... digital forensic cyber incident response team to effectively respond to and recovering from ... Amtrak offers several options for a working environment including 100% remote, on-site, and/or a ...
... digital forensic cyber incident response team to effectively respond to and recovering from ... Amtrak offers several options for a working environment including 100% remote, on-site, and/or a ...
Senior Information Security Analyst (Incident Response)
Carolina, RI · Remote
$140K - $188K/yr
Overview This is a remote role that may be hired in several markets across the United States. As a ... Incident Responder/Incident Lead - Lead Incidents, coordinating the investigation, mitigation, and ...
New
Senior Information Security Analyst (Incident Response)
Carolina, RI · Remote
$140K - $188K/yr
Overview This is a remote role that may be hired in several markets across the United States. As a ... Incident Responder/Incident Lead - Lead Incidents, coordinating the investigation, mitigation, and ...
New
Senior Information Security Analyst (Incident Response)
Raleigh, NC · Remote
$140K - $188K/yr
Overview This is a remote role that may be hired in several markets across the United States. As a ... Incident Responder/Incident Lead - Lead Incidents, coordinating the investigation, mitigation, and ...
New
Senior Information Security Analyst (Incident Response)
Raleigh, NC · Remote
$140K - $188K/yr
Overview This is a remote role that may be hired in several markets across the United States. As a ... Incident Responder/Incident Lead - Lead Incidents, coordinating the investigation, mitigation, and ...
New
Senior Information Security Analyst (Incident Response)
Carolina, RI · Remote
$140K - $188K/yr
Overview This is a remote role that may be hired in several markets across the United States. As a ... Incident Responder/Incident Lead - Lead Incidents, coordinating the investigation, mitigation, and ...
New
Senior Information Security Analyst (Incident Response)
Carolina, RI · Remote
$140K - $188K/yr
Overview This is a remote role that may be hired in several markets across the United States. As a ... Incident Responder/Incident Lead - Lead Incidents, coordinating the investigation, mitigation, and ...
New
Senior Information Security Analyst (Incident Response)
Raleigh, NC · Remote
$140K - $188K/yr
Overview This is a remote role that may be hired in several markets across the United States. As a ... Incident Responder/Incident Lead - Lead Incidents, coordinating the investigation, mitigation, and ...
New
Senior Information Security Analyst (Incident Response)
Raleigh, NC · Remote
$140K - $188K/yr
Overview This is a remote role that may be hired in several markets across the United States. As a ... Incident Responder/Incident Lead - Lead Incidents, coordinating the investigation, mitigation, and ...
New
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
Senior Cyber Incident Response Attorney
Miami, FL · On-site +1
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
Senior Cyber Incident Response Attorney
Miami, FL · On-site +1
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
Senior Cyber Incident Response Attorney
Atlanta, GA · On-site +1
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
Senior Cyber Incident Response Attorney
Atlanta, GA · On-site +1
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
Senior Cyber Incident Response Attorney
Boston, MA · On-site +1
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
Senior Cyber Incident Response Attorney
Boston, MA · On-site +1
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
Senior Cyber Incident Response Attorney
New York, NY · On-site +1
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
Senior Cyber Incident Response Attorney
New York, NY · On-site +1
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Taking lead responsibility in responding to clients and carriers, and overseeing breach response ...
Incident Responder (Tier 2)
$80K - $90K/yr
As a Senior Incident Responder, you will play a crucial role as an independent contributor and an ... Remote Company, within the USA - Comprehensive Medical, Dental, and Vision plans with a 100 ...
Incident Responder (Tier 2)
$80K - $90K/yr
As a Senior Incident Responder, you will play a crucial role as an independent contributor and an ... Remote Company, within the USA - Comprehensive Medical, Dental, and Vision plans with a 100 ...
Cyber Analyst, Digital Forensics Incident Response
$80K - $115K/yr
Intrusion detection / cyber threat hunting * Malware analysis * Incident recovery activities such ... Fully Remote Our estimated base pay range for this role is $80,000-$115,000 per year. Base salary ...
Cyber Analyst, Digital Forensics Incident Response
$80K - $115K/yr
Intrusion detection / cyber threat hunting * Malware analysis * Incident recovery activities such ... Fully Remote Our estimated base pay range for this role is $80,000-$115,000 per year. Base salary ...
Sr. Cyber Analyst, Digital Forensics Incident Response
$130K - $150K/yr
Intrusion detection / cyber threat hunting * Malware analysis * Incident recovery activities such ... Remote Position Our estimated base pay range for this role is $130,000-$150,000 per year. Base ...
