Your day at NTT DATA
- The Principal Information Security Analyst is a highly skilled subject matter expert responsible for Platform evolution, Integration support, New COTS review/analysis, L4 Platform operations support and mentoring for the overall team.
- This includes Platform architecture design, regular architecture reviews, platform build & automation, integration design & build, tool evolution, Major platform upgrades, security event reporting, and content engineering.
Key Responsibilities:
- Lead and Works as part of a Security Platform Engineering team
- Responsible for the MSSP platform architecture designing
- Lead and build new service platform and automation for the SOC/security services
- Conduct architecture reviews and updates
- Support new integrations design and build
- Lead the new COTS capability review and analysis
- Lead the new tool evaluation and POC
- Act as the advisor and consultant for the Platform and Content Engineering, stake holder requests, escalations, reporting, trainings.
- Support the review of lifecycle management of the supported security tools/technologies, Break-fix, Patching
- Support in designing the SOPs and notify stake holders on log flow/log format issues.
- Documents best practices.
- Identifies opportunities to make automations which will help the incident response team.
- Documents and closes resolved incidents according to agreed procedures.
- Investigates and identifies root cause of major platform disruptions and assist with the implementation of agreed remedies and preventative measures.
- Cooperates with all stakeholders including vendors and carriers to expedite diagnosis of errors and problems and to identify a resolution.
Knowledge and Attributes:
- Extended knowledge on implementation and monitoring of MS sentinel, PaloAlto XSIAM, MS LogicApps, XSOAR, and/or other automation tools with Google SecOps (optional)
- Extended knowledge on security and SOC architecture, worked across different security technologies, DevOps & automation tools
- Good knowledge and experience on different cloud native services such as Azure, and Google
- Customer service orientated and pro-active thinking.
- Problem solver who is highly driven and self-organized.
- Great attention to detail.
- Good analytical and logical thinking.
- Excellent spoken and written communication skills.
- Team player and lead with the ability to work well with others and in group with colleagues and stakeholders.
Academic Qualifications and Certifications:
- Bachelor's degree or equivalent in Information Technology or related field.
- Relevant level of security certifications such as PaloAlto XSIAM engineer/Architect, Azure DevOps or equivalent, SC-100, DW-350, DW-360 or equivalent
- Relevant level of additional Security certifications such as AZ-500, CEH, CISSP, CISM etc. will be added advantage.
Required experience:
- 14 + years' experience in Security
- Extended experience in Security technologies like SIEM, SOAR, EDR, XDR, CDR, Cloud native security services and security architecture
- Minimum experience of 5 Years in DevOps, Scripting using Python, KQL and XQL
- Extended experience in technical support to clients.
- Extended experience in diagnosis and troubleshooting.
- Extended experience providing remote support in Security Technologies.
- Extended experience in SOC/CSIRT Operations.
- Knowledge on networking, Linux, Agentic AI/RAG and security concepts.
- Good understanding and experience in configuring/managing security controls such as Firewall, IDS/IPS, EDR, NDR, UTM, Proxy, SOAR, HoneyPots and other security tools.
- Knowledge on log collection mechanism such as Syslog, Log file, DB API.
- Extensive experience in Security Engineering.