Principal Incident Response Analyst - 90397446 - null

Amtrak

United States

Hybrid

USD 125,000 - 161,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health and Wellbeing
401K with Employer Match
Paid Time Off
Rail Pass Privileges

Job summary

Amtrak is seeking a Principal Cyber Threat Incident Response Analyst to join the Cyber Fusion Center. You will coordinate incident response across the organization, lead investigations, and execute response playbooks to reduce business risk.

You will work with security leadership and cross-functional teams to ensure timely resolution of security incidents, build playbooks, and improve Amtrak's cyber resilience through proactive safety and security practices.

Qualifications

  • Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity, or related field; or 7–10 years relevant experience.
  • Experience in incident response, vulnerability management, digital forensics, malware and code reverse engineering, memory and fileless malware analyses, nation-state malware investigations, network or cloud security, and penetration testing.
  • One incident response centric certification from the listed GIAC/EC‑Council/eLearnSecurity/NICCS/SEI families.

Responsibilities

  • Provide incident response support to detect and respond to threats across the organization.
  • Lead complex investigations, coordinate with stakeholders, and apply incident response playbooks.
  • Perform digital forensics, memory analysis, malware analysis, and containment activities.
  • Develop, refine, and maintain playbooks and procedures aligned to industry best practices.
  • Support tabletop exercises, crisis management, and cross‑functional incident response efforts.
  • Review vulnerability and penetration testing results to identify potential incidents.

Skills

Incident Response
Digital Forensics
Malware Analysis
Threat Hunting
MITRE ATT&CK
Log Correlation
Network Forensics
Cloud Security
Written Communication
Team Collaboration

Education

Bachelor's Degree in Computer Science

Job description

Your success is a train ride away!

As we move America’s workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.

Are you ready to join our team?

Our values of ‘Do the Right Thing, Excel Together and Put Customers First’ are at the heart of what matters most to us, and our Core Capabilities, ‘Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security’ are what every employee needs to know and do to be most impactful at Amtrak. By living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.

Principal Cyber Threat Incident Response Analyst

The Principal Cyber Threat Incident Response Analyst will play a critical role within the Amtrak Cyber Fusion Center. In this role, you will support a digital forensic cyber incident response team to effectively respond to and recover from cybersecurity incidents. You will serve as a subject matter expert responsible for coordinating and executing incident response activities across the organization, lead complex investigations involving suspected and confirmed cybersecurity incidents, execute the cyber incident response plan, response playbooks, and partner closely with information security leadership, business stakeholders, and cross-functional teams to ensure timely resolution of security incidents.

