Amerisource Bergen

Engineer II - Cyber Incident Response

Amerisource Bergen$80K — $110K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent work experience.
  • Strong knowledge of cybersecurity fundamentals, incident response methodology, and adversary tactics.
  • Familiarity with industry frameworks such as NIST, MITRE ATT&CK, and ISO 27035.
  • 2–5 years of progressive experience in cybersecurity, with at least 2 years in SOC operations or incident response.
  • Hands-on experience with SIEM, EDR, and forensic tools (e.g., Splunk, CrowdStrike, Wireshark).

Responsibilities

  • Investigate and respond to cybersecurity incidents, including phishing and malware.
  • Perform analysis of logs and forensic data to determine the scope and impact of incidents.
  • Escalate complex incidents to senior staff, providing clear documentation and evidence.
  • Assist in containment, eradication, and recovery during incident response.
  • Contribute to the development and maintenance of SOC playbooks and procedures.
  • Collaborate with threat intelligence and vulnerability management teams to strengthen detection strategies.
  • Support junior analysts by sharing knowledge and providing guidance on investigative techniques.

Benefits

  • Medical, dental, and vision care coverage.
  • Wide range of support for working families, including backup care and adoption assistance.
  • Comprehensive wellness programs focusing on physical, emotional, financial, and social aspects.
  • Training programs and professional development resources available.
  • Opportunities to participate in mentorship programs and volunteer activities.
Full Job Description

Position Summary

The Engineer II, Cyber Incident Response, is a mid-level technical role within the Security Operations Center (SOC) responsible for detecting, investigating, and responding to cybersecurity incidents. This role performs in-depth analysis of alerts, escalates complex cases, and contributes to the improvement of response processes and playbooks. The Engineer II will collaborate with global cyber defense teams to contain threats, minimize business impact, and strengthen detection capabilities. This position requires strong analytical skills, hands-on technical expertise, and the ability to operate effectively in a fast-paced environment.

Primary Duties and Responsibilities 

  • Investigate and respond to cybersecurity incidents, including phishing, malware, ransomware, and unauthorized access attempts. 

  • Perform analysis of logs, alerts, and forensic data to determine the scope and impact of incidents. 

  • Escalate complex or high-severity incidents to Engineer III, Lead, or Principal staff, providing clear documentation and evidence. 

  • Assist in containment, eradication, and recovery activities during incident response. 

  • Contribute to the development and maintenance of SOC playbooks, runbooks, and standard operating procedures. 

  • Collaborate with threat intelligence, vulnerability management, and forensics teams to strengthen detection and response strategies. 

  • Participate in lessons-learned sessions and recommend improvements to SOC processes and tooling. 

  • Support junior analysts (Engineer I) by sharing knowledge and providing guidance on investigative techniques. 

Education and Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, orequivalent work experience.

  • Strong knowledge of cybersecurity fundamentals, incident response methodology, and adversary tactics.

  • Familiarity with industry frameworks such as NIST, MITRE ATT&CK, and ISO 27035.

Preferred Certifications 

  • GIAC Certified Incident Handler (GCIH)

  • GIAC Certified Intrusion Analyst (GCIA)

  • CompTIA Security+ orCySA+

  • Certified Ethical Hacker (CEH)

Work Experience 

  • 3–5 years of progressive experience in cybersecurity, with at least 2 years in SOC operations or incident response. 

  • Hands-on experience with SIEM, EDR, and forensic tools (e.g., Splunk, CrowdStrike, Wireshark). 

  • Demonstrated ability to analyze logs, alerts, and artifacts to support incident investigations. 

  • Strong written and verbal communication skills for documenting findings and briefing stakeholders. 

What Cencora offers

We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit

Full time

About Amerisource Bergen

AmerisourceBergen Corporation is a pharmaceutical distribution company headquartered in Chesterbrook, Pennsylvania. It was founded in 2001 through the merger of AmeriSource Health Corporation and Bergen Brunswig Corporation. The company distributes a wide range of pharmaceutical products, including brand-name and generic drugs, specialty drugs, and over-the-counter medications. AmerisourceBergen serves healthcare providers, including hospitals, pharmacies, and physician practices, as well as pharmaceutical manufacturers. The company is committed to sustainability and has implemented several initiatives to reduce its environmental impact.
Learn more about Amerisource Bergen
Size
21,000 employees
Industry

Similar Jobs

More Jobs at Amerisource Bergen

More Information Technology Jobs

Find similar Engineer II - Cyber Incident Response jobs: