368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$61k – $82k per year
Location
Remote/Hybrid (Lisbon, Portugal)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Amgen is a global biopharmaceutical pioneer headquartered in Thousand Oaks, California, that specializes in discovering, developing, and manufacturing innovative biologic therapies. The company focuses on treating serious illnesses with high unmet medical needs across key areas including oncology, cardiovascular disease, inflammation, rare diseases, and nephrology. Leveraging advanced human genetics, molecular engineering, and biosimilar development, it serves millions of patients worldwide through established blockbuster treatments and cutting-edge pipelines.

Career Category

Information Systems

Job Description

Join our team at AMGEN Capability Center Portugal, consistently recognized among the top companies in the Best Workplaces(TM) ranking by Great Place to Work(R) in Portugal. In 2026, we were once again distinguished as one of the top Best Workplaces in the country (category 201-500 employees), reinforcing our commitment to an exceptional employee experience and workplace culture.

We are a team of over 500 talented individuals, spanning more than 30 functions and areas of expertise, and representing over 40 nationalities. Together, we bring diverse perspectives and professional backgrounds to help shape the future of healthcare through innovation and technology.

This is your opportunity to explore a world of possibilities across areas such as Data & Analytics, Digital, Technology & Innovation, Cybersecurity, R&D Operations, Global Distribution, Finance, Regulatory Affairs, General & Administrative, Human Resources, and many more.

Located in the heart of Lisbon, our AMGEN office fosters a culture of innovation, excellence, and purpose. Come thrive with us at AMGEN, supporting our mission To Serve Patients.

What we do at AMGEN matters in people's lives.

Incident Response Specialist Cybersecurity Ops Analyst

ABOUT THE ROLE Amgen is seeking an Incident Response Specialist Cybersecurity Ops Analyst, who will report to the Senior Manager, Information Systems, and will be based in Portugal ACC. At Amgen, our mission is simple: to serve patients.

Leading Amgen’s Cyber Security Organization, the Incident Response Cybersecurity Ops Analyst engages with key business and operational partners in enhancing the detection, response, and remediation of cyber related attacks on Amgen’s global enterprise while contributing and delivering services and projects that support the mission, priorities, and objectives of the organization.

The Incident Response Cybersecurity Ops Analyst will be part of a global team and is responsible for building services around incident identification, containment, eradication, recovery, and lessons learned. You will be directly responsible for organizing, training and equipping Amgen employees and contractors in a manner directly aligned with Amgen’s culture, principles, and core values.

In the capacity of Incident Response Cybersecurity Ops Analyst, you will craft and oversee standard operating procedures, field manuals, and operating instructions. As part of the investigation or remedial processes you will have to engage with key business and operational partners in managing the detection, response, and remediation of cyber related attacks on Amgen’s global enterprise.

The Incident Response Cybersecurity Ops Analyst is within the Incident Response team and is expected to contribute to and deliver services and projects that support the mission, priorities, and objectives of the organization. In this vital role you will:

Key Activities of the Incident Response Specialist Cybersecurity Ops Analyst

  • Execute all phases of the incident response lifecycle in accordance with the SANS PICERL framework, including preparation, identification, containment, eradication, recovery, and post-incident activities.
  • Perform advanced investigations involving endpoint, network, cloud, and identity-based security incidents across enterprise environments.
  • Analyze security events and alerts from SIEM, EDR/XDR, NDR, cloud security platforms, and threat intelligence sources to determine the scope, impact, and severity of security incidents.
  • Conduct enterprise-wide threat hunting using Indicators of Compromise (IOCs), Indicators of Attack (IOAs), behavioral analytics, and the MITRE ATT&CK framework.
  • Perform incident triage and validation to distinguish malicious activity from benign events and accurately scope security incidents.
  • Correlate endpoint, network, cloud, identity, email, and security control telemetry to reconstruct attack timelines and determine the extent of compromise.
  • Perform root cause analysis to identify initial access vectors, attacker techniques, persistence mechanisms, and opportunities to improve defensive controls.
  • Develop and execute containment, eradication, and recovery strategies that minimize operational impact while preserving investigative evidence.
  • Acquire, preserve, and analyze digital evidence in accordance with established forensic procedures and chain-of-custody requirements.
  • Perform forensic analysis of endpoints and system artifacts, including event logs, registry data, file system metadata, browser artifacts, and other operating system artifacts to support incident investigations.
  • Assist with forensic collection and analysis of endpoint, cloud, email, memory, and disk artifacts to support incident scoping and investigative activities.
  • Create and maintain detection content, including SIEM correlation rules, Sigma rules, IOC feeds, detection use cases, and other analytics to improve detection and response capabilities.
  • Develop automation and scripting using PowerShell, Python, Bash, SQL, or similar languages to improve investigation, evidence collection, and incident response efficiency.
  • Collaborate with SOAR engineering teams to automate investigation, enrichment, containment, and response workflows.
  • Partner with Threat Intelligence, Security Engineering, Cloud Security, Identity, Network Security, Endpoint Security, and other cybersecurity teams to investigate and remediate complex security incidents.
  • Produce detailed technical documentation, forensic findings, incident reports, attack timelines, and lessons learned to support remediation, legal, compliance, and regulatory requirements.
  • Maintain and enhance incident response playbooks, forensic procedures, investigation methodologies, and standard operating procedures based on evolving threats and organizational requirements.
  • Participate in tabletop exercises, purple team engagements, adversary emulation activities, and incident simulations to validate and improve incident response capabilities.
  • Research emerging threats, attacker tradecraft, vulnerabilities, and defensive technologies to continuously improve the organization's detection, response, and forensic capabilities.