Essential Functions
  • As a Principal Cyber Threat Incident Response Analyst, you will provide industry-leading cyber incident response supporting the Cyber Fusion Center mission to effectively detect and respond to threats and reduce the overall impact of business risk before, during, and after an incident
  • You will be able to resolve security incidents quickly, effectively and at scale with complete incident response including investigation, containment to support effective remediation, and crisis management
  • In this role, you will technically navigate critical and high-profile incidents, performing digital forensic and incident response analysis with support from threat hunting, and malware triage analysts
  • Support Amtrak-wide cyber incident response engagements, examine cloud, endpoint, and network-based sources of evidence
  • Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) that can be applied to current and future investigations
  • Conduct both IT and OT Network analysis and forensics
  • Conduct Malware and Malicious Code Reverse Engineering, Malware Analysis, Memory Analysis, Fileless Malware Analysis and Nation state actor malware investigations
  • Build scripts, tools, or methodologies to enhance Amtrak’s incident investigation processes
  • Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations
  • Support Cyber Incident Exercises, Tabletops, and Cyber Incident Management Response Team with business leaders, stakeholders, and cross-functional teams.
  • Support Crisis Management, Emergency Management, Incident Response, Legal and OIG teams to conduct and coordinate on Cyber Incident Response Activities.
  • Regularly participate in tabletop exercises designed to identify gaps, improve skills, enhance communication, and engage with stakeholders.
  • Review technical reports from vulnerability and penetration testing assessments, as well as results from tabletop exercise to identify potential future incidents.
  • Develop, refine, recommend, and maintain playbooks, policies, and procedures to ensure alignment to industry best practices
Minimum Qualifications
  • Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity, or related technical field; or equivalent combination of education, training and/or 7-10 years relevant experience is required.
  • Basic knowledge of privacy, data protection, and compliance requirements related to incident response and breach notification, including PCI DSS, HIPAA, GDPR, CCPA, and other applicable regulatory frameworks is preferred.
  • Experience in one or a combination of the following areas can be used to satisfy education and experience requirements:
    • Incident Response
    • Vulnerability Management
    • Digital Forensics
    • Malware and Malicious Code Reverse Engineering
    • Malware Analysis
    • Memory Analysis
    • Fileless Malware Analysis
    • Nation state actor malware investigations
    • Network or Cloud Security
    • Penetration Testing
  • One incident response centric certification
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Response and Industrial Defense (GRID)
    • GIAC Battlefield Forensics and Acquisition (GBFA)
    • GIAC Certified Forensic Examiner (GCFE)
    • GIAC Advanced Smartphone Forensics
    • GIAC Certified Forensic Analyst (GCFA)
    • GIAC Network Forensic Analyst (GNFA)
    • GIAC Reverse Engineering Malware (GREM)
    • EC-Council Certified Incident Handler (E|CIH)
    • eLearnSecurity Incident Handling & Response Professional (IHRP)
    • SEI Computer Security Incident Handler (CSIH)
    • NICCS Certified Incident Handler Engineer (CIHE)
  • In depth understanding of threats, vulnerabilities and principals of incident response and chain of custody.
  • Hands on experience with forensics tools and log correlation.
  • Ability to think like an attacker and hunt within the security tool stack.
  • Ability to incorporate the MITRE ATT&CK Framework in everyday processes.
Preferred Qualifications
  • Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity or equivalent technical field plus 10+ years of relevant work experience.
  • Knowledge of privacy, data protection, and breach notification regulations and standards, including PCI DSS, HIPAA, GDPR, CCPA, and/or similar regulatory frameworks.
  • Two or more incident response centric certifications
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Response and Industrial Defense (GRID)
    • GIAC Battlefield Forensics and Acquisition (GBFA)
    • GIAC Certified Forensic Examiner (GCFE)
    • GIAC Advanced Smartphone Forensics
    • GIAC Certified Forensic Analyst (GCFA)
    • GIAC Network Forensic Analyst (GNFA)
    • GIAC Reverse Engineering Malware (GREM)
    • EC-Council Certified Incident Handler (E|CIH)
    • eLearnSecurity Incident Handling & Response Professional (IHRP)
    • SEI Computer Security Incident Handler (CSIH)
    • NICCS Certified Incident Handler Engineer (CIHE)
Knowledge, Skills And Abilities
  • Excellent written and oral communication skills to facilitate communication across all levels of the organization.
  • In depth understanding of threats, vulnerabilities and principals of incident response and chain of custody.
  • Hands on experience with forensics tools and log correlation.
  • Must possess excellent customer service, strong communication and interpersonal skills, work well with others in an integrated team environment, and must be self-motivated.
  • Must possess a high degree of integrity and trustworthiness.
  • Must have a deep understanding of computer intrusion activities, incident response techniques, tools, and procedures.
  • Ability to think like an attacker and hunt within the security tool stack.
  • Advanced proficiency with analysis and characterization of cyber0attacks (Kill Chain, MITRE ATT&CK)
  • Ability to incorporate the MITRE ATT&CK Framework in everyday processes.
Salary/Hourly Range

The salary/hourly range is $124,600.00 – $161,352.00. Pay is based on several factors including but not limited to education, work experience, certifications, etc. Depending on an employee’s assigned worksite or location, Amtrak may consider a geo-pay differential to be applied to the employee’s base salary. Amtrak may offer additional incentive and pay programs to recognize and reward our employees, including a short-term incentive bonus based upon factors such as individual and company performance that is commensurate with the level of the position.

