Principal Incident Response Analyst - 90397446 - null
Amtrak connects businesses and communities across the country, employing more than 20,000 diverse professionals. Our values of ‘Do the Right Thing, Excel Together and Put Customers First’ guide our work, alongside core capabilities including Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security.
About the role
The Principal Cyber Threat Incident Response Analyst will play a critical role within the Amtrak Cyber Fusion Center, supporting a digital forensic cyber incident response team to effectively respond to and recover from cybersecurity incidents. You will serve as a subject matter expert responsible for coordinating and executing incident response activities across the organization, leading complex investigations, and partnering with information security leadership, business stakeholders, and cross-functional teams.
Responsibilities
- Resolve security incidents quickly, effectively, and at scale with complete incident response including investigation, containment, remediation, and crisis management.
- Technically navigate critical and high-profile incidents, performing digital forensic and incident response analysis with support from threat hunting and malware triage analysts.
- Support Amtrak-wide cyber incident response engagements, examining cloud, endpoint, and network-based sources of evidence.
- Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) for current and future investigations.
- Conduct IT and OT network analysis and forensics, including malware reverse engineering, memory analysis, fileless malware analysis, and nation-state actor malware investigations.
- Build scripts, tools, or methodologies to enhance Amtrak’s incident investigation processes.
- Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.
- Support cyber incident exercises, tabletops, and the Cyber Incident Management Response Team with business leaders and stakeholders.
- Coordinate with Crisis Management, Emergency Management, Incident Response, Legal, and OIG teams on cyber incident response activities.
- Regularly participate in tabletop exercises to identify gaps, improve skills, and enhance communication.
- Review technical reports from vulnerability and penetration testing assessments to identify potential future incidents.
- Develop, refine, recommend, and maintain playbooks, policies, and procedures aligned with industry best practices.
Requirements
- Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity, or related technical field; or equivalent combination of education, training, and/or 7-10 years of relevant experience.
- Experience in one or more of the following areas: Incident Response, Vulnerability Management, Digital Forensics, Malware Reverse Engineering, Malware Analysis, Memory Analysis, Fileless Malware Analysis, Nation-State Actor Malware Investigations, Network or Cloud Security, or Penetration Testing.
- One incident response-centric certification (e.g., GCIH, GRID, GCFE, GCFA, GNFA, GREM, E|CIH, IHRP, CSIH, CIHE).
- In-depth understanding of threats, vulnerabilities, incident response principles, and chain of custody.
- Hands-on experience with forensics tools and log correlation.
- Ability to think like an attacker and hunt within the security tool stack.
- Ability to incorporate the MITRE ATT&CK Framework into everyday processes.
Preferred Qualifications
- Bachelor’s Degree in Computer Science, Information Systems, Cybersecurity, or equivalent technical field plus 10+ years of relevant work experience.
- Knowledge of privacy, data protection, and breach notification regulations (e.g., PCI DSS, HIPAA, GDPR, CCPA).
- Two or more incident response-centric certifications (e.g., GCIH, GRID, GCFE, GCFA, GNFA, GREM, E|CIH, IHRP, CSIH, CIHE).
Skills
- Excellent written and oral communication skills to facilitate collaboration across all levels of the organization.
- Advanced proficiency in analyzing and characterizing cyberattacks (Kill Chain, MITRE ATT&CK).
- Strong customer service, interpersonal skills, and ability to work in an integrated team environment.
- High degree of integrity and trustworthiness.
- Deep understanding of computer intrusion activities, incident response techniques, tools, and procedures.
Pay
The salary range for this position is $124,600.00 – $161,352.00, based on factors including education, work experience, and certifications. Depending on worksite location, Amtrak may apply a geo-pay differential to the base salary. Additional incentive programs, such as a short-term bonus, may also be offered.
Benefits
- Health, Dental, and Vision Insurance
- 401K with Employer Match
- Generous Paid Time Off and Paid Family Leave
- Wellness Programs and No-cost Personal Health Advocate
- Railroad Retirement Benefits
- Paid Caregiving Days and Backup Care
- Health Savings Account and Flexible Spending Accounts
- Public Service Student Loan Forgiveness and Student Loan Assistance
- Fertility and Family Building Benefits (Adoption and Surrogacy Assistance)
- Medical Plan Opt-out Credit
- Tuition and Education Reimbursement
- Life Insurance and Short- and Long-term Disability Insurance
- Employee Assistance Program and No-cost Financial Advisor Sessions
- Commuter Benefits
- Rail Pass Privileges
Schedule
This role follows a remote-optional work arrangement. Travel requirements may include up to 25% of the time.