NTT DATA  Services

Cyber Defense & Incident Responder

NTT DATA Services$101K — $152K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, Cybersecurity, Data Science, Information Systems, or Computer Science (substitutable with 1.5 years of experience per year of education)
  • 6+ years in IT and/or Information Security
  • DoD 8140 certification or ability to obtain within 6 months
  • Active Secret or higher security clearance, eligible for Top-Secret clearance

Responsibilities

  • Monitor security systems and analyze alerts to identify cybersecurity incidents
  • Perform initial triage and analysis of security events to ascertain severity
  • Execute incident response actions like containment and recovery
  • Document and communicate findings for resolution support
  • Maintain and refine SOC processes, tools, and playbooks
  • Participate in training and knowledge-sharing for response readiness
  • Stay informed on current and emerging cyber threats

Benefits

  • Medical, dental, and vision insurance with employer contribution
  • Flexible spending or health savings account
  • Life and AD&D insurance
  • Short and long-term disability coverage
  • Paid time off
  • 401k program with company match
Full Job Description
Req ID: 382076

We are currently seeking a Cyber Defense & Incident Responder to join our team in Arlington, Virginia (US-VA), United States (US).

Job Summary:

The Cyber Defense & Incident Responder is responsible for monitoring, analyzing, and responding to assigned cybersecurity incidents in accordance with established procedures. This role focuses on incident triage, investigation, containment, and recovery to minimize impact and restore normal operations. Analysts leverage security tools, event logs, correlation data, and threat intelligence to determine the nature and scope of incidents, document findings, and recommend remediation steps.

Job Duties:
  1. Monitor enterprise security systems and analyze alerts to identify potential cybersecurity incidents.
    1. Review SIEM, IDS/IPS, EDR, and other related tool alerts for anomalous activity and indicators of compromise/attacks (IOCs/IOAs).
    2. Validate alerts to reduce false positives and prioritize based on severity and potential impact.
  2. Perform initial triage and analysis of security events to determine scope, severity, and urgency.
    1. Examine log data, network telemetry, and endpoint information to identify possible malicious activity.
    2. Correlate event details with internal and external threat intelligence.
  3. Execute incident response actions in accordance with established procedures.
    1. Contain affected systems, remove malicious artifacts, and assist in system recovery.
    2. Escalate complex or critical incidents to Senior SOC Analysts or SOC Leads.
  4. Document and communicate incident findings to support resolution and improvement efforts.
    1. Prepare incident tickets, timelines, and investigative notes.
    2. Contribute to after-action reviews (AARs) and post-incident reporting.
    3. Create incident tickets
    4. Upload supporting evidence, draw sound conclusions and upload artifacts
    5. Communicate effectively, providing clear, accurate, and concise information
    6. Exercise sound analytical skills to derive correct conclusions associated with incident investigations.
  5. Maintain SOC processes, tools, and playbooks to ensure effective incident handling.
    1. Recommend refinements to SOPs and escalation procedures.
    2. Identify opportunities to streamline analysis workflows and improve detection capabilities.
  6. Participate in training, exercises, and knowledge-sharing to strengthen response readiness.
    1. Support red, blue, or purple team exercises when directed.
    2. Share lessons learned and best practices with SOC team members.
  7. Stay informed on current and emerging cyber threats relevant to the organization's environment.
    1. Track evolving tactics, techniques, and procedures (TTPs) of threat actors.
    2. Incorporate relevant intelligence into incident analysis and response.


Basic Qualifications:
  • Bachelor's degree in information technology, cybersecurity, data science, information systems, or computer science.
    • Education Equivalency: One-and-one- half (1.5) years of additional experience can substitute for one (1) year of a typical degree program.
  • Minimum 6 years experience in Information Technology (IT) and/or Information Security (IS).
  • DoD 8140 certification for respective area or the ability to obtain certification within six (6) months of onboarding.
  • Active Secret or higher security clearance holder and must be eligible for a Top-Secret clearance if requested.


Preferred Qualifications:
  • DCWF Role 511 - Cyber Defense Analyst / 531 - Cyber Defense Incident Responder advanced & intermediate certifications:
    • Cisco: CBROPS
    • CompTIA: CySA+, Cloud+, PenTest+, Security+
    • EC-Council: CEH
    • GIAC: GCFA, GCIA, GICSP, GMON, GRID, CED, GDSA, GSEC
    • ISC2: CCSP


NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this role is $101,376 - $152,064. Actual compensation will depend on a number of factors, including the candidate's relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance. If the position offered in temporary, the position will not be eligible for incentive compensation. This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits.

Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client's needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use [redacted].com, [redacted].com and [redacted].nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us.

About NTT DATA Services

NTT DATA Corporation is a Japanese multinational information technology service and consulting company headquartered in Tokyo, Japan. It is partially-owned subsidiary of Nippon Telegraph and Telephone. Japan Telegraph and Telephone Public Corporation, a predecessor of NTT, started Data Communications business in 1967. NTT, following its privatization in 1985, spun off the Data Communications division as NTT DATA in 1988, which has now become the largest of the IT Services companies headquartered in Japan.
Learn more about NTT DATA Services
Size
151,991 employees
Industry
Founded
1988
NASDAQ

Similar Jobs

More Jobs at NTT DATA Services

More Information Technology Jobs

Find similar Cyber Defense & Incident Responder jobs: