NTT DATA  Services

Cybersecurity Incident Responder

NTT DATA Services$90K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of professional experience in IT or cybersecurity roles.
  • 4+ years in cybersecurity, help desk, system administration, SOC, or incident response.
  • 1+ year of hands-on experience in the full Incident Response lifecycle.
  • 1+ year of experience investigating email phishing incidents.
  • Experience with key cybersecurity tools like Splunk, EDR, and vulnerability scanners.
  • Possession of CompTIA Security+ CE certification.
  • Top Secret Security Clearance, with SCI eligibility.

Responsibilities

  • Detect and analyze cybersecurity incidents across various environments.
  • Contain and eradicate threats while managing recovery processes.
  • Conduct investigations on alerts and confirmed incidents in enterprise networks and the cloud.
  • Utilize SIEM tools for continuous monitoring of security alerts and user reports.
  • Document incident response activities, creating accurate tickets and reports for leadership.
  • Support insider-threat investigations and manage data-loss events.
  • Coordinate containment actions and remediation efforts for compromised systems.

Benefits

  • Flexible work arrangements, including remote or hybrid options based on client needs.
  • Commitment to local hiring, facilitating timely and effective client support.
  • Focus on evolving needs of clients and employees to maintain workplace satisfaction.
  • Access to professional development resources and training opportunities.
Full Job Description
Req ID: 373115

We are currently seeking a Cybersecurity Incident Responder to join our team in Fort Bragg, North Carolina (US-NC), United States (US).

Job Summary:

The Cyber Incident Responder is responsible for detecting, analyzing, containing, eradicating, and recovering from cybersecurity incidents across enterprise, endpoint, network, and cloud environments. This role supports daily cyber defense operations by responding to malicious activity, suspicious events, policy violations, malware infections, spillages, and other reportable cyber incidents. The ideal candidate understands core incident response principles, follows established procedures, and coordinates effectively with system administrators, network teams, security leadership, and mission stakeholders throughout cyber events.

Key responsibilities include conducting investigations and responding to cybersecurity alerts and confirmed incidents across enterprise networks and cloud platforms such as AWS, Microsoft Azure, and Google Cloud. The responder executes containment actions on compromised systems or accounts, supports eradication and recovery efforts, and documents all response activities through incident closure. The role also involves analyzing malware infections and responding to indicators of ransomware, trojans, spyware, and unauthorized software, coordinating host containment and remediation actions such as antivirus or EDR scanning, reimaging, and evidence preservation when necessary.

Additionally, the position requires knowledge of DoD and federal incident categories, including handling or assisting with CAT 1, 2, 4, 7, and CAT 5 spillage events, and understanding appropriate escalation procedures and reporting timelines. The responder also manages spillage and data-loss events by containing and sanitizing affected systems, coordinating reporting and remediation, and supporting insider-threat or data-exfiltration investigations as required.

The role conducts continuous monitoring by reviewing SIEM alerts, logs, endpoint notifications, and user reports, utilizing tools such as Trellix ESS, Splunk ES, Splunk SOAR, MAR/HX, NSM, Varonis, IDS, Stealthwatch, Cylance, and ForeScout to correlate data and determine incident scope and impact. Strong documentation and reporting skills are essential, including creating accurate incident tickets, detailed timelines, after-action reports, maintaining evidence and chain-of-custody records, and briefing leadership or management as needed.

Basic Qualifications:
  • Minimum 7 years' of professional experience
  • Minimum 4 years' of experience in cybersecurity, help desk, system administration, SOC, or IR.
  • Minimum 1 year of experience in Incident Response lifecycle (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned)
  • Minimum 1 year of experience in Email phishing investigations
  • Minimum 1 year of experience with one or more:
    • Splunk and Elastic for Cloud
    • Endpoint Detection & Response (EDR) tools
    • Antivirus platforms
    • Vulnerability scanners (ACAS)
    • ServiceNow, Remedy or similar ticketing systems
  • DoD 8570/8140 certification: CompTIA Security+ CE
  • Top Secret Security Clearance, SCI eligible.


Preferred Qualifications:
  • Malware basics
  • Networking fundamentals (IP, DNS, ports, protocols)
  • Experience supporting enterprise IT environment
  • Certification in one of: CySA+, CASP+, GIAC (GCIH, GCFA, etc.)

Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client's needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use [redacted].com, [redacted].com and [redacted].nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us.

NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us.

About NTT DATA Services

NTT DATA Corporation is a Japanese multinational information technology service and consulting company headquartered in Tokyo, Japan. It is partially-owned subsidiary of Nippon Telegraph and Telephone. Japan Telegraph and Telephone Public Corporation, a predecessor of NTT, started Data Communications business in 1967. NTT, following its privatization in 1985, spun off the Data Communications division as NTT DATA in 1988, which has now become the largest of the IT Services companies headquartered in Japan.
Learn more about NTT DATA Services
Size
151,991 employees
Industry
Founded
1988
NASDAQ

Similar Jobs

More Jobs at NTT DATA Services

More Information Technology Jobs

Find similar Cybersecurity Incident Responder jobs: