Talent.com
This job offer is not available in your country.
Principal Analyst : Information Security Incident Response (NTT)

Principal Analyst : Information Security Incident Response (NTT)

NTTmumbai, India
23 hours ago
Job description

JOB DESCRIPTION

Make an impact with NTT DATA

Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.

Your day at NTT DATA

The Principal Information Security Incident Response Analyst is a highly skilled subject matter exper, responsible for providing an escalation path for Level 1 and 2 workflows for high-risk incidents.

Additionally, this role facilitates proactive security measures through analytics and threat hunting processes and is responsible for detecting and monitoring escalated threats and suspicious activity affecting company technology domain (servers, networks, appliances and all infrastructure supporting production applications for the enterprise, as well as development environments).

This role is responsible to manage critical and high-risk exposures in the daily operation of real-time threat management activities.

This senior technical resource facilitates problem resolution and mentoring for the overall team. This includes operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning).

Key responsibilities :

  • Manages weekly sprints in Threat Hunting analytics.
  • Manages the processing of security alerts, events, and notifications (e.g. via email, ticketing, virus warning, intelligence feeds, workflow, etc.).
  • Manages the notification of internal and / or external teams according to agreed alert priority levels, and escalation trees.
  • Monitors events for suspicious events, investigation, and escalate where applicable.
  • Maintains an understanding of current and emerging threats, vulnerabilities, and trends.
  • Prioritizes threat analysis based on risks associated with each threat and working with the appropriate teams to ensure related communications are in line with company best practice and recommendations.
  • Acts as the primary technical lead for the Computer Incident Response Team (CIRT), coordinating the work of technical staff from various departments, as well as the work of third-party technical experts.
  • Ties third party attack monitoring services and threat reporting services, into internal CIRT communications systems, so as to better alert CIRT team members about what’s coming, and what preparations to undertake before production systems at NTT Ltd are damaged (and what remedial actions to take after damage has taken place).
  • Regularly reviews the current configurations of NTT Ltd production information systems and networks, with an eye towards the steps that attackers must take to break through existing defenses, and recommends configuration changes, system setting changes, network topology changes, and other modifications that would enhance the overall level of security.
  • Designs, specifies, programs, deploys, and fine-tunes custom software which analyses the vast amount of log, audit trail, and other recorded activity information that modern systems record, so as to be able to immediately detect unauthorized activity, most importantly intrusion by unauthorized parties and the execution of unauthorized software.
  • Designs automated scripts, automated contingency plans, and other programmed responses which are launched when an attack against company systems has been detected.
  • Designs, specifies, programs, debugs, and oversees the work of others related to middleware, and other system integration tools, which tie multiple security monitoring systems together so as to better meet company information security needs.
  • Performs post-mortem analyze with logs, network traffic flows, and other recorded information to identify intrusions by unauthorized parties, as well as unauthorized activities of authorized users.
  • Reviews incident and problem management reports to identify potential security weaknesses and perform an impact and risk analysis, developing recommendations for highlighted risks, ensuring that these risks and solutions are presented to the relevant stakeholders.
  • Ensures that security service audit schedules are developed, scoped, discussed and agreed with the business.
  • Reviews access authorization for compliance with policy, administration security controls for effectiveness, security on the operational systems and verify that security monitoring is working.

To thrive in this role, you need to have :

  • Ability to remain calm and focused during stressful situations.
  • Ability to listen and adapt to changing situations.
  • Ability to recognize potential problems and take steps to fix the issues.
  • Extended understanding of complex inter-relationships in an overall system or process.
  • Extended knowledge of technological advances within the information security arena.
  • Demonstrates analytical thinking and a proactive approach.
  • Displays consistent client focus and orientation.
  • Extended knowledge of information security management and policies.
  • Extended understanding of current and emerging threats, vulnerabilities, and trends.
  • Extended understanding of malware forensics, network forensics, and computer forensics also highly desirable.
  • Ability to statically and dynamically analyze malware to determine target and intention.
  • Ability to uncover and document tools, techniques, procedures used by cyber adversaries in attacking managed infrastructure.
  • Sound decision making abilities with demonstrate teamwork and collaboration skills.
  • Displays good planning and organizing ability.
  • Academic qualifications and certifications :

