×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Principal Incident Response Analyst

Job in Washington, District of Columbia, 20022, USA
Listing for: Amtrak
Full Time position
Listed on 2026-09-21
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 124600 - 161352 USD Yearly USD 124600.00 161352.00 YEAR
Job Description & How to Apply Below

Select how often (in days) to receive an alert:

Date:
Sep 15, 2026

Location:

US

Company:
Amtrak

Your success is a train ride away!

As we move America’s workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.

Are you ready to join our team?

Our values of ‘Do the Right Thing, Excel Together and Put Customers First’ are at the heart of what matters most to us, and our Core Capabilities, ‘Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security’ are what every employee needs to know and do to be most impactful  living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.

The Principal Cyber Threat Incident Response Analyst will play a critical role within the Amtrak Cyber Fusion Center. In this role, you will support a digital forensic cyber incident response team to effectively respond to and recover from cybersecurity incidents. You will serve as a subject matter expert responsible for coordinating and executing incident response activities across the organization, lead complex investigations involving suspected and confirmed cybersecurity incidents, execute the cyber incident response plan, response playbooks, and partner closely with information security leadership, business stakeholders, and cross-functional teams to ensure timely resolution of security incidents.

ESSENTIAL FUNCTIONS:
  • As a Principal Cyber Threat Incident Response Analyst, you will provide industry-leading cyber incident response supporting the Cyber Fusion Center mission to effectively detect and respond to threats and reduce the overall impact of business risk before, during, and after an incident
  • You will be able to resolve security incidents quickly, effectively and at scale with complete incident response including investigation, containment to support effective remediation, and crisis management
  • In this role, you will technically navigate critical and high-profile incidents, performing digital forensic and incident response analysis with support from threat hunting, and malware triage analysts
  • Support Amtrak-wide cyber incident response engagements, examine cloud, endpoint, and network-based sources of evidence
  • Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) that can be applied to current and future investigations
  • Conduct both IT and OT Network analysis and forensics
  • Conduct Malware and Malicious Code Reverse Engineering, Malware Analysis, Memory Analysis, Fileless Malware Analysis and Nation state actor malware investigations
  • Build scripts, tools, or methodologies to enhance Amtrak’s incident investigation processes
  • Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations
  • Support Cyber Incident Exercises, Tabletops, and Cyber Incident Management Response Team with business leaders, stakeholders, and cross-functional teams.
  • Support Crisis Management, Emergency Management, Incident Response, Legal and OIG teams to conduct and coordinate on Cyber Incident Response Activities.
  • Regularly participate in tabletop exercises designed to identify gaps, improve skills, enhance communication, and engage with stakeholders.
  • Review technical reports from vulnerability and penetration testing assessments, as well as…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary