Talent.com
Principal Engineer - Cyber Incident Response
Principal Engineer - Cyber Incident ResponseAmerisourceBergen Corporation (Cencora) • Chesterbrook, PA, United States
Principal Engineer - Cyber Incident Response

Principal Engineer - Cyber Incident Response

AmerisourceBergen Corporation (Cencora) • Chesterbrook, PA, United States
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!

Job Details

Position Summary

The Principal Engineer, Cyber Incident Response, will serve as a senior technical expert within the global Cyber Defense team. This role is responsible for leading complex investigations, advancing detection and response capabilities, and providing deep technical expertise during major incidents. The Principal Engineer will collaborate closely with global SOC teams, threat intelligence, vulnerability management, and forensics functions to contain, investigate, and eradicate cyber threats. This position requires advanced technical skills in incident response, threat hunting, malware analysis, and forensic investigations, as well as the ability to influence security architecture and detection engineering across the enterprise.

Primary Duties and Responsibilities

Lead technical response and investigation of complex and high-severity security incidents, including advanced persistent threats, ransomware, and insider activity.

Provide hands-on expertise in forensic analysis, malware reverse engineering, and threat hunting across endpoints, networks, and cloud environments.

Develop and refine incident response playbooks, detection rules, and automation to improve SOC efficiency and response times.

Partner with engineering teams to design and implement resilient detection and response capabilities across SIEM, EDR, SOAR, and cloud platforms.

Mentor and provide technical guidance to SOC analysts, incident responders, and engineering teams.

Collaborate with threat intelligence teams to translate threat actor tactics, techniques, and procedures (TTPs) into actionable detection and response strategies.

Serve as a technical escalation point during major incidents and contribute to root cause analysis and lessons learned reporting.

Contribute to red / blue / purple team exercises to validate detection and response effectiveness.

Provide input on security architecture, tooling enhancements, and emerging technologies to strengthen enterprise cyber defense.

Education and Qualifications

Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or equivalent work experience; Master's degree preferred.

Advanced knowledge of incident response methodologies, digital forensics, malware analysis, and adversary simulation.

Familiarity with industry frameworks such as NIST, MITRE ATT&CK, and ISO 27035.

Preferred Certifications

GIAC Certified Incident Handler (GCIH)

GIAC Certified Intrusion Analyst (GCIA)

GIAC Reverse Engineering Malware (GREM)

GIAC Certified Forensic Analyst (GCFA)

Offensive Security Certified Professional (OSCP)

Certified Information Systems Security Professional (CISSP) or equivalent senior-level certification a plus

Work Experience

10+ years of progressive experience in cybersecurity, with at least 7 years focused on incident response, threat hunting, or forensic investigations.

Demonstrated expertise in analyzing and responding to advanced cyber threats in large enterprise environments.

Hands-on experience with SIEM, EDR, SOAR, and forensic tools (e.g., Splunk, CrowdStrike, EnCase, Magnet, Wireshark).

Experience with malware reverse engineering, memory forensics, and scripting / automation (Python, PowerShell).

Proven ability to serve as a technical authority and mentor within a global SOC or incident response team.

Strong communication skills, with the ability to clearly present complex technical findings to both technical and executive stakeholders.

What Cencora offers

We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members' ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https : / / www.virtualfairhub.com / cencora

Full time

Equal Employment Opportunity

Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.

The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.

Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email hrsc@cencora.com . We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned

Affiliated Companies

Affiliated Companies : AmerisourceBergen Services Corporation

serp_jobs.job_alerts.create_a_job

Principal Cyber Engineer • Chesterbrook, PA, United States

Job_description.internal_linking.related_jobs
Cybersecurity Incident Responder

Cybersecurity Incident Responder

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for an Incident Responder.Key Responsibilities Lead cybersecurity investigations within the Computer Security Incident Response Team (CSIRT) Document and present investigati...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
Principal Engineer - Cyber Incident Coordinator

Principal Engineer - Cyber Incident Coordinator

AmerisourceBergen Corporation (Cencora) • Conshohocken, PA, United States
serp_jobs.job_card.full_time
Our team members are at the heart of everything we do.At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on ...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Principal Engineer - Cyber Countermeasures

