> Markdown version of [/jobs/ext/2097398-principal-incident-response-analyst-90397446-null](https://www.wearedevelopers.com/jobs/ext/2097398-principal-incident-response-analyst-90397446-null). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Incident Response Analyst - 90397446 - null - **Company:** Amtrak - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $124,600.0 - $161,352.0 - **Contract:** Contract - **Skills:** Software System Penetration Testing, Network Analysis, Cyber Security, Information Systems, Digital Forensics, Forensics Tools (Digital Forensics Software), Information Security Management, Log Analysis, Network Forensics, PCI Data Security Standards, Reverse Engineering, Software Vulnerability Management, Mitre Att&ck, Malware, Information Technology - **Published:** August 17, 2026 - **Apply:** https://careers.amtrak.com/talentcommunity/apply/1420017900/?locale=en_US ## About the Role * Bachelor's Degree in Computer Science, Information Systems, Cybersecurity, or related technical field; or equivalent combination of education, training and/or 7-10 years relevant experience is required. * Basic knowledge of privacy, data protection, and compliance requirements related to incident response and breach notification, including PCI DSS, HIPAA, GDPR, CCPA, and other applicable regulatory frameworks is preferred. * Experience in one or a combination of the following areas can be used to satisfy education and experience requirements: * Incident Response * Vulnerability Management * Digital Forensics * Malware and Malicious Code Reverse Engineering * Malware Analysis * Memory Analysis * Fileless Malware Analysis * Nation state actor malware investigations * Network or Cloud Security * Penetration Testing One incident response centric certification * GIAC Certified Incident Handler (GCIH) * GIAC Response and Industrial Defense (GRID) * GIAC Battlefield Forensics and Acquisition (GBFA) * GIAC Certified Forensic Examiner (GCFE) * GIAC Advanced Smartphone Forensics * GIAC Certified Forensic Analyst (GCFA) * GIAC Network Forensic Analyst (GNFA) * GIAC Reverse Engineering Malware (GREM) * EC-Council Certified Incident Handler (E|CIH) * eLearnSecurity Incident Handling & Response Professional (IHRP) * SEI Computer Security Incident Handler (CSIH) * NICCS Certified Incident Handler Engineer (CIHE) In depth understanding of threats, vulnerabilities and principals of incident response and chain of custody. Hands on experience with forensics tools and log correlation. Ability to think like an attacker and hunt within the security tool stack. Ability to incorporate the MITRE ATT&CK Framework in everyday processes., * Bachelor's Degree in Computer Science, Information Systems, Cybersecurity or equivalent technical field plus 10+ years of relevant work experience. * Knowledge of privacy, data protection, and breach notification regulations and standards, including PCI DSS, HIPAA, GDPR, CCPA, and/or similar regulatory frameworks. * Two or more incident response centric certifications * GIAC Certified Incident Handler (GCIH) * GIAC Response and Industrial Defense (GRID) * GIAC Battlefield Forensics and Acquisition (GBFA) * GIAC Certified Forensic Examiner (GCFE) * GIAC Advanced Smartphone Forensics * GIAC Certified Forensic Analyst (GCFA) * GIAC Network Forensic Analyst (GNFA) * GIAC Reverse Engineering Malware (GREM) * EC-Council Certified Incident Handler (E|CIH) * eLearnSecurity Incident Handling & Response Professional (IHRP) * SEI Computer Security Incident Handler (CSIH) * NICCS Certified Incident Handler Engineer (CIHE) KNOWLEDGE, SKILLS and ABILITIES: * Excellent written and oral communication skills to facilitate communication across all levels of the organization. * In depth understanding of threats, vulnerabilities and principals of incident response and chain of custody. * Hands on experience with forensics tools and log correlation. * Must possess excellent customer service, strong communication and interpersonal skills, work well with others in an integrated team environment, and must be self-motivated. * Must possess a high degree of integrity and trustworthiness. * Must have a deep understanding of computer intrusion activities, incident response techniques, tools, and procedures. * Ability to think like an attacker and hunt within the security tool stack. * Advanced proficiency with analysis and characterization of cyber0attacks (Kill Chain, MITRE ATT&CK) * Ability to incorporate the MITRE ATT&CK Framework in everyday processes. ## Description The Principal Cyber Threat Incident Response Analyst will play a critical role within the Amtrak Cyber Fusion Center. In this role, you will support a digital forensic cyber incident response team to effectively respond to and recover from cybersecurity incidents. You will serve as a subject matter expert responsible for coordinating and executing incident response activities across the organization, lead complex investigations involving suspected and confirmed cybersecurity incidents, execute the cyber incident response plan, response playbooks, and partner closely with information security leadership, business stakeholders, and cross-functional teams to ensure timely resolution of security incidents., * As a Principal Cyber Threat Incident Response Analyst, you will provide industry-leading cyber incident response supporting the Cyber Fusion Center mission to effectively detect and respond to threats and reduce the overall impact of business risk before, during, and after an incident * You will be able to resolve security incidents quickly, effectively and at scale with complete incident response including investigation, containment to support effective remediation, and crisis management * In this role, you will technically navigate critical and high-profile incidents, performing digital forensic and incident response analysis with support from threat hunting, and malware triage analysts * Support Amtrak-wide cyber incident response engagements, examine cloud, endpoint, and network-based sources of evidence * Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) that can be applied to current and future investigations * Conduct both IT and OT Network analysis and forensics * Conduct Malware and Malicious Code Reverse Engineering, Malware Analysis, Memory Analysis, Fileless Malware Analysis and Nation state actor malware investigations * Build scripts, tools, or methodologies to enhance Amtrak's incident investigation processes * Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations * Support Cyber Incident Exercises, Tabletops, and Cyber Incident Management Response Team with business leaders, stakeholders, and cross-functional teams. * Support Crisis Management, Emergency Management, Incident Response, Legal and OIG teams to conduct and coordinate on Cyber Incident Response Activities. * Regularly participate in tabletop exercises designed to identify gaps, improve skills, enhance communication, and engage with stakeholders. * Review technical reports from vulnerability and penetration testing assessments, as well as results from tabletop exercise to identify potential future incidents. * Develop, refine, recommend, and maintain playbooks, policies, and procedures to ensure alignment to industry best practices ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)