Principal Analyst: Information Security Incident Response
2 days ago
Make an impact with NTT DATA
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.
The Principal Information Security Incident Response Analyst is a highly skilled subject matter exper, responsible for providing an escalation path for Level 1 and 2 workflows for high-risk incidents.
Additionally, this role facilitates proactive security measures through analytics and threat hunting processes and is responsible for detecting and monitoring escalated threats and suspicious activity affecting company technology domain (servers, networks, appliances and all infrastructure supporting production applications for the enterprise, as well as development environments).
This role is responsible to manage critical and high-risk exposures in the daily operation of real-time threat management activities.
This senior technical resource facilitates problem resolution and mentoring for the overall team. This includes operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning).
Key responsibilities:
- Manages weekly sprints in Threat Hunting analytics.
- Manages the processing of security alerts, events, and notifications (e.g. via email, ticketing, virus warning, intelligence feeds, workflow, etc.).
- Manages the notification of internal and/or external teams according to agreed alert priority levels, and escalation trees.
- Monitors events for suspicious events, investigation, and escalate where applicable.
- Maintains an understanding of current and emerging threats, vulnerabilities, and trends.
- Prioritizes threat analysis based on risks associated with each threat and working with the appropriate teams to ensure related communications are in line with company best practice and recommendations.
- Acts as the primary technical lead for the Computer Incident Response Team (CIRT), coordinating the work of technical staff from various departments, as well as the work of third-party technical experts.
- Ties third party attack monitoring services and threat reporting services, into internal CIRT communications systems, so as to better alert CIRT team members about what's coming, and what preparations to undertake before production systems at NTT Ltd are damaged (and what remedial actions to take after damage has taken place).
- Regularly reviews the current configurations of NTT Ltd production information systems and networks, with an eye towards the steps that attackers must take to break through existing defenses, and recommends configuration changes, system setting changes, network topology changes, and other modifications that would enhance the overall level of security.
- Designs, specifies, programs, deploys, and fine-tunes custom software which analyses the vast amount of log, audit trail, and other recorded activity information that modern systems record, so as to be able to immediately detect unauthorized activity, most importantly intrusion by unauthorized parties and the execution of unauthorized software.
- Designs automated scripts, automated contingency plans, and other programmed responses which are launched when an attack against company systems has been detected.
- Designs, specifies, programs, debugs, and oversees the work of others related to middleware, and other system integration tools, which tie multiple security monitoring systems together so as to better meet company information security needs.
- Performs post-mortem analyze with logs, network traffic flows, and other recorded information to identify intrusions by unauthorized parties, as well as unauthorized activities of authorized users.
- Reviews incident and problem management reports to identify potential security weaknesses and perform an impact and risk analysis, developing recommendations for highlighted risks, ensuring that these risks and solutions are presented to the relevant stakeholders.
- Ensures that security service audit schedules are developed, scoped, discussed and agreed with the business.
- Reviews access authorization for compliance with policy, administration security controls for effectiveness, security on the operational systems and verify that security monitoring is working.
To thrive in this role, you need to have:
- Ability to remain calm and focused during stressful situations.
- Ability to listen and adapt to changing situations.
- Ability to recognize potential problems and take steps to fix the issues.
- Extended understanding of complex inter-relationships in an overall system or process.
- Extended knowledge of technological advances within the information security arena.
- Demonstrates analytical thinking and a proactive approach.
- Displays consistent client focus and orientation.
- Extended knowledge of information security management and policies.
- Extended understanding of current and emerging threats, vulnerabilities, and trends.
- Extended understanding of malware forensics, network forensics, and computer forensics also highly desirable.
- Ability to statically and dynamically analyze malware to determine target and intention.
- Ability to uncover and document tools, techniques, procedures used by cyber adversaries in attacking managed infrastructure.
- Sound decision making abilities with demonstrate teamwork and collaboration skills.
- Displays good planning and organizing ability.
Academic qualifications and certifications:
- Bachelor's degree or equivalent in Information Technology, Computer Science or related field.
- SANS GIAC Security Essentials (GSEC) or equivalent preferred.
- SANS GIAC Certified Intrusion Analyst (GCIA) or equivalent preferred.
- SANS GIAC Certified Incident Handler (GCIH) or equivalent preferred.
- Industry certifications such as CISSP, CISM, CISA, CEH, CHFI preferred.
- Information Technology / ITILSM / ICT Security / ITIL v3 preferred.
Required experience:
- Extended experience in a Technology Information Security Industry.
- Extended experience working in a SOC/CSIRT.
- Extended experience or knowledge of SIEM and IPS technologies.
- Extended experience with Wireshark, tcpdump, Remnux, decoders for conducting payload analysis.
- Extended experience in building SIEM rules and/or indicators of compromise for threat detection.