  • Bachelor’s degree or equivalent in Information Technology, Computer Science or related field.
  • SANS GIAC Security Essentials (GSEC) or equivalent preferred.
  • SANS GIAC Certified Intrusion Analyst (GCIA) or equivalent preferred.
  • SANS GIAC Certified Incident Handler (GCIH) or equivalent preferred.
  • Industry certifications such as CISSP, CISM, CISA, CEH, CHFI preferred.
  • Information Technology / ITILSM / ICT Security / ITIL v3 preferred.
  • Required experience :

  • Extended experience in a Technology Information Security Industry.
  • Extended experience working in a SOC / CSIRT.
  • Extended experience or knowledge of SIEM and IPS technologies.
  • Extended experience with Wireshark, tcpdump, Remnux, decoders for conducting payload analysis.
  • Extended experience in building SIEM rules and / or indicators of compromise for threat detection.
  • Workplace type : On-site Working

    About NTT DATA

    NTT DATA is a $30+ billion trusted global innovator of business and technology services. We serve 75% of the Fortune Global 100 and are committed to helping clients innovate, optimize and transform for long-term success. We invest over $3.6 billion each year in R&D to help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have diverse experts in more than 50 countries and a robust partner ecosystem of established and start-up companies. Our services include business and technology consulting, data and artificial intelligence, industry solutions, as well as the development, implementation and management of applications, infrastructure, and connectivity. We are also one of the leading providers of digital and AI infrastructure in the world. NTT DATA is part of NTT Group and headquartered in Tokyo.

    Equal Opportunity Employer

    NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.

    Create a job alert for this search

    Information Security Analyst • mumbai, India

    Related jobs
    • Promoted
    L3 UCCE and Release Management

    L3 UCCE and Release Management

    Servion Global SolutionsKalyan-Dombivli, IN
    Role : L3 UCCE support and Release Management.Supporting Experience on Cisco UCCE / UCCX / PCCE solutions & 3rd party Call recording platforms. Basic Cisco ICM / CCMP / CVP / CUIC & troubleshooting.MACD cr...Show moreLast updated: 19 days ago
    • Promoted
    Tactical Analyst

    Tactical Analyst

    MAX Securitythane, maharashtra, in
    Max is Global Risk Management organization based out in Tel Aviv, Israel and its APAC HQ is based out of Mumbai.Led by veterans from Israeli Military Special Forces, Intelligence, Cyber and Secret ...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Analyst- Urgent-Thane

    Information Security Analyst- Urgent-Thane

    Aditya Birla GroupThane, Maharashtra, India
    Job Description – Information Security Analyst (Defensive Security).Thane, Maharashtra, India (On-site).Job Description – Senior Information Security Analyst (SOC Function).Senior Information Secur...Show moreLast updated: 9 days ago
    • Promoted
    Senior Information Technology Audit Manager

    Senior Information Technology Audit Manager

    Bahwan CyberTekKalyan-Dombivli, IN
    Role : Information Technology Auditor.We are seeking a highly experienced and motivated.Information Technology Auditor.Group Internal Audit team of BCT. This role requires a minimum of 12 years of ex...Show moreLast updated: 2 days ago
    • Promoted
    Information Technology Governance Consultant

    Information Technology Governance Consultant

    INSPYR SolutionsKalyan-Dombivli, IN
    Job Opening : Governance, Risk & Compliance (GRC) Analyst – Level 2 / 3.Governance, Risk, and Compliance (GRC) Analyst.SaaS applications while helping define governance frameworks and risk processes.S...Show moreLast updated: 2 days ago
    • Promoted
    Information Technology Operations Analyst

    Information Technology Operations Analyst

    Vinebrook Technologymumbai, maharashtra, in
    Managed Service Provider (MSP) team.In this role, you will be responsible for providing 24 / 7 monitoring and management of client server, network, and security systems. You will act as the first line...Show moreLast updated: 30+ days ago
    • Promoted
    ITC Infotech - L3 Vulnerability Management / Risk & Compliance Lead

    ITC Infotech - L3 Vulnerability Management / Risk & Compliance Lead

    ITC Infotech India LtdMumbai, India
    Job Summary : ITCI Cyber Security team is looking for the role which is accountable for leading the organizations end-to-end vulnerability lifecycle and align...Show moreLast updated: 30+ days ago
    • Promoted
    L3 Server Engineer – Major Incident Management