Sr. Cyber Analyst, Digital Forensics Incident Response
$130K - $150K/yr
Intrusion detection / cyber threat hunting * Malware analysis * Incident recovery activities such ... Remote Position Our estimated base pay range for this role is $130,000-$150,000 per year. Base ...
CFC Senior Enterprise Security Incident Manager
$153K - $275K/yr
... our cyber resilience. Must be available to respond to after-hours pages for potentially major ... Flexible work environment, ability to work remote, hybrid or in-office. * Flexible time off ...
New
CFC Senior Enterprise Security Incident Manager
$153K - $275K/yr
... our cyber resilience. Must be available to respond to after-hours pages for potentially major ... Flexible work environment, ability to work remote, hybrid or in-office. * Flexible time off ...
New
Senior Cyber Incident Response Attorney
New York, NY · On-site +1
$155K - $200K/yr
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Responding to regulatory investigations arising out of a data breach * Defending privacy lawsuits
Quick apply
Senior Cyber Incident Response Attorney
New York, NY · On-site +1
$155K - $200K/yr
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Responding to regulatory investigations arising out of a data breach * Defending privacy lawsuits
Senior Cyber Incident Response Attorney
Washington, DC · On-site +1
$155K - $200K/yr
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Responding to regulatory investigations arising out of a data breach * Defending privacy lawsuits
Quick apply
Senior Cyber Incident Response Attorney
Washington, DC · On-site +1
$155K - $200K/yr
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Responding to regulatory investigations arising out of a data breach * Defending privacy lawsuits
Senior Cyber Incident Response Attorney
New Orleans, LA · On-site +1
$96K - $123K/yr
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Responding to regulatory investigations arising out of a data breach * Defending privacy lawsuits
Quick apply
Senior Cyber Incident Response Attorney
New Orleans, LA · On-site +1
$96K - $123K/yr
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Responding to regulatory investigations arising out of a data breach * Defending privacy lawsuits
Senior Cyber Incident Response Attorney
Miami, FL · On-site +1
$95K - $123K/yr
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Responding to regulatory investigations arising out of a data breach * Defending privacy lawsuits
Quick apply
Senior Cyber Incident Response Attorney
Miami, FL · On-site +1
$95K - $123K/yr
This is a fully remote position. The Position This is a excellent opportunity for cybersecurity ... Responding to regulatory investigations arising out of a data breach * Defending privacy lawsuits
Remote Cyber Incident Responder information
See salary details
$65.5K - $74.3K
8% of jobs
$74.3K - $83K
1% of jobs
$83K - $91.8K
5% of jobs
$100K is the 25th percentile. Wages below this are outliers.
$91.8K - $100.6K
12% of jobs
$100.6K - $109.4K
11% of jobs
The median wage is $116.7K / yr.
$109.4K - $118.1K
16% of jobs
$118.1K - $126.9K
18% of jobs
$129.3K is the 75th percentile. Wages above this are outliers.
$126.9K - $135.7K
15% of jobs
$135.7K - $144.5K
8% of jobs
$144.5K - $153.2K
6% of jobs
$153.2K - $162K
0% of jobs
$65.5K
$116K
$162K
How much do remote cyber incident responder jobs pay per year?
How does a remote cyber incident responder typically coordinate with on-site IT teams during an active security incident?
What does a remote cyber incident responder do?
What is the difference between Remote Cyber Incident Responder vs Remote Security Analyst?
| Aspect | Remote Cyber Incident Responder | Remote Security Analyst |
|---|---|---|
| Certifications | GCIH, CISSP, CEH | CISSP, Security+, CEH |
| Work Environment | Responds to active security incidents, often in crisis situations | Monitors security systems, analyzes threats, and implements security measures |
| Employer & Industry Usage | Cybersecurity firms, large corporations, government agencies | Organizations with security teams, IT departments, consulting firms |
Remote Cyber Incident Responders focus on reacting to and managing active security breaches, while Remote Security Analysts monitor systems and analyze threats proactively. Both roles require similar certifications and often work within the same industry environments, but their core responsibilities differ in response versus prevention.
What are the key skills and qualifications needed to thrive as a remote cyber incident responder, and why are they important?
- Director Digital Forensics Incident Response
- Remote Cyber Incident Response
- Digital Forensics Incident Response
- Night Shift Digital Forensics Incident Response
- Internship Digital Forensics Incident Response
- Dfir Analyst Salary
- Director Cyber Incident Response
- Remote Network Forensics
- Volunteer Wsdot Incident Response Team
- Incident Response Intern

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 7 days ago
Amtrak rating
8.0
Based on 146 frontline employees who took The Breakroom Quiz
39th of 97 rated public transport
Job description
As we move America's workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.
