Cyber Defense & Incident Responder
Role details
Job location
Tech stack
Job description
The Cyber Defense & Incident Responder is responsible for monitoring, analyzing, and responding to assigned cybersecurity incidents in accordance with established procedures. This role focuses on incident triage, investigation, containment, and recovery to minimize impact and restore normal operations. Analysts leverage security tools, event logs, correlation data, and threat intelligence to determine the nature and scope of incidents, document findings, and recommend remediation steps., 1. Monitor enterprise security systems and analyze alerts to identify potential cybersecurity incidents.
- Review SIEM, IDS/IPS, EDR, and other related tool alerts for anomalous activity and indicators of compromise/attacks (IOCs/IOAs).
- Validate alerts to reduce false positives and prioritize based on severity and potential impact.
- Perform initial triage and analysis of security events to determine scope, severity, and urgency.
- Examine log data, network telemetry, and endpoint information to identify possible malicious activity.
- Correlate event details with internal and external threat intelligence.
- Execute incident response actions in accordance with established procedures.
- Contain affected systems, remove malicious artifacts, and assist in system recovery.
- Escalate complex or critical incidents to Senior SOC Analysts or SOC Leads.
- Document and communicate incident findings to support resolution and improvement efforts.
- Prepare incident tickets, timelines, and investigative notes.
- Contribute to after-action reviews (AARs) and post-incident reporting.
- Create incident tickets
- Upload supporting evidence, draw sound conclusions and upload artifacts
- Communicate effectively, providing clear, accurate, and concise information
- Exercise sound analytical skills to derive correct conclusions associated with incident investigations.
- Maintain SOC processes, tools, and playbooks to ensure effective incident handling.
- Recommend refinements to SOPs and escalation procedures.
- Identify opportunities to streamline analysis workflows and improve detection capabilities.
- Participate in training, exercises, and knowledge-sharing to strengthen response readiness.
- Support red, blue, or purple team exercises when directed.
- Share lessons learned and best practices with SOC team members.
- Stay informed on current and emerging cyber threats relevant to the organization's environment.
- Track evolving tactics, techniques, and procedures (TTPs) of threat actors.
- Incorporate relevant intelligence into incident analysis and response.
Requirements
- Bachelor's degree in information technology, cybersecurity, data science, information systems, or computer science.
- Education Equivalency: One-and-one- half (1.5) years of additional experience can substitute for one (1) year of a typical degree program.
- Minimum 6 years experience in Information Technology (IT) and/or Information Security (IS).
- DoD 8140 certification for respective area or the ability to obtain certification within six (6) months of onboarding.
- Active Secret or higher security clearance holder and must be eligible for a Top-Secret clearance if requested., * DCWF Role 511 - Cyber Defense Analyst / 531 - Cyber Defense Incident Responder advanced & intermediate certifications:
- Cisco: CBROPS
- CompTIA: CySA+, Cloud+, PenTest+, Security+
Benefits & conditions
NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this role is $101,376 - $152,064. Actual compensation will depend on a number of factors, including the candidate's relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance. If the position offered in temporary, the position will not be eligible for incentive compensation. This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits.