Security Engineer

NTT DATA
Birmingham, United Kingdom
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
£ 84K

Job location

Birmingham, United Kingdom

Tech stack

Microsoft Active Directory
Amazon Web Services (AWS)
Proxy Servers
Software System Penetration Testing
JIRA
Azure
Bash
Burp Suite
Cloud Computing
Cloud Computing Security
Configuration Management Databases
Configuration Management
CompTIA Security+
Computer Security
Data Normalization
Linux
DNS
Multi-Factor Authentication
Identity and Access Management
Issue Tracking Systems
JSON
Python
Lightweight Directory Access Protocols (LDAP)
Microsoft Security Essentials
Windows Server
OAuth
Parsing
Public Key Infrastructure
Powershell
Role-Based Access Control
Openid Connect
ArcSight SIEM Tool
Ansible
Fortify (Software)
Security Assertion Markup Language (SAML)
Security Information and Event Management
Single Sign-On
Syslog
TCP/IP
User Provisioning Software
Software Vulnerability Management
XML
Scripting (Bash/Python/Go/Ruby)
Google Cloud Platform
Okta
System Availability
Grafana
QRadar
Cyber Threat Analysis
Firewalls (Computer Science)
Containerization
Kubernetes
Palo Alto Networks
Patch Management
Cortex XSOAR Platform
Checkmarx
CIS Benchmarks
Kibana
REST
Terraform
Splunk
Software Version Control
Qualys
Docker
Jenkins
Servicenow
Static Application Security Testing
Vulnerability Analysis
Dynamic Application Security Testing

Job description

The Security Tooling Engineer is responsible for the operation, maintenance, integration, and optimization of security platforms and tools that support the delivery of security services across NTT DATA and Service Recipients. This role ensures that security tooling operates reliably, integrates seamlessly with enterprise infrastructure, and complies with governance requirements outlined., Platform Operations & Maintenance

  • Operate and maintain security platforms in accordance with agreed Service Level Agreements (SLAs) as defined in Service Levels and KPIs

  • Ensure high availability, performance, and reliability of all security tooling

  • Monitor platform health and proactively address performance issues

  • Manage platform upgrades, patches, and version control

  • Provide monthly health and performance reports for all managed security platforms

Data Source Management & Integration

  • Manage onboarding of data sources to security platforms (e.g., log sources to SIEM)

  • Configure data parsing, normalization, and enrichment to ensure data quality

  • Design and maintain dashboards and visualizations for security monitoring and reporting

  • Ensure integration with other Security Services and Tooling across the ecosystem

  • Integrate security tools with recipients clients or Globals Splunk SIEM, CMDB, and ticketing systems

  • Implement SSO (Single Sign-On) and MFA (Multi-Factor Authentication) integration with recipient clients or Globals identity and access management systems

Access Management & Governance

  • Enforce Role-Based Access Control (RBAC) across all security platforms

  • Conduct quarterly access reviews to ensure least-privilege access

  • Manage user provisioning and deprovisioning for Global, Service Recipients, and authorized Supplier personnel

  • Maintain auditable logs of all access changes

  • Ensure all access changes are logged and auditable per clients requirements

Configuration & Change Management

  • Manage security tool configurations in accordance with the Change Control Procedure

  • Document all configuration changes and maintain configuration baselines

  • Ensure configuration changes are approved by Global and/or Service Recipients before implementation

  • Maintain configuration management database (CMDB) entries for all security tooling

  • Support configuration audits and compliance reviews

Vulnerability & Patch Management

  • Perform vulnerability scans of security tooling platforms in line with Vulnerability Management Service requirements

  • Apply patches within timelines defined by recipient clients or Global policies and standards

  • Report remediation status monthly

  • Escalate unpatched critical vulnerabilities immediately to recipient clients or Global service

  • Ensure security tooling platforms comply with recipient client or Globals patching policies

Incident & Problem Management

  • Report tooling-related incidents (outages, performance issues, security events) to Global and or Service Recipients immediately

  • Support Third Party vendor cases where Supplier actions affect system availability, integrity, or confidentiality

  • Provide written notice of vulnerability disclosures and critical defects in tooling without undue delay

  • Provide impact assessments and work-around proposals for tooling issues

  • Log all tooling-related incidents and vulnerabilities in the agreed ticketing system

  • Provide monthly reports detailing incident trends, vulnerability status, and remediation progress

Tooling Replacement & Migration

  • Support tooling replacement activities when recipient clients or Global decides to replace existing tools

  • Participate in hypercare activities for Replacement Tooling up to and including implementation date

  • Ensure seamless migration of configurations, data, and integrations to new platforms

  • Retrain on new tooling as required clients

  • Cease use of Replaced Tooling by the specified replacement date

Security Tooling Portfolio Management

Manage and maintain the following categories of security tools:

