Principal Incident Response Analyst – 90406800 – Remote
Amtrak
United States
The Role
The role sits within a Cyber Fusion Center and centres on end-to-end incident response: investigating and containing security breaches, conducting host, network, memory and log forensics, triaging malware, and identifying attacker TTPs and IOCs. The analyst also supports tabletop exercises, crisis management, and cross-functional incident coordination across both IT and OT environments.
Skills & Experience
Candidates should bring hands-on experience with SIEM platforms, network security tooling, and log analysis, alongside proficiency in PowerShell, Python or JavaScript. Familiarity with the MITRE ATT&CK framework, fileless and nation-state malware analysis, and certifications such as GCIH or GCFA are strongly preferred. OT/ICS/SCADA exposure is a bonus.
Who It Suits
This role suits a seasoned DFIR professional comfortable operating independently on high-profile, complex incidents in a large enterprise or critical-infrastructure environment. Those with a background spanning both offensive security concepts and deep forensic analysis, who can communicate effectively with legal, executive and operational stakeholders, will thrive here.
Typical advertised salary for Incident Response roles in United States: $125,000–$180,000 (median $150,000 — from 154 recent listings analysed by Forensic Focus).
Compare Incident Response salaries in United States →
Certifications mentioned: GCFA · GCIH — find training for these on the DFIR Training Finder.