Basic Qualifications

We are all different, yet we all use our unique contributions to serve patients. The incident response professional we seek is a great coordinator with 5 years of directly related experience

Preferred Qualifications

  • Experience as an Incident Response analyst supporting a multinational organization
  • Experience working with Agile principles and values
  • Practical DFIR experience in, Host, Network, Cloud (AWS, GCP, Azure) and Operations Technology (e.g., Purdue model layers 0-3.5)
  • Excellent written and verbal communication skills to diverse target audiences
  • Passionate, collaborative and results oriented
  • Comprehensive knowledge of the workings of security-related controls like firewalls, intrusion detection systems, anti-malware, secure gateways, security monitoring, data encryption and other industry-standard techniques and practices.
  • Extensive experience with security application tools and systems, e.g., CrowdStrike, QRadar, Encase, Office 365 Security, Log and Endpoint analysis tools
  • Demonstrated ability to coordinate/lead multiple projects/activities with competing priorities
  • Excellent data-driven problem solving and analytical skills and proven experience within high-performance team.
  • Skill in applying analytical ability; and communication techniques sufficient to present new or updated plans and procedures to Leadership for review, and final approval with the expectation of little to no rework.
  • Must be team-oriented, placing priority on the successful completion of team goals.
  • Must be highly motivated and able to work effectively under minimal supervision
  • Experience with regulated systems (GxP, SOX) in the pharmaceutical, biotechnology, healthcare industry
  • Demonstrated knowledge of digital network telecom including TCP/IP and related network protocols, Information Security standards and policies such as: ISO 27001/27002, NIST
  • Preferred Certifications (Minimum one of the certificates is a plus):
    • CISSP, GNFA, GCIH, GCFE, GCFA, GRID, CompTIA CySA+,AWS Security Specialist, or equivalent certifications.

APPLY NOW

Objects in your future are closer than they appear. Join us.

CAREERS.AMGEN.COM

EQUAL OPPORTUNITY STATEMENT

Amgen is an Equal Opportunity employer and will consider you without regard to your race, colour, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or any other basis protected by applicable law.

We will ensure that individuals with disabilities are provided with reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment.

.

Salary Range

52 320,90 EUR - 70 787,10 EUR
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Lisbon
$56k – $120k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Toronto
Python
SQL
Analytics
Power BI
Management
Power Apps
Power Automate
Apply
$58k – $135k per year (Estimated) • In office • Full-Time • Frankfurt am Main • Bonn
Python
SQL
Databases
Databricks
DevOps
Azure
Apply
$100k – $145k per year • In office • Full-Time • 5+ years exp • New York
JavaScript
SQL
TypeScript
Java
Java
Spring Boot
Databases
MySQL
Oracle
PostgreSQL
Frontend
Angular
React.js
Vue.js
DevOps
Git
Apply
In office • Full-Time • Noida
C#
SQL
TypeScript
JavaScript
C#
.NET
Databases
Oracle
Frontend
Angular
DevOps
Incident Management
SLI/SLO/SLA
Apply
Lead AI Engineer 7 hours ago
$106k – $227k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Omaha • Alpharetta
Java
Python
C#
TypeScript
JavaScript
Java
Spring Boot
C#
.NET
AI/ML
Claude
Copilot
LLM
Anthropic
OpenAI
Frontend
Angular
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitLab CI
Jenkins
Kubernetes
OpenShift
Rest API
GitLab
Apply
$14k – $38k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Hyderabad
JavaScript
Node JS
Python
SQL
AI/ML
Fine-tuning
LangChain
LlamaIndex
Prompt Engineering
Frontend
React.js
DevOps
AWS
CI/CD
Vector
Apply
Data Engineer 4 days ago
$26k – $51k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Hyderabad
Python
SQL
Python
pySpark
Databases
Databricks
PostgreSQL
AI/ML
Spark
Model Context Protocol
DevOps
AWS
AWS Lambda
Rest API
Amazon S3
GitLab
Management
Confluence
Apply
$184k – $249k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • Holly Springs
Cybersecurity
CAPA
Apply
$22k – $57k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Hyderabad
Python
SQL
Apex
Apex
MuleSoft
Databases
Databricks
AI/ML
Hadoop
Spark
DevOps
AWS
Azure
Docker
GCP
Kubernetes
Management
Jira
Apply
$156k – $211k per year • Remote • Full-Time • 10+ years exp • High School Diploma • Thousand Oaks
Python
Databases
Databricks
AI/ML
Kubeflow
LangChain
MLFlow
PyTorch
Scikit-learn
Spark
TensorFlow
Weights & Biases
DevOps
AWS
Azure
CI/CD
Docker
Kubernetes
Terraform
Apply
$41k – $97k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Lisbon
DevOps
Ansible
AWS
Azure
CI/CD
Docker
FinOps
GCP
Kubernetes
OpenShift
Terraform
Apply
$26k – $63k per year (Estimated) • In office • Full-Time • 5+ years exp • Lisbon
Java
DevOps
CI/CD
Git
GitLab
GitLab CI
Jenkins
Management
Jira
QA
Appium
Cucumber
Postman
Rest-Assured
Selenium
Apply
$36k – $81k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Lisbon
DevOps
IAM
Apply
$39k – $98k per year (Estimated) • In office • Full-Time • 2+ years exp • Lisbon
Bash
PowerShell
Python
SQL
Databases
ElasticSearch
DevOps
CI/CD
Kibana
Apply
$36k – $84k per year (Estimated) • In office • Full-Time • 5+ years exp • Lisbon
Python
SQL
AI/ML
NumPy
Time Series Forecasting
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.