Back

[Remote] Lead IT Threat Hunt Analyst - 90397468 - Remote

Worldwide Salaried Open

Note: The job is a remote job and is open to candidates in USA. Amtrak is a major player in connecting businesses and communities across the country, prioritizing safety and employee success. The Lead IT Threat Hunt Analyst focuses on proactively identifying and neutralizing cyber threats to ensure compliance with security policies and enhance the overall cybersecurity posture of the organization.

Responsibilities

  • Conduct proactive, intelligence-driven threat hunts to identify adversary activity, cyber risks and anomalies, identifying and investigating potential threats to critical infrastructure and operations
  • Evaluate, analyze and synthesize large quantities of data to uncover anomalous activity capable of introducing risk to Amtrak environments
  • Search for potential vulnerability exploitation, post-compromise activity or security control gaps based on emerging and known adversary tactics, techniques and procedures (TTPs), user behavior, endpoint threat detection, network behavior analytics, machine learning-derived trends and external threat reports
  • Review EDR telemetry, Firewall, IDS/IPS logs, web content filtering logs, net flow device logs, antivirus logs
  • Work closely with other cybersecurity teams (detection engineering, threat intelligence, incident response and security operations) and operational technology service owners to escalate anomalous findings, contribute to detection logic improvements and verify security control implementations
  • Support and participate in formal reporting related to threat hunt findings, implementation of security controls and improvements to Cyber Security Operations processes
  • Capture hunt byproducts indicative of poor cyber hygiene practices, company policy violation or misuse; support incident investigations, as needed
  • Participate in the evaluation and recommendation of hardware and software systems that provide security functions
  • Respond and resolve problems, security incidents and forensic investigations, as needed
  • Develop and document workflow, hunt and investigative methodology, and technical standards and assist in cyber fusion analyst upskilling and mentoring
  • Investigate, resolve and escalate problems. Monitor and analyze metrics to ensure customer satisfaction and vendor performance
  • Propose improvements and assist with the implementation of enterprise-wide security standards, procedures and guidelines

Skills

  • Bachelor's Degree in Computer Science, Information Systems, or related field
  • Professional security‐related certifications (e.g. GIAC Certified Forensic Analyst (GCFA), Certified Information Systems Security Professional (CISSP), or equivalent)
  • Enterprise security experience in threat intelligence, investigative and hunt methodologies, detection engineering, security operations and/or incident response
  • Knowledge of Mitre ATT&CK matrices (Enterprise, ICS, Cloud) to map adversary tactics, techniques and procedures (TTPs) and inform structured hunts
  • Knowledge of OS triage artifact analysis and incident investigative methods
  • Strong analytical skills and proficiency with SIEM, EDR, CASB, IDS/IPS, AV, DLP UEBA, FW, and forensic investigative technologies
  • Ability to design and review multi-source correlation queries using Kusto, Kibana and/or Structured query languages, across endpoint, cloud, network, application and identity data
  • Must have excellent oral and written communication skills
  • Master's degree in Information Technology, Cyber Security, or equivalent
  • Experience with scripting languages
  • 8+ years of experience in cyber security specialization (threat hunt, security operations, compliance, information security program management, continuous monitoring, vulnerability assessment)
  • Knowledge and familiarity with Operational Technology (OT), Industrial Controls Systems (ICS) or Supervisory Control and Data Acquisition (SCADA) systems

Benefits

  • Health, dental, and vision plans
  • Health savings accounts
  • Wellness programs
  • Flexible spending accounts
  • 401K retirement plan with employer match
  • Life insurance
  • Short and long term disability insurance
  • Paid time off
  • Back-up care
  • Adoption assistance
  • Surrogacy assistance
  • Reimbursement of education expenses
  • Public Service Loan Forgiveness eligibility
  • Railroad Retirement sickness and retirement benefits
  • Rail pass privileges

Company Overview

  • Amtrak is a provider of intercity passenger rail services across the country, connecting major cities and regions. It was founded in 1971, and is headquartered in Washington, District of Columbia, USA, with a workforce of 10001+ employees. Its website is https://www.amtrak.com/.

Company H1B Sponsorship

  • Amtrak has a track record of offering H1B sponsorships, with 48 in 2025, 40 in 2024, 50 in 2023, 52 in 2022, 42 in 2021, 34 in 2020. Please note that this does not guarantee sponsorship for this specific role.

Apply tot his job Apply To this Job

More jobs

[Remote] Threat Analyst- 3rd shift | Remote, USA

Worldwide Salaried

Sr. Threat Hunting Intelligence Analyst (Remote, West Coast)

Worldwide Salaried

Sr. Threat Hunting Intelligence Analyst (Remote, West Coast)

Worldwide Salaried

Data Analyst, Sales Operations

Worldwide Salaried

Business / Data Analyst – QA Specialist

Worldwide Salaried

Data Analyst

Worldwide Salaried

Data Engineer 5 - Product [Remote]

Worldwide Salaried

Sr. Data Engineer FULL TIME REMOTE

Worldwide Salaried

Semantic Data Engineer job at Cambia Health Solutions in Portland, OR, Salt Lake City, UT, Medford, OR, Renton, WA, Coeur d'Alene, ID, Lewiston, ID, Boise, ID, Burlington, WA, Bellevue, WA

Worldwide Salaried

Remote SME Data Engineer

Worldwide Salaried

Summer Intern - Visual Design Art , Teamfight Tactics - [Remote]

Worldwide Salaried

Vet Tech (100% Remote)

Worldwide Salaried

Structural - Project Manager - Diagnostics (Hybrid Remote)

Worldwide Salaried

Experienced Data Entry Specialist for Teens – Kickstart Your Career in Data Management

Worldwide Salaried

Experienced Telechat/Phone Chat Support Specialist – Remote Customer Service Representative

Worldwide Salaried

Live Chat Operator - Home-Based, Training Provided, Earn $25-$35/Hour

Worldwide Salaried

Senior Data Scientist - Revenue Optimization & Customer Experience Enhancement at Delta Airlines

Worldwide Salaried

Partner Community Manager

Worldwide Salaried

Medical Coder I, Amazon One Medical Senior Health

Worldwide Salaried

Vendor & Partnership Manager

Worldwide Salaried