Fall 2026/Spring - Cyber Incident Response Analyst Intern - 90413071 -
US
As we move America’s workforce toward the future, our goal is to connect businesses and communities across the country. The safety of our passengers, our more than 20,000 colleagues, the public and our operating environment is our priority, and the success of our railroad is due to your efforts
Our values of ‘Do the Right Thing, Excel Together and Put Customers First are at the heart of what matters most to us, and our Core Capabilities, Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security’ are what every employee needs to know and do to be most impactful at Amtrak. By living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.
Position Summary
The Cyber Incident Response Analyst Intern will support the Cyber Fusion Center's mission to effectively detect, investigate, respond to, and recover from cybersecurity threats and incidents. This internship is designed for students pursuing a degree in Cybersecurity or a related field who are interested in gaining hands-on experience in cyber incident response, digital forensics, threat operations, and cybersecurity program development. The intern will work alongside experienced incident responders and cybersecurity professionals to help document processes, develop standard operating procedures (SOPs), create workflow diagrams, support incident response exercises, and enhance the team's operational maturity.
A significant focus of this role will be on translating technical incident response activities into repeatable, documented processes that improve consistency, efficiency, and organizational readiness.
Essential Functions
Incident Response Program Support
- Cyber Incident Response Analysts during cyber incident investigations and response activities.
- Observe and support incident response processes involving endpoint, network, cloud, and log-based investigations.
- Assist with collecting, organizing, and documenting information related to security investigations and response activities.
- Support the maintenance of incident records, lessons learned, and post-incident documentation.
Standard Operating Procedure (SOP) Development
- Develop, review, and maintain incident response standard operating procedures, workflows, job aids, and process documentation.
- Collaborate with team members to capture current-state operational processes and identify opportunities for process standardization.
- Convert technical response activities into documented procedures that can be consistently followed during cyber incidents.
- Assist with maintaining incident response playbooks and operational runbooks.
Process Mapping and Diagramming
- Create visual process maps, workflow diagrams, Swimlane diagrams, and response flowcharts that document Cyber Fusion Center operations.
- Document relationships between Cyber Threat Intelligence, Threat Hunt, Threat Operations, Cyber Engineering, Threat Command Center, Incident Response, Legal, Crisis Management, and other stakeholder teams.
- Develop diagrams illustrating incident response workflows, escalation paths, evidence collection processes, and communication procedures.
- Support continuous improvement initiatives through documentation and visualization of operational processes.
Operational Readiness and Exercises
- Assist in planning, documenting, and supporting cyber incident tabletop exercises and incident response simulations.
- Document exercise objectives, observations, after-action reports, and improvement recommendations.
- Help maintain exercise materials and response documentation used for training and team readiness activities.
Reporting and Analysis Support
- Assist with developing reports, presentations, dashboards, and summaries for technical and non-technical audiences.
- Support documentation of threat actor tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and investigation findings.
- Perform research on cybersecurity trends, frameworks, and industry best practices to support process improvement initiatives.
Minimum Qualifications
- Must be actively pursuing a Bachelor's or Master's degree from an accredited institution.
- Must be enrolled in a Cybersecurity, Information Security, Computer Science, Information Technology, Digital Forensics, Cyber Operations, or related program.
- Must have completed at least one year of undergraduate coursework or possess sophomore standing at minimum.
- Must maintain a cumulative GPA of 2.8 or higher.
- Must demonstrate strong written communication and technical documentation skills.
Preferred Qualifications
- Cybersecurity fundamentals knowledge
- Network security knowledge
- Incident response knowledge
- Digital forensics knowledge
PAY TRANSPARENCY:
The hourly range is $18.00 per hour - $35.00 per hour. Pay is based on factors including school year, program of study, etc. In addition, paid internships include Amtrak rail pass privileges as a part of the experience along with one (1) PTO day per academic year.
Requisition ID:167077
Work Arrangement:06-Onsite 4/5 Days Click here for more information about work arrangements at Amtrak.
Relocation Offered:No
Travel Requirements:Up to 25%
You power our progress through your performance.
We want your work at Amtrak to be more than a job. We want your career at Amtrak to be a fulfilling experience where you find challenging work, rewarding opportunities, respect among colleagues, and attractive compensation. Amtrak maintains a culture that values high performance and recognizes individual employee contributions.
Amtrak is committed to a safe workplace free of drugs and alcohol. All Amtrak positions requires a pre-employment background check that includes prior employment verification, a criminal history check and a pre-employment drug screen.
Candidates who test positive for marijuana will be disqualified, regardless of any state or local statute, ordinance, regulation, or other law that legalizes or decriminalizes the use or possession of marijuana, whether for medical, recreational, or other use. Amtrak's pre-employment drug testing program is administered in accordance with DOT regulations and applicable law.
In accordance with DOT regulations (49 CFR § 40.25), Amtrak is required to obtain prior drug and alcohol testing records for applicants/employees intending to perform safety-sensitive duties for covered Department of Transportation positions. If an applicant/employee refuses to provide written consent for Amtrak to obtain these records, the individual will not be permitted to perform safety-sensitive functions.
In accordance with federal law governing security checks of covered individuals for providers of public transportation (Title 6 U.S.C. §1143), Amtrak is required to screen applicants for any permanent or interim disqualifying criminal offenses.
Note that any education requirement listed above may be deemed satisfied if you have an equivalent combination of education, training and experience.
Amtrak is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race/color, to include traits historically associated with race, including but not limited to, hair texture and hairstyles such as braids, locks and twists, religion, sex (including pregnancy, childbirth and related conditions, such as lactation), national origin/ethnicity, disability (intellectual, mental and physical), veteran status, marital status, ancestry, sexual orientation, gender identity and gender expression, genetic information, citizenship or any other personal characteristics protected by law.