NTT DATA Logo

NTT DATA

Senior Analyst: Information Security Incident Response

Posted 5 Hours Ago
Be an Early Applicant
In-Office
Sydney, New South Wales, AUS
Senior level
In-Office
Sydney, New South Wales, AUS
Senior level
Lead cloud security engineering and incident response across AWS and Azure environments. Manage CSPM, CWPP, SIEM, vulnerability management, cloud monitoring, threat detection, and security controls. Develop detection rules, dashboards, log integrations, threat-hunting processes, and automation using Python or PowerShell. Secure Kubernetes, Docker, CI/CD pipelines, and infrastructure-as-code deployments. Perform L3 troubleshooting, investigations, root cause analysis, governance support, documentation, and mentoring of junior analysts.
The summary above was generated by AI

Make an impact with NTT DATA
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.

We are seeking an experienced Senior Cloud Security Incident Response Analyst to support and enhance security across AWS and Azure environments.

This is a senior hands-on role focused on cloud security engineering, incident response, SIEM operations, DevSecOps integration, security automation, and continuous security improvement. You will work across cloud security platforms, cloud-native security controls, security monitoring, and modern workload protection while mentoring L1 and L2 team members.

Key Responsibilities
  • Implement and manage Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP/CWP) solutions.
  • Secure and support AWS and Azure cloud environments.
  • Configure and maintain compliance, workload protection, vulnerability management, and cloud security monitoring capabilities.
  • Perform L3 troubleshooting and root cause analysis.
  • Lead cloud security incident response and investigations.
  • Implement and review cloud security controls including identity and access management, network security, logging, and monitoring.
  • Support SIEM platforms including Splunk, Microsoft Sentinel, and Palo Alto Cortex XSIAM.
  • Develop and maintain detection rules, correlation searches, analytics content, dashboards, and alerting capabilities.
  • Onboard and integrate log sources across cloud, endpoint, network, identity, and application environments.
  • Support threat hunting, security monitoring, and incident investigations.
  • Integrate security into CI/CD pipelines and Infrastructure-as-Code deployments.
  • Secure Kubernetes, Docker, and other modern cloud workloads.
  • Develop automation using Python, PowerShell, and APIs.
  • Support governance, compliance, and audit activities.
  • Mentor junior team members and maintain operational documentation and runbooks.
  • Engage with stakeholders to support security improvement initiatives.
Skills & Experience

Required

  • 7-10 years of experience in IT, Cyber Security, or related disciplines.
  • Minimum 3 years' experience in Cloud Security Engineering.
  • Strong hands-on experience with AWS and Azure security.
  • Experience with CSPM and CWPP/CWP platforms.
  • Experience with Terraform, CloudFormation, or Infrastructure-as-Code security.
  • Experience with DevSecOps and CI/CD security practices.
  • Experience securing Kubernetes and containerised environments.
  • Strong understanding of cloud architecture, IAM, cloud networking, segmentation, and vulnerability management.
  • Experience with incident response and cloud threat detection.
  • Scripting and automation experience using Python and/or PowerShell.

Highly Desirable

  • Experience with Splunk Enterprise Security, Microsoft Sentinel, or Palo Alto Cortex XSIAM.
  • Experience in SIEM administration, security monitoring, detection engineering, and alert tuning.
  • Experience onboarding and troubleshooting log ingestion pipelines.
  • Familiarity with SPL, KQL, XQL, or similar query languages.
  • Experience with SOC operations, threat hunting, and incident investigation.
  • Experience with Qualys, Tenable, Rapid7, or similar vulnerability management tools.
  • Experience in Managed Security Services or Cloud Security Operations environments.
Qualifications
  • Bachelor's degree in Information Technology, Cyber Security, Engineering, or equivalent experience.
Preferred Certifications
  • AWS Security Specialty
  • Microsoft Azure Security Engineer
  • CISSP or CCSP
  • Kubernetes or DevSecOps certifications
  • Splunk certifications
  • Microsoft SC-200
  • Palo Alto Cortex XSIAM certifications

Workplace type:


About NTT DATA
NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune

Global 100. We are committed to accelerating client success and positively impacting society through

responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with

unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and

application services. Our consulting and industry solutions help organizations and society move

confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more

than 70 countries. We also offer clients access to a robust ecosystem of innovation centers as well as

established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each

year in R&D.


Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.


Third parties fraudulently posing as NTT DATA recruiters 

NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters whether in writing or by phone in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @nttdata.com email address. If you suspect any fraudulent activity, please contact us.

NTT DATA Sydney, New South Wales, AUS Office

Ground Floor, Tower 3, Darling Park, 201 Sussex Street, , , Sydney, NSW , Australia, 2000

Similar Jobs

37 Minutes Ago
Hybrid
Expert/Leader
Expert/Leader
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Leads executive-level strategic advisory engagements across Australia and New Zealand, helping C-suite and board stakeholders define transformation priorities, build investment cases, quantify business value, and align on growth, resilience, productivity, and risk outcomes. Partners with sales and account teams on major deals, mentors teams in value selling, develops thought leadership, and provides market insights to product and engineering teams. Requires extensive strategy consulting or value advisory experience, enterprise technology fluency, and travel up to 50%.
Top Skills: AIEnterprise Cloud SolutionsServicenow
3 Hours Ago
Remote or Hybrid
Entry level
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Supports major enterprise and telecommunications sales by delivering technical presentations, product demonstrations, installations, customizations, evaluation test plans, and Proof of Value engagements. Gathers technical requirements, manages customer evaluations, supports upselling and renewals, trains sales teams, collaborates with Product Management, and acts as a trusted security advisor. Requires expertise in cybersecurity, telecommunications, enterprise architectures, endpoint and cloud security, threat intelligence, and incident response.
Top Skills: AICloud SecurityEndpoint SecurityIdentity PreventionIncident ResponseMdr/XdrThreat IntelligenceZero-Trust
5 Hours Ago
Hybrid
Senior level
Senior level
Big Data • eCommerce • Fintech • Machine Learning • Payments • Software
Lead Riskified’s APAC Business Development team and define regional expansion strategy. Responsibilities include managing and developing business development representatives, using AI to scale personalized outreach, improving prospecting efficiency, researching target industries and companies, partnering with sales leadership, representing the company at industry events, and building relationships across the payments industry. The role requires people-management experience in Japan or Australia, complex sales leadership experience, strong analytical ability, English fluency, and ideally Japanese fluency.
Top Skills: Artificial IntelligenceEcommercePayments Technology

What you need to know about the Sydney Tech Scene

From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account