Specialist Cybersecurity Ops Analyst

Há 7 dias

Lisboa, Lisboa, Portugal Amgen SA Tempo integral 70 000 € - 90 000 € Contrato

Join our team at AMGEN Capability Center Portugal, consistently recognized among the top companies in the Best Workplaces(TM) ranking by Great Place to Work(R) in Portugal. In 2026, we were once again distinguished as one of the top Best Workplaces in the country (category 201-500 employees), reinforcing our commitment to an exceptional employee experience and workplace culture.

We are a team of over 500 talented individuals, spanning more than 30 functions and areas of expertise, and representing over 40 nationalities. Together, we bring diverse perspectives and professional backgrounds to help shape the future of healthcare through innovation and technology.

This is your opportunity to explore a world of possibilities across areas such as Data & Analytics, Digital, Technology & Innovation, Cybersecurity, R&D Operations, Global Distribution, Finance, Regulatory Affairs, General & Administrative, Human Resources, and many more.

Located in the heart of Lisbon, our AMGEN office fosters a culture of innovation, excellence, and purpose. Come thrive with us at AMGEN, supporting our mission To Serve Patients.

What we do at AMGEN matters in people's lives.

Incident Response Specialist Cybersecurity Ops Analyst

ABOUT THE ROLE

Amgen is seeking an Incident Response Specialist Cybersecurity Ops Analyst, who will report to the Senior Manager, Information Systems, and will be based in Portugal ACC. At Amgen, our mission is simple: to serve patients.

Leading Amgen’s Cyber Security Organization, the Incident Response Cybersecurity Ops Analyst engages with key business and operational partners in enhancing the detection, response, and remediation of cyber related attacks on Amgen’s global enterprise while contributing and delivering services and projects that support the mission, priorities, and objectives of the organization.

The Incident Response Cybersecurity Ops Analyst will be part of a global team and is responsible for building services around incident identification, containment, eradication, recovery, and lessons learned. You will be directly responsible for organizing, training and equipping Amgen employees and contractors in a manner directly aligned with Amgen’s culture, principles, and core values.

In the capacity of Incident Response Cybersecurity Ops Analyst, you will craft and oversee standard operating procedures, field manuals, and operating instructions. As part of the investigation or remedial processes you will have to engage with key business and operational partners in managing the detection, response, and remediation of cyber related attacks on Amgen’s global enterprise.

In this vital role you will:

Key Activities of the Incident Response Specialist Cybersecurity Ops Analyst

  • Execute all phases of the incident response lifecycle in accordance with the SANS PICERL framework, including preparation, identification, containment, eradication, recovery, and post-incident activities.
  • Perform advanced investigations involving endpoint, network, cloud, and identity-based security incidents across enterprise environments.
  • Analyze security events and alerts from SIEM, EDR/XDR, NDR, cloud security platforms, and threat intelligence sources to determine the scope, impact, and severity of security incidents.
  • Conduct enterprise-wide threat hunting using Indicators of Compromise (IOCs), Indicators of Attack (IOAs), behavioral analytics, and the MITRE ATT&CK framework.
  • Perform incident triage and validation to distinguish malicious activity from benign events and accurately scope security incidents.
  • Correlate endpoint, network, cloud, identity, email, and security control telemetry to reconstruct attack timelines and determine the extent of compromise.
  • Perform root cause analysis to identify initial access vectors, attacker techniques, persistence mechanisms, and opportunities to improve defensive controls.
  • Develop and execute containment, eradication, and recovery strategies that minimize operational impact while preserving investigative evidence.
  • Acquire, preserve, and analyze digital evidence in accordance with established forensic procedures and chain-of-custody requirements.
  • Perform forensic analysis of endpoints and system artifacts, including event logs, registry data, file system metadata, browser artifacts, and other operating system artifacts to support incident investigations.
  • Assist with forensic collection and analysis of endpoint, cloud, email, memory, and disk artifacts to support incident scoping and investigative activities.
  • Create and maintain detection content, including SIEM correlation rules, Sigma rules, IOC feeds, detection use cases, and other analytics to improve detection and response capabilities.
  • Develop automation and scripting using PowerShell, Python, Bash, SQ