← All jobs · More in this country

Principal Incident Response Analyst – 90406800 – Remote

Amtrak

United States

Remote · Lead/Principal · Full-time

The Role

The role sits within a Cyber Fusion Center and centres on end-to-end incident response: investigating and containing security breaches, conducting host, network, memory and log forensics, triaging malware, and identifying attacker TTPs and IOCs. The analyst also supports tabletop exercises, crisis management, and cross-functional incident coordination across both IT and OT environments.

Skills & Experience

Candidates should bring hands-on experience with SIEM platforms, network security tooling, and log analysis, alongside proficiency in PowerShell, Python or JavaScript. Familiarity with the MITRE ATT&CK framework, fileless and nation-state malware analysis, and certifications such as GCIH or GCFA are strongly preferred. OT/ICS/SCADA exposure is a bonus.

Who It Suits

This role suits a seasoned DFIR professional comfortable operating independently on high-profile, complex incidents in a large enterprise or critical-infrastructure environment. Those with a background spanning both offensive security concepts and deep forensic analysis, who can communicate effectively with legal, executive and operational stakeholders, will thrive here.

Typical advertised salary for Incident Response roles in United States: $125,000–$180,000 (median $150,000 — from 154 recent listings analysed by Forensic Focus).

Learn More/Apply

Applications are handled entirely by the employer or the original listing site. Forensic Focus aggregates and summarises public listings; details can change after publication — always confirm on the employer's page.

Listed: 2026-08-27