Principal Engineer - Cyber Countermeasures

AmerisourceBergen Corporation (Cencora) • Chesterbrook, PA, United States
serp_jobs.job_card.full_time
Our team members are at the heart of everything we do.At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on ...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Engineer II - Cyber Incident Response

Engineer II - Cyber Incident Response

AmerisourceBergen Corporation (Cencora) • Chesterbrook, PA, United States
serp_jobs.job_card.full_time
Our team members are at the heart of everything we do.At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on ...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Engineer III - Cyber Incident Response

Engineer III - Cyber Incident Response

AmerisourceBergen Corporation (Cencora) • Conshohocken, PA, United States
serp_jobs.job_card.full_time
Our team members are at the heart of everything we do.At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on ...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Cybersecurity Incident Response Engineer

Cybersecurity Incident Response Engineer

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for a Security Engineer III.Key Responsibilities Assist in scoping security incidents and identifying indicators of attack and compromise Analyze incident data from threat a...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
Intermediate Cybersecurity Engineer

Intermediate Cybersecurity Engineer

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for an Intermediate Cybersecurity Engineer to protect its colocation and cloud-based infrastructure. Key Responsibilities : Design and implement security controls across coloca...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
Network Cloud Analyst / AWS / GCP / Cisco

Network Cloud Analyst / AWS / GCP / Cisco

Motion Recruitment • Horsham, PA, US
serp_jobs.job_card.temporary
A national based company is growing and looking to hire a Cloud Network Analyst to join their team.You will be a part of a 6 person team and working in a hybrid on prem and cloud environment.They a...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Cyber Incident Response Engineer

Cyber Incident Response Engineer

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for an Engineer III - Cyber Incident Response.Key Responsibilities Lead the investigation and resolution of complex security incidents Perform forensic analysis across vario...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Principal Engineer, Cyber Threat Intelligence

Principal Engineer, Cyber Threat Intelligence

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for a Principal Engineer - Cyber Threat Intelligence.Key Responsibilities Lead advanced research and analysis of cyber adversary tactics and procedures Produce threat intell...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Cyber Incident Coordinator

Cyber Incident Coordinator

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for a Principal Engineer - Cyber Incident Coordinator.Key Responsibilities Manage and coordinate major cyber incident response activities, including detection, containment, e...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
Incident Response Managing Director

Incident Response Managing Director

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for a Managing Director, Incident Response.Key Responsibilities : Lead and manage the cyber incident response team, providing strategic direction and operational oversight Ov...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Principal Engineer Cyber Incident Response

Principal Engineer Cyber Incident Response

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for a Principal Engineer - Cyber Incident Response.Key Responsibilities Lead technical response and investigation of complex security incidents Provide expertise in forensic...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Lead Cybersecurity Engineer

Lead Cybersecurity Engineer

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for a Lead Cybersecurity Engineer, Engineering Operations.Key Responsibilities Provide direction for building and enhancing an operational excellence model for the global sec...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
Principal Engineer - Cyber Threat Intelligence

Principal Engineer - Cyber Threat Intelligence

AmerisourceBergen Corporation (Cencora) • Chesterbrook, PA, United States
serp_jobs.job_card.full_time
Our team members are at the heart of everything we do.At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on ...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Principal Engineer Cyber Countermeasures

Principal Engineer Cyber Countermeasures

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for a Principal Engineer - Cyber Countermeasures.Key Responsibilities Lead the design and implementation of cyber countermeasures against advanced adversary tactics Develop ...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Mid-Level Cybersecurity Engineer

Mid-Level Cybersecurity Engineer

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for a Mid-Level Cybersecurity Maintenance Engineer (Prisma Cloud).Key Responsibilities Maintain and enhance the Prisma Cloud Console and deploy Defenders / Enforcers across var...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
Principal Security Engineer

Principal Security Engineer

VirtualVocations • Newark, Delaware, United States
serp_jobs.job_card.full_time
A company is looking for a Principal Security Engineer to lead information security initiatives and collaborate with development and operational teams. Key Responsibilities Identify security threa...serp_jobs.internal_linking.show_more
serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted