Investigate and respond to cybersecurity incidents including phishing, malware, ransomware, and unauthorized access. Analyze logs, alerts, and forensic data; support containment, eradication, and recovery; escalate complex incidents; document findings; maintain SOC playbooks and procedures; and collaborate with threat intelligence, vulnerability management, and forensics teams to improve detection and response capabilities.
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!
Job Details
The Engineer I - Cyber Incident Response, is a junior-level technical role within the Security Operations Center (SOC) responsible for detecting, investigating, and responding to cybersecurity incidents. This role performs in-depth analysis of alerts, escalates complex cases, and contributes to the improvement of response processes and playbooks. The Engineer I will collaborate with global cyber defense teams to contain threats, minimize business impact, and strengthen detection capabilities. This position requires strong analytical skills, hands-on technical expertise, and the ability to operate effectively in a fast-paced environment.
Primary Duties and Responsibilities
Education and Qualifications
Preferred Certifications (at least 1)
Work Experience
Bachelor's degree in cybersecurity, computer science, information technology, or a related field required, or equivalent experience required. Less than 2 years of experience in IT support, network administration, security operations (SOC), or entry-level cybersecurity required. Certifications such as CompTIA Security+, GIAC Information Security Fundamentals (GISF), Certified in Cybersecurity (CC), or equivalent preferred. Beginning to moderate expertise in foundational IT and security concepts (e.g., networking protocols, operating systems, basic malware behavior). Ability to apply standard practices to resolve routine issues and follow documented steps accurately. Strong willingness to learn and build technical capability in the incident response domain. Effective written and verbal communication skills to share progress and basic observations within the immediate team. Detail-oriented approach to ensure accuracy and timeliness of localized outputs and alert handling.
What Cencora offers
Benefit offerings outside the US may vary by country and will be aligned to local market practice. The eligibility and effective date may differ for some benefits and for team members covered under collective bargaining agreements.
Full time
Affiliated Companies
Affiliated Companies: CENCORA BUSINESS SERVICES INDIA PRIVATE LIMITED
Equal Employment Opportunity
Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.
The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.
Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email [email protected]. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned
Job Details
The Engineer I - Cyber Incident Response, is a junior-level technical role within the Security Operations Center (SOC) responsible for detecting, investigating, and responding to cybersecurity incidents. This role performs in-depth analysis of alerts, escalates complex cases, and contributes to the improvement of response processes and playbooks. The Engineer I will collaborate with global cyber defense teams to contain threats, minimize business impact, and strengthen detection capabilities. This position requires strong analytical skills, hands-on technical expertise, and the ability to operate effectively in a fast-paced environment.
Primary Duties and Responsibilities
- Investigate and respond to cybersecurity incidents, including phishing, malware, ransomware, and unauthorized access attempts.
- Perform analysis of logs, alerts, and forensic data to determine the scope and impact of incidents.
- Escalate complex or high-severity incidents to Engineer II/III, Lead, or Principal staff, providing clear documentation and evidence.
- Assist in containment, eradication, and recovery activities during incident response.
- Contribute to the development and maintenance of SOC playbooks, runbooks, and standard operating procedures.
- Collaborate with threat intelligence, vulnerability management, and forensics teams to strengthen detection and response strategies.
- Participate in lessons-learned sessions and recommend improvements to SOC processes and tooling.
Education and Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent work experience.
- Strong knowledge of cybersecurity fundamentals, incident response methodology, and adversary tactics.
- Familiarity with industry frameworks such as NIST, MITRE ATT&CK, and ISO 27035.
Preferred Certifications (at least 1)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- CompTIA Security+ or CySA+
- Certified Ethical Hacker (CEH)
Work Experience
- 2+ years of progressive experience in cybersecurity, with knowledge in SOC operations or incident response.
- Hands-on experience with SIEM, EDR, and forensic tools (e.g., Splunk, CrowdStrike, Wireshark).
- Demonstrated ability to analyze logs, alerts, and artifacts to support incident investigations.
- Strong written and verbal communication skills for documenting findings and briefing stakeholders.
Bachelor's degree in cybersecurity, computer science, information technology, or a related field required, or equivalent experience required. Less than 2 years of experience in IT support, network administration, security operations (SOC), or entry-level cybersecurity required. Certifications such as CompTIA Security+, GIAC Information Security Fundamentals (GISF), Certified in Cybersecurity (CC), or equivalent preferred. Beginning to moderate expertise in foundational IT and security concepts (e.g., networking protocols, operating systems, basic malware behavior). Ability to apply standard practices to resolve routine issues and follow documented steps accurately. Strong willingness to learn and build technical capability in the incident response domain. Effective written and verbal communication skills to share progress and basic observations within the immediate team. Detail-oriented approach to ensure accuracy and timeliness of localized outputs and alert handling.
What Cencora offers
Benefit offerings outside the US may vary by country and will be aligned to local market practice. The eligibility and effective date may differ for some benefits and for team members covered under collective bargaining agreements.
Full time
Affiliated Companies
Affiliated Companies: CENCORA BUSINESS SERVICES INDIA PRIVATE LIMITED
Equal Employment Opportunity
Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law.
The company's continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non-discriminatory.
Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email [email protected]. We will make accommodation determinations on a request-by-request basis. Messages and emails regarding anything other than accommodations requests will not be returned
Similar Jobs at Cencora
Healthtech • Logistics • Pharmaceutical
Investigates and responds to cybersecurity incidents including phishing, malware, ransomware, and unauthorized access. Analyzes logs, alerts, forensic data, and security artifacts; supports containment, eradication, and recovery; escalates high-severity cases; and maintains SOC playbooks and procedures. The role collaborates with threat intelligence, vulnerability management, and forensics teams, improves detection capabilities, participates in lessons learned, and guides junior analysts.
Top Skills:
CrowdstrikeEdrIso 27035Mitre Att&CkNistSIEMSplunkWireshark
Healthtech • Logistics • Pharmaceutical
Leads complex technical projects and programs by managing scope, schedules, budgets, risks, dependencies, governance, stakeholder expectations, and executive reporting. Coordinates engineering, product, data, and business teams, resolves delivery issues, improves project management frameworks, and mentors junior project managers within pharmaceutical distribution technology programs.
Healthtech • Logistics • Pharmaceutical
Leads complex cyber incident investigations involving advanced threats, ransomware, phishing, and insider activity. Performs forensic analysis across endpoints, networks, and cloud environments; develops incident response playbooks and detection use cases; and coordinates with threat intelligence and vulnerability teams. Serves as an escalation point for critical incidents, reports findings to leadership, contributes to red and purple team exercises, improves SOC processes, and mentors junior engineers.
Top Skills:
CrowdstrikeEdrEncaseIso 27035Mitre Att&CkNistSIEMSoarSplunkWireshark
What you need to know about the Mumbai Tech Scene
From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

