Key Roles and Responsibilities:
Work as part of a global CSIRT team that works 24/7 on rotational shifts. Work as part of Platform and Content Engineering handling tunings, stake holder requests, escalations, reporting, trainings Administration of the NTT Data Inc security tools to gather security logs from environment Life cycle management of the supported security tools/technologies, Break-fix, Patching, Live update Adhering to SOPs and notify stake holders on log flow/log format issues Document best practices Identify opportunities to make automations which will help the incident response team. This role involves security incident handling and response from several vectors including End Point Protection and Enterprise Detection and response tools, attack analysis, malware analysis, network forensics, computer forensics, and a broad range of skills in LAN technologies, Windows and Linux O/S’s, and general security infrastructure. Carry out agreed maintenance tasks Ensures usage of knowledge articles in incident diagnosis and resolution and assist with updating as and when required Perform defined tasks to monitor service delivery against service level agreements and maintains records of relevant information Investigate causes of incidents and seeks resolution Escalate unresolved incidents and follow up until incident is resolved Provide service recovery, following resolution of incidents Document and close resolved incidents according to agreed procedures
Knowledge, Skills and Attributes:
Applies learned techniques, as well as company policies and procedures to resolve a variety of issues Working knowledge on implementation and monitoring of any SIEM or security tools/technologies Knowledge on security architecture, worked across different security technologies Customer service orientated and pro-active thinking Problem solver who is highly driven and self-organised Great attention to detail Good analytical and logical thinking Excellent spoken and written communication skills Team player with the ability to work well with others and in group with colleagues and stakeholders
Academic Qualifications and Certifications:
Degree or relevant qualification in IT/Computing Relevant level of Networking certifications such as CCNA, JNCIA, ACCA, PCNSA, CCSA etc. Relevant level of Security certifications such as AZ-, SC-, Security+, CEH etc. will be added advantage
Required Experience:
Moderate level experience in Security technologies like (Firewall, IPS, IDS, Proxy etc.) Moderate level experience in technical support to clients Moderate level experience in diagnosis and troubleshooting Moderate level experience providing remote support in Security Technologies Moderate level experience in SOC/CSIRT Operations Moderate level experience in handling security incidents end to end Knowledge on networking, Linux and security concepts Moderate level experience in configuring/managing security controls such as Firewall, IDS/IPS, EDR, NDR, UTM, Proxy, SOAR, HoneyPots and other security tools Knowledge on log collection mechanism such as Syslog, Log file, DB API Knowledge in security architecture Moderate level experience in Security engineering Skills Summary
Ability to Work Under Pressure, Critical Thinking, Customer Service, Cybersecurity, Logical Thinking, Problem Solving, Teamwork, Troubleshooting, Written Communication
What will make you a good fit for the role?
Workplace type:
Hybrid Working
Equal Opportunity Employer
NTT is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, color, sex, religion, national origin, disability, pregnancy, marital status, sexual orientation, gender reassignment, veteran status, or other protected category