For Employers

Amtrak

Principal Cybersecurity Gov Risk & Compliance

Posted an hour ago
$113K - $146K per year
10+ years experience
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review
AI Summary

The Principal Cybersecurity Gov Risk & Compliance acts as a subject matter expert to translate cyber risks into business impacts for leadership. They are responsible for performing quantitative risk assessments, developing risk models, and ensuring organizational compliance with regulatory standards.

Your success is a train ride away!

As we move America’s workforce toward the future, Amtrak connects businesses and communities across the country. We employ more than 20,000 diverse, energetic professionals in a variety of career fields throughout the United States. The safety of our passengers, our employees, the public and our operating environment is our priority, and the success of our railroad is due to our employees.

 

Are you ready to join our team?

Our values of ‘Do the Right Thing, Excel Together and Put Customers First’ are at the heart of what matters most to us, and our Core Capabilities, ‘Building Trust, Accountability, Effective Communication, Customer Focus, and Proactive Safety & Security’ are what every employee needs to know and do to be most impactful at Amtrak. By living the Amtrak values, focusing on our capabilities, and actively embracing and fostering diverse ideas, backgrounds, and perspectives, together we will honor our past and make Amtrak a company of the future.

 

Job Summary

The Principal DT Gov Risk & Compliance serves as the subject matter expert responsible for translating cyber risk into business impact. This position evaluates the potential operational, customer, financial, and revenue impacts associated with cyber risks and provides risk-based recommendations to leadership. The role supports Cybersecurity’s mission of determining which information security risks matter most by quantifying exposure, assessing business consequences, evaluating risk treatment options, and supporting informed decision-making across technology, cybersecurity, and business stakeholders.

Essential Functions

  • Perform quantitative and qualitative cyber risk assessments to evaluate potential operational, customer, financial, and revenue impacts associated with cyber risks.
  • Develop risk quantification models, business impact analyses, and risk scenarios to support executive decision-making and risk acceptance activities.
  • Analyze the effectiveness of proposed risk treatments and cybersecurity investments by evaluating potential risk reduction and residual risk.
  • Collaborate with enterprise risk stakeholders, business stakeholders, and technology teams to translate technical risks into business consequences and recommendations.
  • Prepare and present cyber risk quantification analyses, business impact assessments, and executive decision-support materials for leadership review.
  • Develop and support new policies, standards, guidelines, and procedures to ensure compliance with NIST, PCI-DSS, GDPR/CCPA, and other regulations.
  • Collaborate with GRC leadership to develop and review audit responses for external audits and ensure compliance with laws and regulations.
  • Develop and manage GRC Administrative, Physical, and Technical Controls Catalog, including system security plans and cybersecurity language in contracts and agreements.
  • Work with internal and external audit firms, regulatory agencies, and the Infrastructure systems team to provide documentation and develop ITGC process standards.
  • Identify major risk factors impacting Amtrak's objectives, generate communication and educational plans, and mitigate obstacles to change.

Minimum Qualifications

  • Bachelor’s Degree or equivalent combination of education, training and/or relevant experience. Plus 7 years of relevant work experience.
  • Experience performing cyber risk assessments, business impact analysis, enterprise risk analysis, risk quantification, or related risk management activities.
  • Demonstrated ability to communicate complex technical and cybersecurity risks in business terms to non-technical stakeholders

Preferred Qualifications

  • Bachelor’s Degree or equivalent combination of education, training and/or relevant experience. Plus 9 years of relevant work experience.
  • Experience with cyber risk quantification methodologies such as FAIR or similar quantitative risk analysis frameworks.
  • Experience performing operational, financial, customer-impact, or business impact assessments
  • Experience supporting executive decision-making through development of risk analyses, business cases, or investment prioritization recommendations
  • Relevant certifications such as CRISC, CISM, CISSP, FAIR Analyst (FAIRA), or FAIR Practitioner (FAIRP)

