Logo for AmerisourceBergen

Engineer III - Cyber Incident Response

Role overview

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent work experience; Master’s degree preferred.
  • Strong knowledge of incident response methodologies, digital forensics, and adversary tactics.
  • 7+ years of progressive experience in cybersecurity, with at least 4 years in incident response or SOC operations.
  • Relevant industry certifications preferred (e.g., GCFA, GCIH, CISSP).

Responsibilities

  • Lead the investigation and resolution of complex security incidents.
  • Perform forensic analysis across endpoints, networks, and cloud environments.
  • Develop and enhance incident response playbooks and detection use cases.
  • Act as a mentor to junior analysts and escalate high-severity incidents to senior leadership.

About the company

AmerisourceBergen logo

AmerisourceBergen

Pharmaceutical Wholesale & Distribution

On August 30, 2023, AmerisourceBergen became Cencora. Cencora is a leading global pharmaceutical solutions organization centered on improving the lives of people and animals around the world. We partner with pharmaceutical innovators across the value chain to facilitate and optimize market access to therapies. Care providers depend on us for the secure, reliable delivery of pharmaceuticals, healthcare products, and solutions. Previously known as AmerisourceBergen, our new name, Cencora, unites our 46,000+ team members under one identity in pursuit of a shared purpose: We are united in our responsibility to create healthier futures. : We are united in our responsibility to create healthier futures. AmerisourceBergen is ranked #11 on the Fortune 500 and #24 on the Global Fortune 500 with more than $200 billion in annual revenue.

Company details

Company typeXLarge
IndustryPharmaceutical Wholesale & Distribution
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!

Job Details

The Engineer III, Cyber Incident Response, is a senior technical role within the Security Operations Center (SOC) responsible for leading complex incident investigations and supporting the continuous improvement of detection and response capabilities. This role provides advanced technical expertise in identifying, analyzing, containing, and remediating cyber threats. The Engineer III will act as a mentor to junior analysts, serve as an escalation point for critical incidents, and collaborate with global cyber defense teams to ensure timely and effective responses to advanced threats.

Primary Duties and Responsibilities

  • Lead the investigation and resolution of complex security incidents, including advanced persistent threats, ransomware, phishing campaigns, and insider activities.
  • Perform forensic analysis across endpoints, networks, and cloud environments to identify root causes and scope of compromise.
  • Develop and enhance incident response playbooks, runbooks, and detection use cases.
  • Collaborate with threat intelligence, vulnerability management, and countermeasures teams to strengthen defenses.
  • Escalate high-severity incidents to senior leadership and provide clear, actionable reporting.
  • Act as a technical escalation point for Engineer I/II analysts during incident investigations.
  • Contribute to red team and purple team exercises to validate and improve response capabilities.
  • Participate in after-action reviews and lessons-learned sessions to improve SOC processes.
  • Mentor and train junior engineers on incident response best practices and investigative techniques.

Education and Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent work experience; Master’s degree preferred.
  • Strong knowledge of incident response methodologies, digital forensics, and adversary tactics.
  • Familiarity with security frameworks such as NIST, MITRE ATT&CK, and ISO 27035.

Preferred Certifications

  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Certified Forensic Analyst (GCFA)
  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP) 

Work Experience

  • 7+ years of progressive experience in cybersecurity, with at least 4 years in incident response or SOC operations.
  • Hands-on experience with SIEM, EDR, SOAR, and forensic tools (e.g., Splunk, CrowdStrike, EnCase, Wireshark).
  • Proven ability to investigate advanced threats and coordinate response activities across teams.
  • Demonstrated success in mentoring junior analysts and improving SOC processes.
  • Strong written and verbal communication skills with the ability to document and present technical findings clearly.

.

Bachelor's degree in cybersecurity, computer science, information technology, or a related field required, or equivalent experience required. 4+ years of experience in incident response, digital forensics, or advanced threat hunting required. Demonstrates advanced capability in a primary technical area with growing breadth across related security domains. Relevant industry certifications (e.g., GCFA, GCIH, CISSP) preferred.

What Cencora offers

​Benefit offerings outside the US may vary by country and will be aligned to local market practice. The eligibility and effective date may differ for some benefits and for team members covered under collective bargaining agreements.

Full time

Affiliated Companies

Affiliated Companies: CENCORA BUSINESS SERVICES INDIA PRIVATE LIMITED

Equal Employment Opportunity

Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.

The company’s continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.

Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email hrsc@cencora.com. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at AmerisourceBergen

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.