Amerisource Bergen

Engineer III - Cyber Incident Response

Amerisource Bergen$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s Degree in Computer Science, Information Technology, or related field
  • 4+ years of experience in information security
  • Preferred certifications: Azure Security Engineer, CCSP, CISM, CISSP, CompTIA Security+, SSCP
  • Strong knowledge of cybersecurity frameworks like SOX, ISO, COBIT, ITIL, NIST, PCI
  • Proficiency in programming languages such as JavaScript, HTML/CSS, Python, SQL.

Responsibilities

  • Conduct proactive research to identify and address security vulnerabilities
  • Assist with initiatives across various cybersecurity functions like Incident Response and Threat Intelligence
  • Develop and implement security policies and ensure compliance
  • Review and implement cybersecurity solutions and technical documentation
  • Manage multiple cybersecurity projects and provide strategic consultation
  • Advise business and IT leaders on security concerns and assist with inquiries
  • Conduct security testing and support mentorship for junior engineers
  • Analyze metrics and reporting for executive-level insights.

Benefits

  • Opportunities for professional certification and skill development
  • Collaborative and dynamic work environment
  • Engagement in cutting-edge cybersecurity projects
  • Mentorship from experienced cybersecurity professionals
  • Access to advanced security tools and technologies.
Full Job Description

Position Summary:
The Engineer III, Cyber Incident Response, is a senior technical role within the Security Operations Center (SOC) responsible for leading complex incident investigations and supporting the continuous improvement of detection and response capabilities. This role provides advanced technical expertise in identifying, analyzing, containing, and remediating cyber threats. The Engineer III will act as a mentor to junior analysts, serve as an escalation point for critical incidents, and collaborate with global cyber defense teams to ensure timely and effective responses to advanced threats.

Primary Duties and Responsibilities:

  • Lead the investigation and resolution of complex security incidents, including advanced persistent threats, ransomware, phishing campaigns, and insider activities.

  • Perform forensic analysis across endpoints, networks, and cloud environments to identify root causes and scope of compromise.

  • Develop and enhance incident response playbooks, runbooks, and detection use cases.

  • Collaborate with threat intelligence, vulnerability management, and countermeasures teams to strengthen defenses.

  • Escalate high-severity incidents to senior leadership and provide clear, actionable reporting.

  • Act as a technical escalation point for Engineer I/II analysts during incident investigations.

  • Contribute to red team and purple team exercises to validate and improve response capabilities.

  • Participate in after-action reviews and lessons-learned sessions to improve SOC processes.

  • Mentor and train junior engineers on incident response best practices and investigative techniques.

Education and Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, orequivalent work experience; Master’s degree preferred.

  • Strong knowledge of incident response methodologies, digital forensics, and adversary tactics.

  • Familiarity with security frameworks such as NIST, MITRE ATT&CK, and ISO 27035.

Preferred Certifications

  • GIAC Certified Incident Handler (GCIH)

  • GIAC Certified Intrusion Analyst (GCIA)

  • GIAC Certified Forensic Analyst (GCFA)

  • Certified Ethical Hacker (CEH)

  • Certified Information Systems Security Professional (CISSP) 

Work Experience 

  • 5–7 years of progressive experience in cybersecurity, with at least 3 years in incident response or SOC operations. 

  • Hands-on experience with SIEM, EDR, SOAR, and forensic tools (e.g., Splunk, CrowdStrike, EnCase, Wireshark). 

  • Proven ability to investigate advanced threats and coordinate response activities across teams. 

  • Demonstrated success in mentoring junior analysts and improving SOC processes. 

  • Strong written and verbal communication skills with the ability to document and present technical findings clearly. 

What Cencora offers

We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit

Full time

About Amerisource Bergen

AmerisourceBergen Corporation is a pharmaceutical distribution company headquartered in Chesterbrook, Pennsylvania. It was founded in 2001 through the merger of AmeriSource Health Corporation and Bergen Brunswig Corporation. The company distributes a wide range of pharmaceutical products, including brand-name and generic drugs, specialty drugs, and over-the-counter medications. AmerisourceBergen serves healthcare providers, including hospitals, pharmacies, and physician practices, as well as pharmaceutical manufacturers. The company is committed to sustainability and has implemented several initiatives to reduce its environmental impact.
Learn more about Amerisource Bergen
Size
21,000 employees
Industry

Similar Jobs

More Jobs at Amerisource Bergen

More Information Technology Jobs

Find similar Engineer III - Cyber Incident Response jobs: