Talent.com
This job offer is not available in your country.
Principal Analyst : Information Security Incident Response (NTT)

Principal Analyst : Information Security Incident Response (NTT)

ConfidentialMumbai, India
7 days ago
Job description

Make an impact with NTT DATA

Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.

Your day at NTT DATA

The Principal Information Security Incident Response Analyst is a highly skilled subject matter exper, responsible for providing an escalation path for Level 1 and 2 workflows for high-risk incidents.

Additionally, this role facilitates proactive security measures through analytics and threat hunting processes and is responsible for detecting and monitoring escalated threats and suspicious activity affecting company technology domain (servers, networks, appliances and all infrastructure supporting production applications for the enterprise, as well as development environments).

This role is responsible to manage critical and high-risk exposures in the daily operation of real-time threat management activities.

This senior technical resource facilitates problem resolution and mentoring for the overall team. This includes operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning).

Key responsibilities :

  • Manages weekly sprints in Threat Hunting analytics.
  • Manages the processing of security alerts, events, and notifications (e.g. via email, ticketing, virus warning, intelligence feeds, workflow, etc.).
  • Manages the notification of internal and / or external teams according to agreed alert priority levels, and escalation trees.
  • Monitors events for suspicious events, investigation, and escalate where applicable.
  • Maintains an understanding of current and emerging threats, vulnerabilities, and trends.
  • Prioritizes threat analysis based on risks associated with each threat and working with the appropriate teams to ensure related communications are in line with company best practice and recommendations.
  • Acts as the primary technical lead for the Computer Incident Response Team (CIRT), coordinating the work of technical staff from various departments, as well as the work of third-party technical experts.
  • Ties third party attack monitoring services and threat reporting services, into internal CIRT communications systems, so as to better alert CIRT team members about what's coming, and what preparations to undertake before production systems at NTT Ltd are damaged (and what remedial actions to take after damage has taken place).
  • Regularly reviews the current configurations of NTT Ltd production information systems and networks, with an eye towards the steps that attackers must take to break through existing defenses, and recommends configuration changes, system setting changes, network topology changes, and other modifications that would enhance the overall level of security.
  • Designs, specifies, programs, deploys, and fine-tunes custom software which analyses the vast amount of log, audit trail, and other recorded activity information that modern systems record, so as to be able to immediately detect unauthorized activity, most importantly intrusion by unauthorized parties and the execution of unauthorized software.
  • Designs automated scripts, automated contingency plans, and other programmed responses which are launched when an attack against company systems has been detected.
  • Designs, specifies, programs, debugs, and oversees the work of others related to middleware, and other system integration tools, which tie multiple security monitoring systems together so as to better meet company information security needs.
  • Performs post-mortem analyze with logs, network traffic flows, and other recorded information to identify intrusions by unauthorized parties, as well as unauthorized activities of authorized users.
  • Reviews incident and problem management reports to identify potential security weaknesses and perform an impact and risk analysis, developing recommendations for highlighted risks, ensuring that these risks and solutions are presented to the relevant stakeholders.
  • Ensures that security service audit schedules are developed, scoped, discussed and agreed with the business.
  • Reviews access authorization for compliance with policy, administration security controls for effectiveness, security on the operational systems and verify that security monitoring is working.

To thrive in this role, you need to have :

  • Ability to remain calm and focused during stressful situations.
  • Ability to listen and adapt to changing situations.
  • Ability to recognize potential problems and take steps to fix the issues.
  • Extended understanding of complex inter-relationships in an overall system or process.
  • Extended knowledge of technological advances within the information security arena.
  • Demonstrates analytical thinking and a proactive approach.
  • Displays consistent client focus and orientation.
  • Extended knowledge of information security management and policies.
  • Extended understanding of current and emerging threats, vulnerabilities, and trends.
  • Extended understanding of malware forensics, network forensics, and computer forensics also highly desirable.
  • Ability to statically and dynamically analyze malware to determine target and intention.
  • Ability to uncover and document tools, techniques, procedures used by cyber adversaries in attacking managed infrastructure.
  • Sound decision making abilities with demonstrate teamwork and collaboration skills.
  • Displays good planning and organizing ability.
  • Academic qualifications and certifications :

  • Bachelor's degree or equivalent in Information Technology, Computer Science or related field.
  • SANS GIAC Security Essentials (GSEC) or equivalent preferred.
  • SANS GIAC Certified Intrusion Analyst (GCIA) or equivalent preferred.
  • SANS GIAC Certified Incident Handler (GCIH) or equivalent preferred.
  • Industry certifications such as CISSP, CISM, CISA, CEH, CHFI preferred.
  • Information Technology / ITILSM / ICT Security / ITIL v3 preferred.
  • Required experience :

  • Extended experience in a Technology Information Security Industry.
  • Extended experience working in a SOC / CSIRT.
  • Extended experience or knowledge of SIEM and IPS technologies.
  • Extended experience with Wireshark, tcpdump, Remnux, decoders for conducting payload analysis.
  • Extended experience in building SIEM rules and / or indicators of compromise for threat detection.
  • Workplace type : On-site Working

    About NTT DATA

    NTT DATA is a $30+ billion trusted global innovator of business and technology services. We serve 75% of the Fortune Global 100 and are committed to helping clients innovate, optimize and transform for long-term success. We invest over $3.6 billion each year in R&D to help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have diverse experts in more than 50 countries and a robust partner ecosystem of established and start-up companies. Our services include business and technology consulting, data and artificial intelligence, industry solutions, as well as the development, implementation and management of applications, infrastructure, and connectivity. We are also one of the leading providers of digital and AI infrastructure in the world. NTT DATA is part of NTT Group and headquartered in Tokyo.

    Equal Opportunity Employer

    NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.

    Show more

    Show less

    Skills Required

    Wireshark, Tcpdump, Log Monitoring, Computer Forensics, Threat Hunting, network forensics, Siem

    Create a job alert for this search

    Information Security Analyst • Mumbai, India

    Related jobs
    • Promoted
    SOC Analyst L2 / L3 - SIEM,IBM Qradar,SOAR,Threat hunting,Forensics - 4+ Years - Mumbai Vikhroli

    SOC Analyst L2 / L3 - SIEM,IBM Qradar,SOAR,Threat hunting,Forensics - 4+ Years - Mumbai Vikhroli

    Innova ESImumbai, maharashtra, in
    Interview Date - 18th Sep - Thursday.Job Location - Mumbai / Vikhroli.Please refer to the job description below for your kind reference : . SOC Analyst – Level 2 (L2) / Level 3 (L3).Deep-dive investiga...Show moreLast updated: 5 days ago
    • Promoted
    TPRM Analyst

    TPRM Analyst

    ConfidentialMumbai
    Understanding the requirement to conduct comprehensive information security risk assessment of 3rd party service provider (TPRM) who will provide new services / applications.Plan / conduct periodic as...Show moreLast updated: 15 days ago
    • Promoted
    Senior Security Operations Center (SOC) Analyst

    Senior Security Operations Center (SOC) Analyst

    ConfidentialMumbai
    We are seeking a highly skilled and motivated Senior SOC Analyst to join our dynamic team.You will play a critical role in safeguarding our organization's information assets by monitoring, detectin...Show moreLast updated: 30+ days ago
    • Promoted
    Associate Information Security Analyst

    Associate Information Security Analyst

    ConfidentialMumbai, India
    Join a company that is pushing the boundaries of what is possible.We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society.Our wo...Show moreLast updated: 30+ days ago
    • Promoted
    Bandhan AMC - Infosec Analyst

    Bandhan AMC - Infosec Analyst

    Bandhan Asset Management CompanyThane
    Job Description & responsibilities : - Oversee the information security programs including data protection, risk management, and compliance testing.Audit...Show moreLast updated: 30+ days ago
    • Promoted
    Security Analyst

    Security Analyst

    Total CollectR Virtual Collector & Debt Negotiatordombivli, maharashtra, in
    SaaS platform that helps businesses manage past-due debt collection accounts.We create better consumer experiences, help our customers collect more and empower our employees to succeed through cust...Show moreLast updated: 2 days ago
    • Promoted
    Manager Incident Response and Threat Intelligence

    Manager Incident Response and Threat Intelligence

    ConfidentialNavi Mumbai, Mumbai, Mumbai City
    Manage the full lifecycle of incident response, including detection, containment, eradication, and recovery.Serve as the escalation point for complex incidents and ensure timely resolution.Develop ...Show moreLast updated: 11 days ago
    • Promoted
    Information Security Analyst- Urgent-Thane

    Information Security Analyst- Urgent-Thane

    Aditya Birla Groupthane, maharashtra, in
    Job Description – Information Security Analyst (Defensive Security).Thane, Maharashtra, India (On-site).Job Description – Senior Information Security Analyst (SOC Function).Senior Information Secur...Show moreLast updated: 5 days ago
    • Promoted
    Lead - Information Security Audit

    Lead - Information Security Audit

    Alpha OrionMumbai, India
    Lead IS Audit Job description The primary objective of Technology audits includes : - Ensure IT systems and...Show moreLast updated: 13 days ago
    • Promoted
    Security Analyst

    Security Analyst

    ConfidentialMumbai
    We are hiring a Security Analyst to work on our growing IT Security team.This position will primarily monitor our computer networks and IT assets for security issues. install, operate, and maintain...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Associate Information Security Analyst

    Senior Associate Information Security Analyst

    ConfidentialMumbai, India
    Join a company that is pushing the boundaries of what is possible.We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society.Our wo...Show moreLast updated: 7 days ago
    • Promoted
    Oracle Cloud ERP Senior Analyst (Security and Risk Management)

    Oracle Cloud ERP Senior Analyst (Security and Risk Management)

    Sikich IndiaThane, IN
    Oracle Cloud ERP Senior Analyst.Security and Risk Management) with 5+ years of related experience in Oracle Cloud or any other Tier 1 ERP application. Accounting, Advisory, and Technical professiona...Show moreLast updated: 30+ days ago
    • Promoted
    D&T Analyst II - Cyber Security, Incident Response

    D&T Analyst II - Cyber Security, Incident Response

    ConfidentialPowai, Mumbai
    D&T Analyst II, Cyber Security, Incident Response.We make foodthe world loves : 100 brands.With iconic brands like Cheerios, Pillsbury, Betty Crocker, Nature Valley, and Häagen-Dazs, we've been serv...Show moreLast updated: 7 days ago
    • Promoted
    Incident Response - Lead

    Incident Response - Lead

    ConfidentialNavi Mumbai
    The Lead Incident Response Team is responsible for overseeing the end-to-end management of technology incidents across the enterprise. This role ensures rapid detection, containment, resolution, and...Show moreLast updated: 7 days ago
    • Promoted
    Lead - Information Security Auditor

    Lead - Information Security Auditor

    ConfidentialMumbai
    Conduct the IS audits (ITGC controls, VA, PT, APPSEC, NSAR, CA, BCP, DR, Cloud Security, Cyber.Security, Security Operations and Surveillance, Information security and privacy controls, IT Processe...Show moreLast updated: 7 days ago
    • Promoted
    Security Operations Analyst, Senior

    Security Operations Analyst, Senior

    ConfidentialMumbai, India
    Senior Information Security Analyst - SOC.Newfold Digital is a leading web technology company serving millions of customers globally. Our customers know us through our robust portfolio of brands.We ...Show moreLast updated: 7 days ago
    • Promoted
    Security Analyst

    Security Analyst

    SBI Operations SupportMumbai
    About the Role : We are seeking a proactive Security Analyst to join our growing Information Security team.The role focuses on threat detection, inc...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Information Security Analyst

    Senior Information Security Analyst

    ConfidentialMumbai
    Senior Information Security Analyst.The ideal candidate will have extensive experience in information security, a solid understanding of a wide range of security technologies, and the ability to ef...Show moreLast updated: 7 days ago