SIGN IN
Cyber Defense & Incident Responder jobs in United States
cer-icon
Apply on Employer Site
company-logo

NTT DATA North America · 12 hours ago

Cyber Defense & Incident Responder

NTT DATA is a business and technology services leader, and they are seeking a Cyber Defense & Incident Responder to join their team. This role is responsible for monitoring, analyzing, and responding to cybersecurity incidents, focusing on incident triage, investigation, containment, and recovery to minimize impact and restore normal operations.
ConsultingDigital MarketingInformation ServicesInformation TechnologyIT Management
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Monitor enterprise security systems and analyze alerts to identify potential cybersecurity incidents
Review SIEM, IDS/IPS, EDR, and other related tool alerts for anomalous activity and indicators of compromise/attacks (IOCs/IOAs)
Validate alerts to reduce false positives and prioritize based on severity and potential impact
Perform initial triage and analysis of security events to determine scope, severity, and urgency
Examine log data, network telemetry, and endpoint information to identify possible malicious activity
Correlate event details with internal and external threat intelligence
Execute incident response actions in accordance with established procedures
Contain affected systems, remove malicious artifacts, and assist in system recovery
Escalate complex or critical incidents to Senior SOC Analysts or SOC Leads
Document and communicate incident findings to support resolution and improvement efforts
Prepare incident tickets, timelines, and investigative notes
Contribute to after-action reviews (AARs) and post-incident reporting
Create incident tickets
Upload supporting evidence, draw sound conclusions and upload artifacts
Communicate effectively, providing clear, accurate, and concise information
Exercise sound analytical skills to derive correct conclusions associated with incident investigations
Maintain SOC processes, tools, and playbooks to ensure effective incident handling
Recommend refinements to SOPs and escalation procedures
Identify opportunities to streamline analysis workflows and improve detection capabilities
Participate in training, exercises, and knowledge-sharing to strengthen response readiness
Support red, blue, or purple team exercises when directed
Share lessons learned and best practices with SOC team members
Stay informed on current and emerging cyber threats relevant to the organization’s environment
Track evolving tactics, techniques, and procedures (TTPs) of threat actors
Incorporate relevant intelligence into incident analysis and response

Qualification

Cybersecurity incident responseSIEM toolsThreat intelligenceDoD 8140 certificationInformation Technology experienceAnalytical skillsCommunication skillsTeam collaboration

Required

Bachelor's degree in information technology, cybersecurity, data science, information systems, or computer science
Minimum 6 years of experience in Information Technology (IT) and/or Information Security (IS)
DoD 8140 certification for their respective area or the ability to obtain certification within six (6) months of onboarding
Ability to obtain a interim Secret Security Clearance and must be eligible for a Top-Secret clearance if requested

Company

NTT DATA North America

company-logo
NTT DATA, Inc. is a trusted global innovator of business and technology services.