> Markdown version of [/jobs/ext/2445389-principal-incident-response-analyst-90406800-remote](https://www.wearedevelopers.com/jobs/ext/2445389-principal-incident-response-analyst-90406800-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Incident Response Analyst - 90406800 - Remote - **Company:** Amtrak - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $124,600.0 - $161,352.0 - **Contract:** Contract - **Skills:** JavaScript (Programming Language), Software System Penetration Testing, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Digital Forensics, Forensics Tools (Digital Forensics Software), Supervisory Control and Data Acquisition (SCADA), Information Security Management, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Log Analysis, Network Forensics, Windows PowerShell, Reverse Engineering, Security Information and Event Management, Software Vulnerability Management, Web Testing, Mitre Att&ck, Malware, Cyber Threat Analysis, Information Technology, Process Control Systems, Operational Systems - **Published:** August 4, 2026 - **Apply:** https://careers.amtrak.com/talentcommunity/apply/1415197400/?locale=en_US ## About the Role * Preferred knowledge and familiarity with Operational Technology (OT), Industrial Controls Systems (ICS) or Supervisory Control and Data Acquisition (SCADA) systems but not required. * Cybersecurity certifications, courses, or hands-on experience with some of the following: + Advanced Threat Detection + Hacker tools, techniques + Penetration Testing, Exploit Writing, and Ethical Hacking + Offensive Security, Security Operations, Web Application Testing, or Cloud Security + Reverse-Malware Engineering + Digital Forensics and Incident Response + PowerShell, JavaScript and Python + Relevant certifications including GIAC Certified Incident Handler (GCIH), Certified Incident Response Handler (GCFA) or similar + Experience with using SIEM systems, network security tools, and log analysis tools + Experience with cyber incident response + Experience with Mitre ATT&CK framework + Experience with threat intelligence, vulnerability management, and security incident response * Regularly participate in tabletop exercises designed to identify gaps, improve skills, enhance communication, and engage with stakeholders. * Review technical reports from vulnerability and penetration testing assessments, as well as results from tabletop exercise to identify potential future incidents. * Develop, refine, recommend, and maintain playbooks, policies, and procedures to ensure alignment to industry best practices., * Bachelor's degree in computer science, Information Systems, Cybersecurity, or related technical field plus 7-10 years of relevant experience is required. * Experience on one or the combination of the below to satisfy education and experience requirements: + Incident Response + Vulnerability Management + Digital Forensics + Network or Cloud Security + Penetration Testing One incident response centric certification: * + GIAC Certified Incident Handler (GCIH) + GIAC Response and Industrial Defense (GRID) + GIAC Battlefield Forensics and Acquisition (GBFA) + GIAC Certified Forensic Examiner (GCFE) + GIAC Advanced Smartphone Forensics + GIAC Certified Forensic Analyst (GCFA) + GIAC Network Forensic Analyst (GNFA) + GIAC Reverse Engineering Malware (GREM) EC-Council Certified Incident Handler (E|CIH) + eLearnSecurity Incident Handling & Response Professional (IHRP) + SEI Computer Security Incident Handler (CSIH) + NICCS Certified Incident Handler Engineer (CIHE) * In depth understanding of threats, vulnerabilities and principals of incident response and chain of custody. * + Hands on experience with forensics tools and log correlation. + Ability to think like an attacker and hunt within the security tool stack. + Ability to incorporate the MITRE ATT&CK Framework in everyday processes., * Master's degree in Cybersecurity, Information Technology, Digital Forensics, Computer Science, or equivalent technical field * 10+ years of experience within the cybersecurity field * Basic knowledge of Operation Technology (OT), SCADA, HVAC and/or IoT * Two or more incident response centric certifications: + GIAC Certified Incident Handler (GCIH) + GIAC Response and Industrial Defense (GRID) + GIAC Battlefield Forensics and Acquisition (GBFA) + GIAC Advanced Smartphone Forensics + GIAC Certified Forensic Analyst (GCFA) + GIAC Network Forensic Analyst (GNFA) + GIAC Reverse Engineering Malware (GREM) + EC-Council Certified Incident Handler (E|CIH) + SEI Computer Security Incident Handler (CSIH) + NICCS Certified Incident Handler Engineer (CIHE) + eLearnSecurity Incident Handling & Response Professional (IHRP) + GIAC Certified Forensic Examiner (GCFE)., Please note your headquarters office may be in any one of Amtrak's locations across the United States. The ability and willingness to travel up to 30% to other office locations is required. COMMUNICATIONS AND INTERPERSONAL SKILLS: Must have excellent oral and written communication skills. ## Description The Principal Incident Response Analyst will play a critical role within the Amtrak Cyber Fusion Center. In this role, you will support a digital forensic cyber incident response team to effectively respond to and recovering from cybersecurity incidents. You will execute the cyber incident response plan, response playbooks, and will ensuring timely resolution of security breaches., * As a Principal Cyber Threat Incident Response Analyst, you will provide industry-leading cyber incident response supporting the Cyber Fusion Center mission to effectively detect and respond to threats and reduce the overall impact of business risk before, during, and after an incident. * You will be able to resolve security incidents quickly, effectively and at scale with complete incident response including investigation, containment to support effective remediation, and crisis management. * In this role, you will technically navigate critical and high-profile incidents, performing digital forensic and incident response analysis with support from threat hunting, and malware triage analysts, * Support Amtrak-wide cyber incident response engagements, examine cloud, endpoint, and network-based sources of evidence. * Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) that can be applied to current and future investigations. * Both IT and OT Network analsis and forencis. * Experience handlig Malware and Malicious Code Reverse Engineering, Malware Analysis, Memory Analysis, Fileless Malware Analysis and Nation state actor malware investigations. * Build scripts, tools, or methodologies to enhance Amtrak's incident investigation processes. * Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations. * Support Cyber Incident Exercises, Tabletops, and Cyber Incident Management Response Team with business leaders, stakeholders, and cross-functional teams. * Support with Crisis Management, Emergency Management, Incident Response, Legal and OIG teams to conduct and coordinate on Cyber Incident Response Activities., This is a position that requires off-hours work and on-call participation. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof](https://www.wearedevelopers.com/videos/1792-developer-time-is-valuable-use-the-right-tools-kilian-valkhof) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [A Practical Guide to Reducing Bundle Size](https://www.wearedevelopers.com/videos/1439-a-practical-guide-to-reducing-bundle-size) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Tips on mastering remote job interviews](https://www.wearedevelopers.com/magazine/23-tips-on-mastering-remote-job-interviews) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)