Are you ready to join our team?
Our values of 'Do the Right Thing, Excel Together and Put Customers First' are at the heart of what matters most to us, and our Core Capabilities, 'Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security' are what every employee needs to know and do to be most impactful at Amtrak. By living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.
JOB SUMMARY:
The Principal Incident Response Analyst will play a critical role within the Amtrak Cyber Fusion Center. In this role, you will support a digital forensic cyber incident response team to effectively respond to and recovering from cybersecurity incidents. You will execute the cyber incident response plan, response playbooks, and will ensuring timely resolution of security breaches.
ESSENTIAL FUNCTIONS:
- As a Principal Cyber Threat Incident Response Analyst, you will provide industry-leading cyber incident response supporting the Cyber Fusion Center mission to effectively detect and respond to threats and reduce the overall impact of business risk before, during, and after an incident.
- You will be able to resolve security incidents quickly, effectively and at scale with complete incident response including investigation, containment to support effective remediation, and crisis management.
- In this role, you will technically navigate critical and high-profile incidents, performing digital forensic and incident response analysis with support from threat hunting, and malware triage analysts,
- Support Amtrak-wide cyber incident response engagements, examine cloud, endpoint, and network-based sources of evidence.
- Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) that can be applied to current and future investigations.
- Both IT and OT Network analsis and forencis.
- Experience handlig Malware and Malicious Code Reverse Engineering, Malware Analysis, Memory Analysis, Fileless Malware Analysis and Nation state actor malware investigations.
- Build scripts, tools, or methodologies to enhance Amtrak's incident investigation processes.
- Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.
- Support Cyber Incident Exercises, Tabletops, and Cyber Incident Management Response Team with business leaders, stakeholders, and cross-functional teams.
- Support with Crisis Management, Emergency Management, Incident Response, Legal and OIG teams to conduct and coordinate on Cyber Incident Response Activities.
- Preferred knowledge and familiarity with Operational Technology (OT), Industrial Controls Systems (ICS) or Supervisory Control and Data Acquisition (SCADA) systems but not required.
- Cybersecurity certifications, courses, or hands-on experience with some of the following:
- Advanced Threat Detection
- Hacker tools, techniques
- Penetration Testing, Exploit Writing, and Ethical Hacking
- Offensive Security, Security Operations, Web Application Testing, or Cloud Security
- Reverse-Malware Engineering
- Digital Forensics and Incident Response
- PowerShell, JavaScript and Python
- Relevant certifications including GIAC Certified Incident Handler (GCIH), Certified Incident Response Handler (GCFA) or similar
- Experience with using SIEM systems, network security tools, and log analysis tools
- Experience with cyber incident response
- Experience with Mitre ATT&CK framework
- Experience with threat intelligence, vulnerability management, and security incident response
- Regularly participate in tabletop exercises designed to identify gaps, improve skills, enhance communication, and engage with stakeholders.
- Review technical reports from vulnerability and penetration testing assessments, as well as results from tabletop exercise to identify potential future incidents.
- Develop, refine, recommend, and maintain playbooks, policies, and procedures to ensure alignment to industry best practices.
MINIMUM QUALIFICATIONS:
- Bachelor's degree in computer science, Information Systems, Cybersecurity, or related technical field plus 7-10 years of relevant experience is required.
- Experience on one or the combination of the below to satisfy education and experience requirements:
- Incident Response
- Vulnerability Management
- Digital Forensics
- Network or Cloud Security
- Penetration Testing
One incident response centric certification:
-
- GIAC Certified Incident Handler (GCIH)
- GIAC Response and Industrial Defense (GRID)
- GIAC Battlefield Forensics and Acquisition (GBFA)
- GIAC Certified Forensic Examiner (GCFE)
- GIAC Advanced Smartphone Forensics
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Network Forensic Analyst (GNFA)
- GIAC Reverse Engineering Malware (GREM)
EC-Council Certified Incident Handler (E|CIH) - eLearnSecurity Incident Handling & Response Professional (IHRP)
- SEI Computer Security Incident Handler (CSIH)
- NICCS Certified Incident Handler Engineer (CIHE)
In depth understanding of threats, vulnerabilities and principals of incident response and chain of custody.
-
- Hands on experience with forensics tools and log correlation.
- Ability to think like an attacker and hunt within the security tool stack.
- Ability to incorporate the MITRE ATT&CK Framework in everyday processes.
