Principal DT Security Engineer - Operational Technology

Amtrak
$124,600 - $161,352Remote

About The Position

The Sr Principal Cybersecurity Engineer serves as a senior technical engineer within the Enterprise Network & Critical Infrastructure Security (ENCIS) organization and is responsible for securing Amtrak's enterprise networks, critical infrastructure, and operational technology (OT) environments. This role provides advanced cybersecurity engineering expertise across IT and OT domains, ensuring the confidentiality, integrity, availability, and resilience of systems supporting business operations and rail transportation services. The position leads the design, implementation, and continuous improvement of security architectures, controls, and technologies that protect enterprise infrastructure and critical operational assets. The Sr Principal Cybersecurity Engineer collaborates closely with infrastructure, network, engineering, operations, and cybersecurity teams to identify risks, implement safeguards, and reduce cyber threats across interconnected environments. This role participates in and supports SAFe Agile practices, providing cybersecurity leadership across Agile Release Trains (ARTs), contributing to Program Increment (PI) planning, and ensuring security requirements are integrated into technology initiatives throughout the system lifecycle.

Requirements

  • Bachelor’s Degree or equivalent combination of education, training and/or relevant experience.
  • Plus 7 years of relevant work experience.
  • Experience securing enterprise network technologies, including firewalls, IDS/IPS, VPNs, network segmentation, proxies, and wireless infrastructure.
  • Experience working with Operational Technology (OT), Industrial Control Systems (ICS), SCADA environments, or other critical infrastructure technologies.
  • Experience participating in SAFe Agile, Agile Scrum, or similar Agile delivery frameworks.
  • Strong understanding of cybersecurity frameworks including NIST Cybersecurity Framework, NIST 800-53, NIST 800-82, CIS Controls, and MITRE ATT&CK.
  • Experience performing risk assessments, security architecture reviews, and vulnerability management activities.
  • Strong knowledge of TCP/IP networking, routing, switching, and network security principles.
  • Experience supporting incident response, threat hunting, or security operations functions.
  • Strong communication, documentation, and stakeholder management skills.
  • Ability to work effectively across technical and non-technical teams.

Nice To Haves

  • Bachelor’s Degree or equivalent combination of education, training and/or relevant experience.
  • Plus 9 years of relevant work experience.
  • One or more certifications: CISSP, GIAC, Security+, CCNP, CCSP, CEH, CISM, or SABSA
  • Direct experience within transportation, railroad, energy, manufacturing, utility, or industrial sectors.
  • Advanced expertise in OT/ICS security technologies and architectures.
  • Experience implementing Zero Trust architectures and network segmentation strategies.
  • Experience with cloud security technologies in Microsoft Azure and Amazon Web Services (AWS).
  • Experience with Microsoft Security technologies including Microsoft Defender, Sentinel, Entra ID, and related security platforms.
  • Familiarity with TSA Security Directives, NERC-CIP, IEC 62443, or similar critical infrastructure security standards.
  • SAFe Agilist (SA), SAFe Practitioner (SP), or other SAFe certifications.
  • Experience leading enterprise-scale cybersecurity transformation initiatives.
  • Excellent customer service, strong communication and interpersonal skills, work well with others in an integrated team environment, and must be self-motivated
  • Proficient in securing Windows and nix operating systems, endpoint applications, networking protocols and devices
  • In-depth understanding of scripting in Python, Bash, Perl, PowerShell or other relevant language
  • Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the secure software development lifecycle (SLDC)
  • Experience with industry standard information security technologies
  • Experience performing technical risk and vulnerability assessments
  • Strong analytical skills with experience working in or supporting a Security Operations Center

Responsibilities

  • Lead the design, implementation, and management of cybersecurity controls supporting enterprise networks and critical infrastructure environments.
  • Evaluate and recommend security technologies, platforms, and architectural solutions that strengthen Amtrak's security posture.
  • Develop and maintain security architectures for network, cloud, data center, remote access, wireless, and OT/ICS environments.
  • Lead initiatives to improve network visibility, threat detection, and security monitoring capabilities.
  • Partner with Network Engineering teams to implement secure infrastructure and resiliency improvements.
  • Provide cybersecurity leadership and engineering support for Operational Technology (OT), Industrial Control Systems (ICS), SCADA, and other critical infrastructure environments.
  • Collaborate with operational stakeholders to improve cyber resilience, incident readiness, and business continuity capabilities.
  • Support compliance efforts aligned with NIST, TSA Security Directives, CIS Controls, and other applicable transportation and critical infrastructure security requirements.
  • Provide advanced technical support during cyber incidents affecting enterprise or operational environments.
  • Collaborate with threat intelligence, SOC, and infrastructure teams to improve detection and response capabilities.
  • Participate in SAFe Agile ceremonies including PI Planning, Sprint Reviews, System Demos, and ART events.
  • Partner with Product Managers, Product Owners, Release Train Engineers, Architects, and Engineering teams to integrate security requirements into initiatives.
  • Track and communicate cybersecurity risks, dependencies, and deliverables across technology programs.
  • Serve as a trusted advisor to business and technology stakeholders on cybersecurity strategy and risk management.
  • Drive continuous improvement initiatives that enhance operational efficiency, automation, and security effectiveness.
  • Support periodic assessments, audits, tabletop exercises, and recovery testing activities.

Benefits

  • Health, Dental, and Vision Insurance
  • Wellness Programs
  • Health Savings Account
  • No-cost Personal Health Advocate
  • Medical Plan Opt-out Credit
  • Life Insurance
  • Short- and Long-term Disability Insurance
  • No-cost Financial Advisor Sessions
  • Commuter and Flexible Spending Accounts
  • 401K with Employer Match
  • Railroad Retirement Benefits
  • Public Service Student Loan Forgiveness
  • Student Loan Assistance
  • Tuition and Education Reimbursement
  • Rail Pass Privileges
  • Employee Assistance Program
  • Generous Paid Time Off
  • Paid Caregiving Days and Backup Care
  • Fertility and Family Building Benefits
  • Adoption and Surrogacy Assistance
  • Paid Family Leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service