Jobs · Management

Principal Incident Response Analyst - 90406800 - Remote

Amtrak · United States · 3 wk ago
RemoteRemoteManagementFull-time

About the Role

The Principal Incident Response Analyst will play a critical role within the Amtrak Cyber Fusion Center. In this role, you will support a digital forensic cyber incident response team to effectively respond to and recover from cybersecurity incidents. You will execute the cyber incident response plan, response playbooks, and ensure timely resolution of security breaches.

As a Principal Cyber Threat Incident Response Analyst, you will provide industry-leading cyber incident response supporting the Cyber Fusion Center mission to detect and respond to threats, reducing the overall impact of business risk before, during, and after an incident. You will resolve security incidents quickly, effectively, and at scale with complete incident response including investigation, containment, and crisis management.

Responsibilities

  • Technically navigate critical and high-profile incidents, performing digital forensic and incident response analysis with support from threat hunting and malware triage analysts.
  • Support Amtrak-wide cyber incident response engagements, examining cloud, endpoint, and network-based sources of evidence.
  • Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) that can be applied to current and future investigations.
  • Perform IT and OT network analysis and forensics, including handling malware and malicious code reverse engineering, malware analysis, memory analysis, fileless malware analysis, and nation-state actor malware investigations.
  • Build scripts, tools, or methodologies to enhance Amtrak’s incident investigation processes.
  • Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.
  • Support Cyber Incident Exercises, Tabletops, and the Cyber Incident Management Response Team with business leaders, stakeholders, and cross-functional teams.
  • Coordinate with Crisis Management, Emergency Management, Incident Response, Legal, and OIG teams to conduct and manage Cyber Incident Response Activities.
  • Regularly participate in tabletop exercises designed to identify gaps, improve skills, enhance communication, and engage with stakeholders.
  • Review technical reports from vulnerability and penetration testing assessments, as well as results from tabletop exercises to identify potential future incidents.
  • Develop, refine, recommend, and maintain playbooks, policies, and procedures to ensure alignment with industry best practices.

Requirements

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related technical field plus 7-10 years of relevant experience.
  • Experience in one or a combination of the following areas to satisfy education and experience requirements:
    • Incident Response
    • Vulnerability Management
    • Digital Forensics
    • Network or Cloud Security
    • Penetration Testing
  • One Incident Response Centric Certification such as:
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Response and Industrial Defense (GRID)
    • GIAC Battlefield Forensics and Acquisition (GBFA)
    • GIAC Certified Forensic Examiner (GCFE)
    • GIAC Advanced Smartphone Forensics
    • GIAC Certified Forensic Analyst (GCFA)
    • GIAC Network Forensic Analyst (GNFA)
    • GIAC Reverse Engineering Malware (GREM)
    • EC-Council Certified Incident Handler (E|CIH)
    • eLearnSecurity Incident Handling & Response Professional (IHRP)
    • SEI Computer Security Incident Handler (CSIH)
    • NICCS Certified Incident Handler Engineer (CIHE)
  • In-depth understanding of threats, vulnerabilities, and principles of incident response and chain of custody.
  • Hands-on experience with forensics tools and log correlation.
  • Ability to think like an attacker and hunt within the security tool stack.
  • Ability to incorporate the MITRE ATT&CK Framework in everyday processes.

Preferred Qualifications

  • Master's degree in Cybersecurity, Information Technology, Digital Forensics, Computer Science, or an equivalent technical field.
  • 10+ years of experience within the cybersecurity field.
  • Basic knowledge of Operational Technology (OT), SCADA, HVAC, and/or IoT.
  • Two or more incident response centric certifications from the list above.
  • Preferred knowledge and familiarity with cybersecurity certifications, courses, or hands-on experience in:
    • Advanced Threat Detection
    • Hacker tools and techniques
    • Penetration Testing, Exploit Writing, and Ethical Hacking
    • Offensive Security, Security Operations, Web Application Testing, or Cloud Security
    • Reverse-Malware Engineering
    • Digital Forensics and Incident Response
    • PowerShell, JavaScript, and Python
  • Experience with using SIEM systems, network security tools, and log analysis tools.
  • Experience with the Mitre ATT&CK framework, threat intelligence, vulnerability management, and security incident response.

Work Environment

Amtrak offers several options for a working environment including 100% remote, on-site, and/or a hybrid schedule. This position requires off-hours work and on-call participation. Headquarters may be in any one of Amtrak’s locations across the United States, and the ability and willingness to travel up to 30% to other office locations is required.

Must have excellent oral and written communication skills.

Pay

The salary range for this position is $124,600.00 – $161,352.00. Pay is based on several factors including but not limited to education, work experience, and certifications. Depending on an employee’s assigned worksite or location, Amtrak may consider a geo-pay differential to be applied to the employee’s base salary. Amtrak may offer additional incentive and pay programs to recognize and reward employees, including a short-term incentive bonus based on individual and company performance.

Benefits

  • Health, Dental, and Vision Insurance
  • 401K with Employer Match
  • Generous Paid Time Off
  • Wellness Programs
  • Railroad Retirement Benefits
  • Paid Caregiving Days and Backup Care
  • Health Savings Account
  • Public Service Student Loan Forgiveness
  • Fertility and Family Building Benefits
  • No-cost Personal Health Advocate
  • Student Loan Assistance
  • Adoption and Surrogacy Assistance
  • Medical Plan Opt-out Credit
  • Tuition and Education Reimbursement
  • Paid Family Leave
  • Life Insurance
  • Rail Pass Privileges
  • Short- and Long-term Disability Insurance
  • Employee Assistance Program
  • No-cost Financial Advisor Sessions
  • Commuter and Flexible Spending Accounts

Similar jobs