PREFERRED QUALIFICATIONS:
- Master's degree in Cybersecurity, Information Technology, Digital Forensics, Computer Science, or equivalent technical field
- 10+ years of experience within the cybersecurity field
- Basic knowledge of Operation Technology (OT), SCADA, HVAC and/or IoT
- Two or more incident response centric certifications:
- GIAC Certified Incident Handler (GCIH)
- GIAC Response and Industrial Defense (GRID)
- GIAC Battlefield Forensics and Acquisition (GBFA)
- GIAC Advanced Smartphone Forensics
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Network Forensic Analyst (GNFA)
- GIAC Reverse Engineering Malware (GREM)
- EC-Council Certified Incident Handler (E|CIH)
- SEI Computer Security Incident Handler (CSIH)
- NICCS Certified Incident Handler Engineer (CIHE)
- eLearnSecurity Incident Handling & Response Professional (IHRP)
- GIAC Certified Forensic Examiner (GCFE).
WORK ENVIRONMENT:
Amtrak offers several options for a working environment including 100% remote, on-site, and/or a hybrid schedule.
This is a position that requires off-hours work and on-call participation.
Please note your headquarters office may be in any one of Amtrak's locations across the United States. The ability and willingness to travel up to 30% to other office locations is required.
COMMUNICATIONS AND INTERPERSONAL SKILLS:
Must have excellent oral and written communication skills.
The salary/hourly range is $124,600.00 - $161,352.00. Pay is based on several factors including but not limited to education, work experience, certifications, etc. Depending on an employee's assigned worksite or location, Amtrak may consider a geo-pay differential to be applied to the employee's base salary. Amtrak may offer additional incentive and pay programs to recognize and reward our employees, including a short-term incentive bonus based upon factors such as individual and company performance that is commensurate with the level of the position.
Health and WellbeingFinancial and RetirementWork and Family Life SupportHealth, Dental, and Vision Insurance401K with Employer MatchGenerous Paid Time Off Wellness ProgramsRailroad Retirement BenefitsPaid Caregiving Days and Backup CareHealth Savings AccountPublic Service Student Loan ForgivenessFertility and Family Building BenefitsNo-cost Personal Health AdvocateStudent Loan AssistanceAdoption and Surrogacy AssistanceMedical Plan Opt-out CreditTuition and Education ReimbursementPaid Family Leave Life InsuranceRail Pass Privileges Short- and Long-term Disability InsuranceEmployee Assistance Program No-cost Financial Advisor SessionsCommuter and Flexible Spending Accounts
Learn more about our benefits offerings here.
Requisition ID:166962
Work Arrangement:02-Remote Optional Click here for more information about work arrangements at Amtrak.
Relocation Offered:No
Travel Requirements:Up to 25%
You power our progress through your performance.
We want your work at Amtrak to be more than a job. We want your career at Amtrak to be a fulfilling experience where you find challenging work, rewarding opportunities, respect among colleagues, and attractive compensation. Amtrak maintains a culture that values high performance and recognizes individual employee contributions.
Amtrak is committed to a safe workplace free of drugs and alcohol. All Amtrak positions requires a pre-employment background check that includes prior employment verification, a criminal history check and a pre-employment drug screen.
Candidates who test positive for marijuana will be disqualified, regardless of any state or local statute, ordinance, regulation, or other law that legalizes or decriminalizes the use or possession of marijuana, whether for medical, recreational, or other use. Amtrak's pre-employment drug testing program is administered in accordance with DOT regulations and applicable law.
In accordance with DOT regulations (49 CFR § 40.25), Amtrak is required to obtain prior drug and alcohol testing records for applicants/employees intending to perform safety-sensitive duties for covered Department of Transportation positions. If an applicant/employee refuses to provide written consent for Amtrak to obtain these records, the individual will not be permitted to perform safety-sensitive functions.
In accordance with federal law governing security checks of covered individuals for providers of public transportation (Title 6 U.S.C. §1143), Amtrak is required to screen applicants for any permanent or interim disqualifying criminal offenses.
Note that any education requirement listed above may be deemed satisfied if you have an equivalent combination of education, training and experience.
Amtrak is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race/color, to include traits historically associated with race, including but not limited to, hair texture and hairstyles such as braids, locks and twists, religion, sex (including pregnancy, childbirth and related conditions, such as lactation), national origin/ethnicity, disability (intellectual, mental and physical), veteran status, marital status, ancestry, sexual orientation, gender identity and gender expression, genetic information, citizenship or any other personal characteristics protected by law.
About Amtrak
Sourced by ZipRecruiter
As we move America's workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.
Industry
Travel arrangement services
Company size
10,000+ Employees
Headquarters location
Washington, DC, US
Year founded
1971