Workplace type:
On-site WorkingAbout NTT DATA
NTT DATA is a $30+ billion trusted global innovator of business and technology services. We serve 75% of the Fortune Global 100 and are committed to helping clients innovate, optimize and transform for long-term success. We invest over $3.6 billion each year in R&D to help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have diverse experts in more than 50 countries and a robust partner ecosystem of established and start-up companies. Our services include business and technology consulting, data and artificial intelligence, industry solutions, as well as the development, implementation and management of applications, infrastructure, and connectivity. We are also one of the leading providers of digital and AI infrastructure in the world. NTT DATA is part of NTT Group and headquartered in Tokyo.
Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.
-
Incident Response Analyst
2 weeks ago
Mumbai, Maharashtra, India L&T Technology Services Ltd. Full time ₹ 6,00,000 - ₹ 18,00,000 per yearLTTS IndiaMumbaiJob DescriptionJob Description: Level 2 Incident Response AnalystRole Overview:As a Level 2 Incident Response Analyst, you will play a pivotal role in enhancing the cybersecurity posture of Maharashtra. Your expertise will contribute to deep investigations, escalated incident handling, and proactive threat mitigation. This position requires 5...
-
Analyst, Information Security
5 days ago
Mumbai, Maharashtra, India Pall Corporation Full time ₹ 5,00,000 - ₹ 12,00,000 per yearBring more to life.Are you ready to accelerate your potential and make a real difference within life sciences, diagnostics and biotechnology?At Pall Corporation, one of Danaher's 15+ operating companies, our work saves lives—and we're all united by a shared commitment to innovate for tangible impact.You'll thrive in a culture of belonging where you and...
-
Incident Response
4 days ago
Navi Mumbai, Maharashtra, India KPMG Assurance and Consulting Services LLP Full time ₹ 8,00,000 - ₹ 24,00,000 per yearRole SummaryWe are seeking a highly skilled cybersecurity professional to join our team as a Threat Hunter / Incident Response Specialist. The ideal candidate will have hands-on experience in proactive threat hunting, incident detection, and response, with strong expertise in ELK (Elasticsearch, Logstash, Kibana) for log analysis and visualization.Key...
-
Cyber Security Incident Response handler
2 weeks ago
Mumbai, Maharashtra, India FlexibleIR Full time ₹ 6,00,000 - ₹ 18,00,000 per yearA very interesting and responsible role to defend India's largest Critical Infrastructure companies against major Cyber attacks and overall Crisis Management in general for the organisation Company DescriptionFlexibleIR helps organizations be prepared for cyber attacks by providing a process-centered approach to building strong cyber Incident Response...
-
Information Security Analyst
7 days ago
Mumbai, Maharashtra, India NTT DATA Global Delivery Services Ltd Full time ₹ 12,00,000 - ₹ 36,00,000 per yearSenior MS Engineer, SOC Make an impact with NTT DATA Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.Your...
-
Information Security Analyst
2 weeks ago
Mumbai, Maharashtra, India NTT DATA Global Delivery Services Ltd Full time ₹ 5,00,000 - ₹ 15,00,000 per yearSec Ops - L2 Make an impact with NTT DATA Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.Your day at NTT...
-
Information Security Analyst
2 weeks ago
Mumbai, Maharashtra, India NTT DATA Global Delivery Services Ltd Full time ₹ 6,00,000 - ₹ 18,00,000 per yearSOC Engineer - L2 Make an impact with NTT DATA Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.Your day at...
-
soc analyst- l3
4 days ago
Mumbai, Maharashtra, India IARM Information Security Full time ₹ 15,00,000 - ₹ 25,00,000 per yearJOB DESCRIPTION:Responsible for responding to security incidents identified by internal controls or external SOC partnersStrictly adhere to service level agreements (SLAs), metrics and business scorecard obligations for ticket handling security incidents and events.Hands-on experience with Security Information and Event Management (SIEM) tools...
-
Incident Response Lead
2 weeks ago
Mumbai, Maharashtra, India Anzen Technologies Full time ₹ 12,00,000 - ₹ 24,00,000 per yearANZEN Technologies Pvt. Ltd. is a leading cybersecurity service provider that empowers organizations across various industries with advanced security services, innovative solutions, and unmatched expertise in cybersecurity, IT Governance, Risk Management, and Compliance.Incident Response Lead Profile:The Incident Response Lead is responsible for driving and...
-
Analyst, Security Operations, Information
6 days ago
Mumbai, Maharashtra, India CPP Investments Full time ₹ 12,00,000 - ₹ 36,00,000 per yearCompany Description Make an impact at a global and dynamic investment organizationWhen you join CPP Investments, you are joining one of the world's most admired and respected institutional investors. With more than $600 billion in assets under management, CPP Investments is a professional investment management organization that globally invests the funds of...