{"id":1174219,"url":"https://alion.io/job/cencora-engineer-iii-cyber-incident-response-2","title":"Engineer III - Cyber Incident Response","company":{"id":1040788,"name":"Cencora","domain":"cencora.com","url":"https://alion.io/company/cencora","size_band":"5000+","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Vilnius, Lithuania"],"countries":["LT"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":40000,"max_usd":96000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":337},"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Crowdstrike","optional":false},{"name":"EnCase","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"Red Teaming","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"Wireshark","optional":false}],"status":"live","first_seen_at":"2026-08-14T00:00:00Z","employer_posted_date":"2026-08-14","last_verified_at":"2026-09-25T01:20:30Z","board_verified":true,"closed_at":null,"days_open":42,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":42},"description":"Cencora, previously known as AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving lives. Ranked #21 on the Global Fortune 500, our team members are united in our responsibility to create healthier futures.\nOur Shared Service Center in Lithuania is experiencing rapid growth and we have many diverse and exciting roles in Customer Service, Operations, IT, Finance and HR. Join us and make a positive impact on human and animal health.\nJob Details\nThe Engineer III - Cyber Incident Response, is a senior technical role within the Security Operations Center (SOC) responsible for leading complex incident investigations and supporting the continuous improvement of detection and response capabilities. This role provides advanced technical expertise in identifying, analyzing, containing, and remediating cyber threats. The Engineer III will act as a mentor to junior analysts, serve as an escalation point for critical incidents, and collaborate with global cyber defense teams to ensure timely and effective responses to advanced threats.\nResponsibilities:\nLead the investigation and resolution of complex security incidents, including advanced persistent threats, ransomware, phishing campaigns, and insider activities.\n\nPerform forensic analysis across endpoints, networks, and cloud environments to identify root causes and scope of compromise.\n\nDevelop and enhance incident response playbooks, runbooks, and detection use cases.\n\nCollaborate with threat intelligence, vulnerability management, and countermeasures teams to strengthen defenses.\n\nEscalate high-severity incidents to senior leadership and provide clear, actionable reporting.\n\nAct as a technical escalation point for Engineer I/II analysts during incident investigations.\n\nContribute to red team and purple team exercises to validate and improve response capabilities.\n\nParticipate in after-action reviews and lessons-learned sessions to improve SOC processes.\n\nMentor and train junior engineers on incident response best practices and investigative techniques.\n\nEducation:\nBachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent work experience; Master’s degree preferred.\n\nPreferred Certifications:\nGIAC Certified Incident Handler (GCIH)\n\nGIAC Certified Intrusion Analyst (GCIA)\n\nGIAC Certified Forensic Analyst (GCFA)\n\nCertified Ethical Hacker (CEH)\n\nCertified Information Systems Security Professional (CISSP)\n\nWork Experience:\n7+ years of progressive experience in cybersecurity, with at least 4 years in incident response or SOC operations.\n\nHands-on experience with SIEM, EDR, SOAR, and forensic tools (e.g., Splunk, CrowdStrike, EnCase, Wireshark).\n\nProven ability to investigate advanced threats and coordinate response activities across teams.\n\nDemonstrated success in mentoring junior analysts and improving SOC processes.\n\nStrong written and verbal communication skills with the ability to document and present technical findings clearly.\n\nSkills and Knowledge:\nStrong knowledge of incident response methodologies, digital forensics, and adversary tactics.\n\nFamiliarity with security frameworks such as NIST, MITRE ATT&CK, and ISO 27035.\n\nSalary Ranges: 4657 - 6653 EUR gross monthly\n# Li-hybrid\nWhat Cencora offers\nWe offer a competitive annual bonus, life insurance from Day 1, a best-in-class health insurance package, and up to 6 fully paid benefit days a year. As a Cencora employee, you have the benefit of our referral bonus scheme, our boundless learning opportunities and our global Employee Assistance Program. We have a wonderful office location in Quadrum, equipped with everything you need for a small break at work and fresh snacks at all times. Become part of our purpose-driven, multicultural team now and help us create healthier futures\nFull timeAffiliated Companies:\nAffiliated Companies: World Courier (Lithuania) UAB","description_format":"text","description_chars":3898,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Health insurance","Life insurance"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response","Health Care","Pharmaceuticals","Cell & Gene Therapy"],"lifecycle":[{"event":"open","at":"2026-09-24T10:26:56Z"}],"liveness":{"score":17,"band":"cold","label":"Long shot","p_open":1,"p_active":0.624,"p_room":0.28,"age_days":42,"expected_fill_days":18,"reasons":["conf:2","win:tail","crowd:brand"],"computed_at":"2026-09-25T03:38:35Z"},"pay":null,"html_url":"https://alion.io/job/cencora-engineer-iii-cyber-incident-response-2","json_url":"https://alion.io/job/cencora-engineer-iii-cyber-incident-response-2.json","meta":{"generated_at":"2026-09-25T03:38:35Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3971,"day_limit":5000,"remaining_today":1029,"minute_limit":60,"resets_at":"2026-09-26T00:00:00Z"}}}