Cyber Security Engineer

NTT Data, Inc.

$124K — $137K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in cybersecurity, detection engineering, SOC engineering, security analytics, or security operations.
  • Experience in analyzing logs and security telemetry from various sources.
  • Familiarity with cloud SIEM, UEBA, EDR, SOAR technologies.
  • Proficient in query languages and data analysis for security event investigation.
  • Skilled in developing automation and detection-as-code pipelines.
  • Ability to convert threat intelligence into actionable detection strategies.
  • Experience with MITRE framework or similar mapping techniques.

Responsibilities

  • Design and maintain threat detection logic for cloud and on-premises environments.
  • Build data ingestion and log onboarding pipelines for security telemetry.
  • Collaborate with threat intelligence teams to create actionable detections.
  • Work with security analysts and responders to validate detection coverage.
  • Develop detection rules and fine-tune alert thresholds to minimize false positives.
  • Map detection strategies to the MITRE framework for improvement tracking.
  • Leverage automation and scripting to enhance detection processes.

Benefits

  • Medical, dental, and vision insurance.
  • Flexible spending or health savings account.
  • Life and AD&D insurance.
  • Short- and long-term disability coverage.
  • Paid time off and employee assistance programs.
  • Participation in a 401k program with company match.
  • Additional voluntary or legally required benefits.
Full Job Description
We are currently seeking a Cyber Security Engineer to join our team in Charlotte, North Carolina (US-NC), United States (US). Job Description:
Cyber Security Engineer - Threat Detection

Role Description
Client is seeking a Cyber Security Engineer - Threat Detection to join a high-performing Security Operations team responsible for advancing the Bank's security monitoring, detection engineering, and cyber defense capabilities. This role focuses on building, tuning, and maintaining effective detections across cloud and on-premises environments to help proactively identify, investigate, and respond to threats before they impact SMBC. The successful candidate will bring hands-on experience with security telemetry, analytics, automation, and detection-as-code practices, and will be expected to execute detection engineering activities with limited guidance while collaborating closely with analysts, incident responders, threat intelligence, and technology partners. Role Objectives
  • Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness.
  • Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services.
  • Partner with threat intelligence teams to translate emerging threats, attacker techniques, and indicators of compromise into actionable detection strategies.
  • Collaborate with security analysts, incident responders, SOC engineers, and cross-functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond.
  • Develop and fine-tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to improve fidelity and reduce false positives.
  • Map detections and coverage to relevant frameworks, including MITRE Telecommunication&CK, to support measurable improvements in monitoring and response capabilities.
  • Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content.
  • Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency.
  • Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements.
  • Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks.
  • Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen SMBC's cyber resilience.
Qualifications and Skills
  • Minimum of 3 years of relevant cybersecurity, detection engineering, SOC engineering, security analytics, or security operations experience.
  • Hands-on experience analyzing logs and security telemetry from multiple sources, including endpoint, network, identity, cloud, infrastructure, and application platforms.
  • Experience with cloud SIEM, UEBA, EDR, SOAR, data lake, or related detection and monitoring technologies.
  • Strong knowledge of query languages and data analysis techniques used to investigate security events and develop detection logic.
  • Experience developing detection-as-code pipelines, automation, scripts, or repeatable processes to improve security operations efficiency.
  • Ability to translate threat intelligence, adversary behaviors, and attack techniques into practical detections and monitoring use cases.
  • Experience mapping detections to MITRE Telecommunication & CK or similar security frameworks.
  • Working knowledge of Windows and Linux operating systems, common enterprise infrastructure, and cloud environments.
  • Strong troubleshooting, analytical, and problem-solving skills, with the ability to identify root cause and recommend practical improvements.
  • Ability to balance operational responsibilities with project delivery in a fast-paced environment.
  • Strong documentation, communication, collaboration, and stakeholder management skills.
  • Demonstrated ownership, attention to detail, and ability to work effectively in a global team environment.
  • Additional cybersecurity experience in incident response, threat intelligence, vulnerability management, security engineering, or cloud security is a plus.
Where required by law, NTT DATA provides a reasonable range of compensation for specific roles. The starting hourly range for this remote role is ($60-$66/hour). This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on several factors, including the candidate's actual work location, relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance.

This position is eligible for company benefits that will depend on the nature of the role offered. Company benefits may include medical, dental, and vision insurance, flexible spending or health savings account, life, and AD&D insurance, short-and long-term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally required benefits.

Similar Jobs

More Jobs at NTT Data, Inc.

More Information Technology Jobs

Find similar Cyber Security Engineer jobs: