Incident Response Analyst L2

Posted:
1/10/2025, 4:06:55 AM

Location(s):
Arizona, United States

Experience Level(s):
Junior ⋅ Mid Level ⋅ Senior

Field(s):
IT & Security

Amex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We’re here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued.

 

Ready to explore a career path? Start your journey.

As a Cybersecurity Level Two Analyst in the travel industry, you will be responsible for enhancing and maintaining the security posture of Amex GBT, the leading business travel company in the world. You will support the Cybersecurity team by identifying, analyzing, and mitigating security threats and vulnerabilities, ensuring the protection of sensitive customer and operational data. Your role will involve responding to and investigating security incidents, as well as implementing and monitoring security controls to safeguard our IT infrastructure and applications.

*Must be located within 60 miles of Phoenix, AZ*

What You’ll Do:

1. Incident Response and Management:

  • Monitor security alerts and incidents using SIEM (Security Information and Event Management) tools and other monitoring systems.
  • Analyze and triage security incidents to determine their severity and potential impact.
  • Assist in the coordination of incident response activities, including containment, eradication, and recovery.

2. Security Monitoring and Analysis:

  • Review and analyze security logs and alerts to detect unauthorized access, anomalies, and potential breaches.
  • Perform root cause analysis of security events to improve detection and prevention measures.

3. Threat Intelligence Monitoring and Threat Hunt Management:

  • In coordination with the Cyber Threat Intelligence team, review threat intelligence to understand emerging threats and recommend appropriate mitigation strategies.
  • Collaborate with other teams to identify and scope systems with identified vulnerabilities in a timely manner.
  • Contain and remove indicators of attack and/or compromise found pursuant to threat hunting activity.

4. Security Policy and Procedure Enforcement:

  • Ensure compliance with industry regulations and organizational security policies and procedures.
  • Assist in the development and implementation of security policies, standards, and procedures specific to the travel industry.

5. Collaboration and Communication:

  • Work closely with IT teams, vendors, and other stakeholders to address security concerns and implement effective security solutions.
  • Provide technical support and guidance to less experienced team members and other departments as needed.

6. Documentation and Reporting:

  • Maintain accurate and up-to-date documentation of security incidents, investigations, and remediation efforts.
  • Prepare detailed reports on security incidents, vulnerabilities, and trends for management review.

What We’re Looking For:

  • Bachelor’s degree in Computer Science, Information Security, or a related field
  • 5  years of experience in cybersecurity or a related IT role, with hands-on experience in security monitoring, incident response, and vulnerability management.
  • Relevant certifications such as CompTIA Security+, CEH (Certified Ethical Hacker), or equivalent are preferred.
  • Familiarity with industry standards and frameworks (e.g., NIST, ISO 27001).
  • Understanding of common security technologies and practices (e.g., firewalls, IDS/IPS, antivirus solutions).
  • Knowledge of security issues specific to the travel industry, such as data protection regulations and secure transaction processing preferred.
  • Strong analytical and problem-solving skills with attention to detail.
  • Proficiency in using security tools and technologies (e.g., XSoar, Crowdstrike, NG SIEM, Proofpoint, Abnormal, Palo Alto, Cisco,  ).
  • Scripting language proficiency (Python, PowerShell, etc.) with the ability to filter and analyze large data sets.
  • Experience with cloud security and emerging technologies.

#GBTJobs

     

Location

Arizona, United States

     

     

The US national annual base salary range for this position is from $60,000 to $120,000.  The national range provided includes the base salary that GBT expects to pay for the role.  Actual base salary will be based on factors including the scope and complexity of the role and the successful candidate’s relevant experience, skills, knowledge, and work location.

In addition to base salary, this role is eligible for an annual Performance Based Incentive, which rewards participants based on company performance.  For information about our comprehensive US benefits programs and eligibility, please review our Benefits-at-a-Glance document.

Benefits at a glance

     

     

The #TeamGBT Experience

Work and life: Find your happy medium at Amex GBT.

  • Flexible benefits are tailored to each country and start the day you do. These include health and welfare insurance plans, retirement programs, parental leave, adoption assistance, and more.

  • Travel perks: get a choice of deals each week from major travel providers on everything from flights to hotels to cruises and car rentals.

  • Develop the skills you want when the time is right for you, with global tuition assistance, access to over 20,000 courses on our learning platform, leadership courses, and new job openings available to internal candidates first.

  • We strive to champion Diversity, Equity, and Inclusion in every aspect of our business at GBT. You can connect with colleagues through our global Inclusion Groups, centered around common identities or initiatives, to discuss challenges, obstacles, achievements, and drive company awareness and action.

  • Wellbeing resources to support mental and emotional health for you and your immediate family.

  • And much more!

All applicants will receive equal consideration for employment without regard to age, sex, gender (and characteristics related to sex and gender), pregnancy (and related medical conditions), race, color, citizenship, religion, disability, or any other class or characteristic protected by law.

Click Here for Additional Disclosures in Accordance with the LA County Fair Chance Ordinance.

Furthermore, we are committed to providing reasonable accommodation to qualified individuals with disabilities. Please let your recruiter know if you need an accommodation at any point during the hiring process. For details regarding how we protect your data, please consult GBT Recruitment Privacy Statement.

What if I don’t meet every requirement? If you’re passionate about our mission and believe you’d be a phenomenal addition to our team, don’t worry about “checking every box;" please apply anyway. You may be exactly the person we’re looking for!

American Express Global Business Travel

Website: https://www.amexglobalbusinesstravel.com/

Headquarter Location: Jersey City, New Jersey, United States

Employee Count: 10001+

Year Founded: 2014

IPO Status: Public

Last Funding Type: Post-IPO Debt

Industries: Consulting ⋅ Event Management ⋅ Travel