Knowledge, Skills, and Abilities

  • Experience in GRC/IRM space with leading, developing and maintaining cybersecurity and ITGC policies and associated controls management
  • Understanding of the ServiceNow platform ecosystem
  • Familiarity with the risk-based frameworks’ associated analysis and data analytics
  • Familiarity with industry frameworks (e.g., NIST, CIS, COBIT, etc.), best practices and methodologies
  • Strong understanding of cybersecurity risk management principles and risk assessment methodologies.
  • Ability to evaluate and quantify operational, customer, financial, and revenue impacts associated with cyber risks.
  • Strong analytical and critical-thinking skills with the ability to assess competing priorities and risk treatment options.
  • Experience developing executive-level presentations, briefings, and decision-support materials.
  • Strong communication and interpersonal skills, work well with others in an integrated team environment, and must be self-motivated
  • Solid understanding of data handling best-practices, information management, and governance
  • Strong writing and oral skills with ability to effectively communicate technical issues to diverse audiences
  • Excellent attention to detail
  • Ability to translate technical cybersecurity risks into business-focused recommendations and actionable insights

The salary/hourly range is $113,200.00 – $146,664.00. Pay is based on several factors including but not limited to education, work experience, certifications, etc. Depending on an employee’s assigned worksite or location, Amtrak may consider a geo-pay differential to be applied to the employee’s base salary. Amtrak may offer additional incentive and pay programs to recognize and reward our employees, including a short-term incentive bonus based upon factors such as individual and company performance that is commensurate with the level of the position. 

 

Health and Wellbeing Financial and Retirement Work and Family Life Support
Health, Dental, and Vision Insurance 401K with Employer Match Generous Paid Time Off 
Wellness Programs Railroad Retirement Benefits Paid Caregiving Days and Backup Care
Health Savings Account Public Service Student Loan Forgiveness Fertility and Family Building Benefits
No-cost Personal Health Advocate Student Loan Assistance Adoption and Surrogacy Assistance
Medical Plan Opt-out Credit Tuition and Education Reimbursement Paid Family Leave
  Life Insurance Rail Pass Privileges
  Short- and Long-term Disability Insurance Employee Assistance Program
  No-cost Financial Advisor Sessions Commuter and Flexible Spending Accounts

 

Learn more about our benefits offerings here.

 

Requisition ID:167003

Work Arrangement:02-Remote Optional Click here for more information about work arrangements at Amtrak.
Relocation Offered:No
Travel Requirements:Up to 25%

You power our progress through your performance.

We want your work at Amtrak to be more than a job. We want your career at Amtrak to be a fulfilling experience where you find challenging work, rewarding opportunities, respect among colleagues, and attractive compensation. Amtrak maintains a culture that values high performance and recognizes individual employee contributions.


Amtrak is committed to a safe workplace free of drugs and alcohol. All Amtrak positions requires a pre-employment background check that includes prior employment verification, a criminal history check and a pre-employment drug screen.

Candidates who test positive for marijuana will be disqualified, regardless of any state or local statute, ordinance, regulation, or other law that legalizes or decriminalizes the use or possession of marijuana, whether for medical, recreational, or other use. Amtrak's pre-employment drug testing program is administered in accordance with DOT regulations and applicable law.


In accordance with DOT regulations (49 CFR § 40.25), Amtrak is required to obtain prior drug and alcohol testing records for applicants/employees intending to perform safety-sensitive duties for covered Department of Transportation positions. If an applicant/employee refuses to provide written consent for Amtrak to obtain these records, the individual will not be permitted to perform safety-sensitive functions.

 

In accordance with federal law governing security checks of covered individuals for providers of public transportation (Title 6 U.S.C. §1143), Amtrak is required to screen applicants for any permanent or interim disqualifying criminal offenses.


Note that any education requirement listed above may be deemed satisfied if you have an equivalent combination of education, training and experience.


Amtrak is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race/color, to include traits historically associated with race, including but not limited to, hair texture and hairstyles such as braids, locks and twists, religion, sex (including pregnancy, childbirth and related conditions, such as lactation), national origin/ethnicity, disability (intellectual, mental and physical), veteran status, marital status, ancestry, sexual orientation, gender identity and gender expression, genetic information, citizenship or any other personal characteristics protected by law.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Legal jobs →

Associate Counsel - Bronx, NY (Remote)

Full Time United States $118K - $186K per year Legal

Commercial Quality Compliance Specialist

Full Time United States $79000 - $127K per year Legal

Principal/Senior Consultant, Governance, Risk & Compliance 

Full Time United States Legal

Associate Director, Regulatory Strategy

Full Time United States $195K - $220K per year Legal

Lead Legal Counsel, Employment (EMEA)

Full Time Ireland, United Kingdom Legal

Senior Regulatory Compliance Coordinator (Remote) - Tisch Cancer Center

Full Time United States Legal
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Legal

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified