Sr Mgr Cyber Incident Response - null Job at Amtrak, Washington DC

QllrR0h0djhLc2xKVGRrZmw3WEhON3N6eUE9PQ==
  • Amtrak
  • Washington DC

Job Description

Sr Mgr Cyber Incident Response

Your success is a train ride away! As we move America's workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.

Are you ready to join our team? Our values of 'Do the Right Thing, Excel Together and Put Customers First' are at the heart of what matters most to us, and our Core Capabilities, 'Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security' are what every employee needs to know and do to be most impactful at Amtrak. By living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.

The Senior Manager of Cyber Threat Incident Response will play a critical role within the Amtrak Cyber Fusion Center. The successful candidate leads a digital forensic cyber incident response team to effectively respond to and recovering from cybersecurity incidents. Conduct digital forensic investigations in response to high or critical security incidents. Lead the development of digital forensic and incident response playbooks and scalable procedures, recommending technical solutions to reduce risk across the enterprise. Act as a mentor and provide guidance to team members.

Essential Functions:

  • Provide industry-leading cyber incident response leadership support to the Cyber Fusion Center mission to effectively detect and respond to threats and reduce the overall impact of business risk before, during, and after an incident
  • Resolve security incidents quickly, effectively and at scale with complete incident response including investigation, containment to support effective remediation, and crisis management
  • Technically navigate critical and high-profile incidents, performing digital forensic and incident response analysis with support from threat hunting, and malware triage analysts
  • Lead Amtrak-wide cyber incident response engagements, examine cloud, endpoint, and network-based sources of evidence
  • Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) that can be applied to current and future investigations
  • Build scripts, tools, or methodologies to enhance Amtrak's incident investigation processes
  • Lead Cyber Incident Exercises, Tabletops, and Cyber Incident Management Response Team with business leaders, stakeholders, and cross-functional teams.
  • Preferred ability for effective communication and interpersonal skills, work well with others in an integrated team environment, and must be self-motivated.
  • Preferred knowledge and familiarity with Operational Technology (OT), Industrial Controls Systems (ICS) or Supervisory Control and Data Acquisition (SCADA) systems, but not required.
  • Cybersecurity certifications, courses, or hands-on experience with some of the following:
    • Advanced Threat Detection
    • Hacker tools, techniques
    • Penetration Testing, Exploit Writing, and Ethical Hacking
    • Offensive Security, Security Operations, Web Application Testing, or Cloud Security
    • Reverse-Malware Engineering
    • Digital Forensics and Incident Response
    • PowerShell, JavaScript and Python
    • Relevant certifications including GIAC Certified Incident Handler (GCIH), Certified Incident Response Handler (GCFA) or similar
    • Experience with using SIEM systems, network security tools, and log analysis tools
    • Experience with cyber incident response
    • Experience with Mitre ATT&CK framework
    • Experience with threat intelligence, vulnerability management, and security incident response.
  • Partner with Crisis Management, Emergency Management, Incident Response, Legal and OIG teams to conduct and coordinate on Cyber Incident Response Activities.
  • Correlate threat intelligence, to develop deeper understandings of tracked threat activity.
  • Apply basic threat hunting techniques to pivot for given information to known attack patterns, malicious code families, tracked threat groups and other historical information.
  • Prepare and report risk analysis and threat findings to appropriate stakeholders.
  • Conduct cyber threat intelligence analysis, develops correlation techniques, correlates actionable cybersecurity events, participates in the coordination of resources during incident response efforts, and reports and tracks incident findings and resolutions to leadership that include trends, responses, and mitigation actions.

Minimum Qualifications:

  • Bachelor's degree in computer science, Information Systems, Software Engineering, Software Development, or relevant field, and 9+ years of relevant experience or 13+ years of relevant work experience in Cybersecurity.
  • Experience with Cyber Incident Handling, Cyber Incident Response, and/or Cyber Incident Management.
  • Must possess 3+ years of relevant experience leadership acumen focusing on developing high-performing talent.
  • Ability to switch between strategic, tactical, and operational concepts and be comfortable in either setting.
  • Ability to build and deliver executive level presentations to clients and organizational leadership.
  • Ability to develop high-performing talent.
  • Ability to think critically and like threat actors.
  • Knowledge of attack vectors, threat tactics, and attacker techniques.
  • Knowledge of penetration testing principles, tools, and techniques.
  • Knowledge of Application Security Risks (e.g., Open Web Application Security Project Top 10 list).
  • Knowledge of using a variety of forensic analysis tools in incident response investigations to determine the extent and scope of compromise.
  • Knowledge of cloud service models and how those models can limit incident response.
  • Knowledge of cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
  • Skill in protecting a network against malware. (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters).

Preferred Qualifications:

  • Cybersecurity certifications, courses, or hands-on experience with some of the following:
    • Red Team Operations and Adversary Emulation
    • Penetration Testing, Exploit Writing, and Ethical Hacking.
    • Offensive Security, Security Operations, Web Application Testing, or Cloud Security
    • Reverse-Malware Engineering
    • Digital Forensics and Incident Response
    • Cyber Deception Attack Detection, Disruption, Active Defense
    • Preferred knowledge and familiarity with Operational Technology (OT), Industrial Controls Systems (ICS) or Supervisory Control and Data Acquisition (SCADA) systems, but not required

Work Environment:

  • 100% Remote, On-site, or Hybrid options available.
  • May require occasional travel up to 25% of the time. May require occasional after hours, weekend, or periodic shift work supporting a 24x7x365 Cyber Fusion Center.

Communications and Interpersonal Skills: Must have excellent oral and written communication skills.

Job Tags

Work experience placement, Remote work, Shift work,

Similar Jobs

Global Staffing Service's

Social Media Director Job at Global Staffing Service's

 ...SOCIAL MEDIA / MARKETING DIRECTOR As part of our expansion, this growing and dynamic full-service recruitment organization...  ...Salary: Competitive base / Bonus Commute/Remote: Work remotely from your home office Travel: 20% Global Staffing Service's objective... 

HHDC

Administrative Assistant - Bilingual in Polish Preferred Job at HHDC

 ...community development has an immediate opening for a Administrative Assistant in Chicago, IL . Must be fluent in English and Polish language. The Administrative Assistant is responsible for providing clerical assistance and general backup to Property Management staff... 

Exclusive Household Staff

Live-in Nanny Job at Exclusive Household Staff

 ...Ventura County, northwest of Los Angeles, is looking for a Live-in Nanny for her 2 young children aged 6 & 7. There is also an older...  ...the children ~Running errands ~Doing the weekly food shop ~Travelling with the family during school holiday periods The family do... 

First Alliance Home Mortgage

Sr Mortgage Underwriter Job at First Alliance Home Mortgage

Senior Underwriter DE/LAPP/SAR Location: Remote Reports To: Chief Operating Officer Division: First Alliance Home Mortgage Wholesale Channel Position Summary: We are seeking a highly experienced Senior Mortgage Underwriter to join our growing wholesale team... 

JobElephant

Executive Assistant to the Chief Advancement Officer Job at JobElephant

 ...Executive Assistant to the Chief Advancement Officer Amherst Campus Full Time JR6372 Amherst has taken a leadership role among highly selective liberal arts colleges and universities in successfully diversifying the racial, socio-economic, and geographic profile...