Lead Threat Hunter Analyst - 90397468 - Remote
US
Your success is a train ride away!
As we move America’s workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.
Are you ready to join our team?
Our values of ‘Do the Right Thing, Excel Together and Put Customers First’ are at the heart of what matters most to us, and our Core Capabilities, ‘Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security’ are what every employee needs to know and do to be most impactful at Amtrak. By living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.
Job Summary
The Lead DT Threat Hunt Analyst proactively identifies and neutralizes cyber threats in Amtrak’s critical infrastructure environments before they impact the organization. This role ensures enterprise-wide DT security, service quality, and process improvement through structured threat hunt development, execution, analysis, documentation, and collaboration with business and DT stakeholders. The Lead DT Threat Hunt Analyst performs a broad range of complex technical and professional work functions to identify, investigate, analyze, and remediate existing threats that evade signatured detection strategies across Amtrak’s IT and OT environments. This position ensures compliance of security policies and procedures through effective security controls, identifying risks and control gaps, areas of process improvement and solutions.
Essential Functions
• Conduct proactive, intelligence-driven threat hunts to identify adversary activity, cyber risks and anomalies, identifying and investigating potential threats to critical infrastructure and operations.
• Evaluate, analyze and synthesize large quantities of data to uncover anomalous activity capable of introducing risk to Amtrak environments.
• Facilitate hunt byproducts indicative of poor cyber hygiene practices, company policy violation or misuse; support incident investigations, as needed.
• Participate in project and technology planning sessions, assess improvement needs, document requirements, and implement enterprise-wide process and security enhancements.
• Build relationships with business partners and cybersecurity teams (detection engineering, threat intelligence, incident response and security operations) and operational technology service owners to escalate anomalous findings, contribute to detection logic improvements and verify security control implementations.
• Govern hunt workflows, investigative methodologies, and technical standards; mentor analysts and produce formal reporting on hunt findings and security improvements
Knowledge, Skills, and Abilities
• Proven experience developing and implementing IT security policies and procedures across a large organization.
• Proven experience monitoring, investigating, and solving IT security related concerns in a timely manner.
• Working knowledge within IT operations and/or Service Management functions.
• Must possess excellent customer service, strong communication and interpersonal skills, work well with others in an integrated team environment, and must be self-motivated.
• Experience evaluating large systems (hardware and software) for IT security compliance.
• Experience conducting IT security forensic investigations.
• Experience with development and reporting towards KPI's and knowledge of industry best practice/industry benchmarks.
• Extensive knowledge of OS triage artifact analysis and incident investigative methods.
• Strong analytical skills and technical proficiency with SIEM, EDR, CASB, IDS/IPS, AV, DLP UEBA, FW, and forensic investigative technologies.
• Ability to design and review multi-source correlation queries using Kusto, Kibana and/or Structured query languages, across endpoint, cloud, network, application and identity data.
• Knowledge and familiarity with Operational Technology (OT), Industrial Controls Systems (ICS) or Supervisory Control and Data Acquisition (SCADA) systems.
• Knowledge of Mitre ATT&CK matrices (Enterprise, ICS, Cloud) to map adversary tactics, techniques and procedures (TTPs) and inform structured hunts.
Minimum Qualifications
• Bachelor’s Degree or equivalent combination of education, training and/or relevant experience. Plus 6 years of relevant work experience.
• Enterprise security experience in threat intelligence, investigative and hunt methodologies, detection engineering, security operations and/or incident response
Preferred Qualifications
- Master's degree or equivalent combination of education, training and/or relevant experience.
- 8+ years of experience in one or more of the following cyber security specializations (threat hunt, security operations, compliance, information security program management, continuous monitoring, vulnerability assessment).
- Professional security related certifications (e.g. GIAC Certified Forensic Analyst (GCFA),
- Certified Information Systems Security Professional (CISSP), or equivalent).
- Experience working in a Security Operations Center (SOC) as an analyst and with Security
- Incident and Event Management (SIEM) systems.
- Scripting language and vender management experience.
- Experience conducting vulnerability management assessments.
#LI-LA1
The salary/hourly range is $103,700.00 – $134,460.00. Pay is based on several factors including but not limited to education, work experience, certifications, etc. Depending on an employee’s assigned worksite or location, Amtrak may consider a geo-pay differential to be applied to the employee’s base salary. Amtrak may offer additional incentive and pay programs to recognize and reward our employees, including a short-term incentive bonus based upon factors such as individual and company performance that is commensurate with the level of the position. In addition to your salary, Amtrak offers a comprehensive benefit package that includes health, dental, and vision plans; health savings accounts; wellness programs; flexible spending accounts; 401K retirement plan with employer match; life insurance; short and long term disability insurance; paid time off; back-up care; adoption assistance; surrogacy assistance; reimbursement of education expenses; Public Service Loan Forgiveness eligibility; Railroad Retirement sickness and retirement benefits; and rail pass privileges. Learn more about our benefits offerings here.
Requisition ID:166278
Work Arrangement:02-Remote Optional Click here for more information about work arrangements at Amtrak.
Relocation Offered:No
Travel Requirements:Up to 25%
You power our progress through your performance.
We want your work at Amtrak to be more than a job. We want your career at Amtrak to be a fulfilling experience where you find challenging work, rewarding opportunities, respect among colleagues, and attractive compensation. Amtrak maintains a culture that values high performance and recognizes individual employee contributions.
Amtrak is committed to a safe workplace free of drugs and alcohol. All Amtrak positions requires a pre-employment background check that includes prior employment verification, a criminal history check and a pre-employment drug screen.
Candidates who test positive for marijuana will be disqualified, regardless of any state or local statute, ordinance, regulation, or other law that legalizes or decriminalizes the use or possession of marijuana, whether for medical, recreational, or other use. Amtrak's pre-employment drug testing program is administered in accordance with DOT regulations and applicable law.
In accordance with DOT regulations (49 CFR § 40.25), Amtrak is required to obtain prior drug and alcohol testing records for applicants/employees intending to perform safety-sensitive duties for covered Department of Transportation positions. If an applicant/employee refuses to provide written consent for Amtrak to obtain these records, the individual will not be permitted to perform safety-sensitive functions.
In accordance with federal law governing security checks of covered individuals for providers of public transportation (Title 6 U.S.C. §1143), Amtrak is required to screen applicants for any permanent or interim disqualifying criminal offenses.
Note that any education requirement listed above may be deemed satisfied if you have an equivalent combination of education, training and experience.
Amtrak is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race/color, to include traits historically associated with race, including but not limited to, hair texture and hairstyles such as braids, locks and twists, religion, sex (including pregnancy, childbirth and related conditions, such as lactation), national origin/ethnicity, disability (intellectual, mental and physical), veteran status, marital status, ancestry, sexual orientation, gender identity and gender expression, genetic information, citizenship or any other personal characteristics protected by law.