    L3 Server Engineer – Major Incident Management

    Nextbridge IT SolutionsKalyan-Dombivli, IN
    We are seeking an experienced L3 Infrastructure Engineer to join our IT Operations team with a focus on Major Incident Management (MIM), incident request management, and rapid response for Priority...Show moreLast updated: 9 days ago
    • Promoted
    Information Technology Security Manager

    Information Technology Security Manager

    VAYUZ TechnologiesMumbai, Maharashtra, India
    Information Security Manager (AVP level).The role involves designing, implementing, and monitoring advanced security controls, ensuring compliance, and managing risk across IT systems and infrastru...Show moreLast updated: 1 day ago
    • Promoted
    Third Party Risk Management - Cyber Security (Pune, Bangalore, Gurgaon)

    Third Party Risk Management - Cyber Security (Pune, Bangalore, Gurgaon)

    DigiHelic Solutions Pvt. Ltd.Thane, IN
    Lead the end-to-end third-party risk assessment process including initial due diligence, onboarding, and periodic reviews. Collaborate and lead discussions with various departments from client’s tea...Show moreLast updated: 2 days ago
    • Promoted
    Security Lead

    Security Lead

    Eventus SecurityNavi Mumbai, Maharashtra, India
    Job Title : Security Lead (SOC).Location : Ahmedabad and Navi Mumbai.Responsibility Areas – Security Lead (L3) – SOC.Lead high-priority security investigations and incident response activities, ensur...Show moreLast updated: 30+ days ago
    • Promoted
    Technical Lead – Incident / Process Management(Location : Bangalore)

    Technical Lead – Incident / Process Management(Location : Bangalore)

    DigiHelic Solutions Pvt. Ltd.Thane, IN
    Technical Lead – Incident / Process Management.Technical Lead – Incident / Process Management.Lead day-to-day operations of the India team, ensure ITIL processes are followed, manage incidents, coordin...Show moreLast updated: 2 days ago
    • Promoted
    IAM Analyst

    IAM Analyst

    Dexian IndiaKalyan-Dombivli, IN
    Contractual Role / Freelancer-3 Months.Skills-IAM, Data analysis or validation (Excel, VLookup, Macro), Query Language (SQL or PowerShell) , Python (Good-to-Have). Need basic IAM conceptual Knowledge....Show moreLast updated: 2 days ago
    • Promoted
    Lead - Information Security Audit

    Lead - Information Security Audit

    Alpha OrionMumbai, India
    Lead IS Audit Job description The primary objective of Technology audits includes : - Ensure IT systems and...Show moreLast updated: 16 days ago
    • Promoted
    Cloud Security Architect

    Cloud Security Architect

    CloudThatthane, maharashtra, in
    Strategic role ensuring secure cloud design by reviewing infrastructure, tools, and practices across full cloud lifecycle. Own end-to-end security in project life cycle.Perform security design revie...Show moreLast updated: 27 days ago
    • Promoted
    Practice Lead

    Practice Lead

    Network IntelligenceThane, Maharashtra, India
    Strategic Leadership & Practice Development.MDR, CES, and MSSP lines of business (LOB).Security Operations & Threat Management. Security Operations Center (SOC).SIEM, EDR, SOAR, and threat intellige...Show moreLast updated: 27 days ago
    • Promoted
    Chief Information Security Officer

    Chief Information Security Officer

    AimhireThane, Maharashtra, India
    Job Opening : Chief Information Security Officer (CISO).Our client is a global leader in AI / ML-powered Customer Engagement and Experience Platforms (CEE). They are dedicated to revolutionizing how B2...Show moreLast updated: 30+ days ago
    • Promoted
    Lead Security Engineer

    Lead Security Engineer

    interface.aiThane, IN
    Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show moreLast updated: 28 days ago
    • Promoted
    Principal Analytics Consultant

    Principal Analytics Consultant

    ProspectionKalyan-Dombivli, IN
    Are you passionate about turning real-world healthcare data into actionable insights that improve patient outcomes? At.Principal Analytics Consultant. RWD) to deliver high-impact outcomes for pharma...Show moreLast updated: 14 days ago
    • Promoted
    Tuta Insurance Brokerage - Chief Information Security Officer

    Tuta Insurance Brokerage - Chief Information Security Officer

    Tuta Insurance BrokerageMumbai, India
    Chief Information Security Officer (CISO) Job Description Role Overview We are looking for a Chief Information Security Offic...Show moreLast updated: 30+ days ago