Benefits
  • Health and Wellbeing Financial and Retirement Work and Family Life Support
  • Health, Dental, and Vision Insurance 401K with Employer Match Generous Paid Time Off
  • Wellness Programs Railroad Retirement Benefits Paid Caregiving Days and Backup Care
  • Health Savings Account Public Service Student Loan Forgiveness Fertility and Family Building Benefits
  • No-cost Personal Health Advocate Student Loan Assistance Adoption and Surrogacy Assistance
  • Medical Plan Opt-out Credit Tuition and Education Reimbursement Paid Family Leave
  • Life Insurance Rail Pass Privileges
  • Short- and Long-term Disability Insurance Employee Assistance Program
  • No-cost Financial Advisor Sessions Commuter and Flexible Spending Accounts

Learn More About Our Benefits Offerings Here.

Requisition ID

167030

Work Arrangement

02-Remote Optional Click here for more information about work arrangements at Amtrak.

Relocation Offered

No

Travel Requirements

Up to 25%

Company Vision

You power our progress through your performance.

We want your work at Amtrak to be more than a job. We want your career at Amtrak to be a fulfilling experience where you find challenging work, rewarding opportunities, respect among colleagues, and attractive compensation. Amtrak maintains a culture that values high performance and recognizes individual employee contributions.

Amtrak is committed to a safe workplace free

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Mgr. Cyber Threat Intelligence - 90397460
Sr Mgr. Cyber Threat Intelligence - 90397460

Amtrak • Washington

On-site
USD 149,000 - 194,000
Health Insurance
401K with Employer Match
Paid Time Off
+2
Principal Cybersecurity Systems Security Officer - 90307947 - null
Principal Cybersecurity Systems Security Officer - 90307947 - null

Amtrak • Northern (KY)

Hybrid
USD 113,000 - 147,000
Health Insurance
Dental Insurance
Vision Insurance
+5
Sr Principal DT Security Engineer - 90343213 - Remote
Sr Principal DT Security Engineer - 90343213 - Remote

Amtrak • United States

Hybrid
USD 149,000 - 194,000
Health and wellbeing programs
401K with employer match
Paid time off
+2
Sr Mgr Digital Technology - Physical Security Systems
Sr Mgr Digital Technology - Physical Security Systems

Amtrak • Wilmington (DE)

On-site
USD 149,000 - 194,000
Health, Dental, Vision
401K with employer match
Rail Pass Privileges
Lead Network Engineer - Washington DC, Phila, Wilmington, Chicago
Lead Network Engineer - Washington DC, Phila, Wilmington, Chicago

Amtrak • Wilmington (DE)

On-site
USD 104,000 - 134,000
Health and Wellbeing
401K with Employer Match
Paid Time Off
+2
Director of Technology, Customer Engagement Platforms - Washington DC, Philadelphia, Remote Optional
Director of Technology, Customer Engagement Platforms - Washington DC, Philadelphia, Remote Optional

Amtrak • Philadelphia

On-site
USD 179,000 - 233,000
Health, Dental, and Vision Insurance
401K with Employer Match
Generous Paid Time Off
+4
Lead Technical Recruiter - 90410602 - Washington DC / Philadelphia / Wilmington / Chicago / New York
Lead Technical Recruiter - 90410602 - Washington DC / Philadelphia / Wilmington / Chicago / New York

Amtrak • Wilmington (DE)

On-site
USD 94,000 - 123,000
Health insurance
401K with employer match
Paid time off
Sr Principal Systems Engineer - 90394673 - Philadelphia Job Details | Amtrak
Sr Principal Systems Engineer - 90394673 - Philadelphia Job Details | Amtrak

Amtrak • New York (NY)

On-site
USD 136,000 - 176,000
Health and Wellbeing
Financial and Retirement
Paid Time Off
+1
Principal Operations Research Scientist - 90028548 - Washington
Principal Operations Research Scientist - 90028548 - Washington

Amtrak • Washington

On-site
USD 125,000 - 161,000
Health insurance
401K with employer match
Paid time off
+1
Lead Compliance Analyst / Safety Auditor - 90205030 - WIL / PHL / CHI / DC / BOS / NY
Lead Compliance Analyst / Safety Auditor - 90205030 - WIL / PHL / CHI / DC / BOS / NY

Amtrak • Wilmington (DE)

On-site
USD 94,000 - 122,000
Health, Dental, Vision Insurance
401K with Employer Match
Generous Paid Time Off
+6