Security Operations Tools

  • SIEM (Security Information and Event Management) - e.g., Splunk

  • EDR (Endpoint Detection and Response)

  • SOAR (Security Orchestration, Automation and Response)

  • Threat Intelligence Platforms

  • Vulnerability Scanners (e.g., Qualys, Tenable)

  • Brand Protection and Domain Monitoring Tools

  • Certificate Authority (CA) and PKI Management Platforms

Security Architecture & Engineering Tools

  • SAST (Static Application Security Testing) - e.g., Checkmarx, Fortify

  • DAST (Dynamic Application Security Testing) - e.g., Burp Suite, OWASP ZAP

  • SCA (Software Composition Analysis) - e.g., Snyk, Black Duck

  • CSPM (Cloud Security Posture Management) - e.g., Prisma Cloud, Wiz

  • Container Scanning Tools

  • Penetration Testing Tools

Information Security Tools

  • Third Party Risk Management Platforms

  • Case Management Systems for Third Party Security Assessments

Service Support Tools

  • Security Service Desk Ticketing Systems (e.g., Jira, ServiceNow)

  • Reporting and Dashboard Platforms

Exit & Offboarding Support

  • Upon expiry/termination of tooling contracts or at Globals request:

  • Return all configurations, runbooks, and artifacts

  • Ensure orderly transfer of Supplier-created content

  • Support account de-provisioning

  • Return/destroy data per Global/Service Recipient policies

  • Provide detailed handover plans for tooling transition to Global, Service Recipients, or Replacement Suppliers

Requirements

  • Splunk Certified Admin / Splunk Certified Architect

  • Certified Information Systems Security Professional (CISSP)

  • GIAC Security Essentials (GSEC)

  • CompTIA Security+

Certifications (Preferred)

  • Vendor-specific certifications for managed tools (e.g., Qualys, Tenable, Palo Alto Networks)

  • ITIL Foundation or higher

  • Cloud certifications (AWS, Azure, GCP)

  • Automation certifications (Ansible, Terraform)

Experience

  • Minimum 4 years of experience in security operations, security engineering, or IT systems administration

  • Minimum 2 years of hands-on experience with SIEM platforms (preferably Splunk)

  • Proven experience managing security tooling in enterprise environments

  • Experience with integration of security tools with enterprise infrastructure (IAM, CMDB, ticketing)

  • Demonstrated experience with access management and RBAC implementation

  • Experience with vulnerability management and patch management processes

Technical Skills

Security Platforms

  • SIEM: Splunk (required), QRadar, ArcSight, LogRhythm, Sentinel

  • EDR: CrowdStrike, Carbon Black, SentinelOne, Microsoft Defender

  • SOAR: Splunk Phantom, Palo Alto Cortex XSOAR, IBM Resilient

  • Vulnerability Management: Qualys, Tenable, Rapid7

  • Threat Intelligence: Recorded Future, ThreatConnect, MISP

Integration & Automation

  • REST APIs and API integration

  • Scripting: Python, PowerShell, Bash

  • Automation tools: Ansible, Terraform, Jenkins

  • Data formats: JSON, XML, CSV, Syslog, CEF

Infrastructure & Networking

  • Linux and Windows server administration

  • Networking fundamentals (TCP/IP, DNS, firewalls, proxies)

  • Cloud platforms: AWS, Azure, GCP

  • Containerization: Docker, Kubernetes

Identity & Access Management

  • SSO protocols: SAML, OAuth, OpenID Connect

  • MFA solutions: Duo, Okta, Azure MFA

  • LDAP/Active Directory integration

  • RBAC design and implementation

Data & Reporting

  • Log management and parsing

  • Data normalization and enrichment

  • Dashboard and visualization design (Splunk, Grafana, Kibana)

  • Reporting and metrics

Frameworks & Standards

  • Clients Global Security Control Framework

  • ISO 27001, NIST Cybersecurity Framework, CIS Benchmarks

  • ITIL service management practices

  • Change management and configuration management

Soft Skills

  • Strong problem-solving and troubleshooting abilities

  • Excellent attention to detail

  • Effective communication skills (written and verbal)

  • Ability to work collaboratively across teams

  • Customer service orientation

  • Ability to manage multiple priorities and deadlines

  • Proactive and self-motivated

Key Performance Indicators (KPIs)

  • Platform uptime and availability (per SLA targets)

  • Incident response time for tooling issues

  • Monthly health report delivery timeliness and quality

About the company

NTT DATA is one of the world's largest global security services providers, with over 7,500 security SMEs. We work with leading security technology vendors and pride ourselves on delivering innovative and effective solutions. Our people, clients, and communities are at the core of what we do. We're seeking individuals passionate about building a more secure and sustainable world.

Apply for this position