values high performance and recognizes individual employee contributions.


Amtrak is committed to a safe workplace free of drugs and alcohol. All Amtrak positions requires a pre-employment background check that includes prior employment verification, a criminal history check and a pre-employment drug screen.


Candidates who test positive for marijuana will be disqualified, regardless of any state or local statute, ordinance, regulation, or other law that legalizes or decriminalizes the use or possession of marijuana, whether for medical, recreational, or other use. Amtrak's pre-employment drug testing program is administered in accordance with DOT regulations and applicable law.


In accordance with DOT regulations (49 CFR § 40.25), Amtrak is required to obtain prior drug and alcohol testing records for applicants/employees intending to perform safety-sensitive duties for covered Department of Transportation positions. If an applicant/employee refuses to provide written consent for Amtrak to obtain these records, the individual will not be permitted to perform safety-sensitive functions.

In accordance with federal law governing security checks of covered individuals for providers of public transportation (Title 6 U.S.C. §1143), Amtrak is required to screen applicants for any permanent or interim disqualifying criminal offenses.


Note that any education requirement listed above may be deemed satisfied if you have an equivalent combination of education, training and experience.


Amtrak is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race/color, to include traits historically associated with race, including but not limited to, hair texture and hairstyles such as braids, locks and twists, religion, sex (including pregnancy, childbirth and related conditions, such as lactation), national origin/ethnicity, disability (intellectual, mental and physical), veteran status, marital status, ancestry, sexual orientation, gender identity and gender expression, genetic information, citizenship or any other personal characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, DT Threat Detection & Engineering- 90284261 - null
Director, DT Threat Detection & Engineering- 90284261 - null

Amtrak • Northern (KY)

Hybrid
USD 179,000 - 232,000
Health Insurance
Dental Insurance
Vision Insurance
+3
Sr Mgr. Cyber Threat Intelligence - 90397460
Sr Mgr. Cyber Threat Intelligence - 90397460

Amtrak • Washington

On-site
USD 149,000 - 194,000
Health Insurance
401K with Employer Match
Paid Time Off
+2
Sr Principal DT Security Engineer - 90343213 - Remote
Sr Principal DT Security Engineer - 90343213 - Remote

Amtrak • United States

Hybrid
USD 149,000 - 194,000
Health and wellbeing programs
401K with employer match
Paid time off
+2
Sr Mgr Digital Technology - Physical Security Systems
Sr Mgr Digital Technology - Physical Security Systems

Amtrak • Wilmington (DE)

On-site
USD 149,000 - 194,000
Health, Dental, Vision
401K with employer match
Rail Pass Privileges
Lead Network Engineer - Washington DC, Phila, Wilmington, Chicago
Lead Network Engineer - Washington DC, Phila, Wilmington, Chicago

Amtrak • Wilmington (DE)

On-site
USD 104,000 - 134,000
Health and Wellbeing
401K with Employer Match
Paid Time Off
+2
Sr Software Engineer - 90404987 Job Details | Amtrak
Sr Software Engineer - 90404987 Job Details | Amtrak

Amtrak • Washington

On-site
USD 119,162,000 - 154,286,000
Health, dental, vision plans
401K retirement plan with employer-"“맞
Principal Incident Response Analyst - 90397446 - null
Principal Incident Response Analyst - 90397446 - null

Amtrak • United States

Hybrid
USD 125,000 - 161,000
Health and Wellbeing
401K with Employer Match
Paid Time Off
+1
Sr Principal Systems Engineer - 90394673 - Philadelphia Job Details | Amtrak
Sr Principal Systems Engineer - 90394673 - Philadelphia Job Details | Amtrak

Amtrak • New York (NY)

On-site
USD 136,000 - 176,000
Health and Wellbeing
Financial and Retirement
Paid Time Off
+1
Lead Compliance Analyst / Safety Auditor - 90205030 - WIL / PHL / CHI / DC / BOS / NY
Lead Compliance Analyst / Safety Auditor - 90205030 - WIL / PHL / CHI / DC / BOS / NY

Amtrak • Wilmington (DE)

On-site
USD 94,000 - 122,000
Health, Dental, Vision Insurance
401K with Employer Match
Generous Paid Time Off
+6
Principal Software Engineer - 90402969
Principal Software Engineer - 90402969

Amtrak • Wilmington (DE)

On-site
USD 124,000 - 162,000
Health, dental, and vision plans
401(k) retirement plan with employer match
Paid time off
+2