Nttlimited

Senior Analyst: Information Security Incident Response

Sydney AustraliaFull timeSeniorPosted about 1 month ago
Apply on Nttlimited →Sign in to save this role

Sign in to see who you know at Nttlimited.

Make an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.We are seeking an experienced Senior Cloud Security Incident Response Analyst to support and enhance security across AWS and Azure environments.This is a senior hands-on role focused on cloud security engineering, incident response, SIEM operations, DevSecOps integration, security automation, and continuous security improvement. You will work across cloud security platforms, cloud-native security controls, security monitoring, and modern workload protection while mentoring L1 and L2 team members.Key ResponsibilitiesImplement and manage Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP/CWP) solutions.Secure and support AWS and Azure cloud environments.Configure and maintain compliance, workload protection, vulnerability management, and cloud security monitoring capabilities.Perform L3 troubleshooting and root cause analysis.Lead cloud security incident response and investigations.Implement and review cloud security controls including identity and access management, network security, logging, and monitoring.Support SIEM platforms including Splunk, Microsoft Sentinel, and Palo Alto Cortex XSIAM.Develop and maintain detection rules, correlation searches, analytics content, dashboards, and alerting capabilities.Onboard and integrate log sources across cloud, endpoint, network, identity, and application environments.Support threat hunting, security monitoring, and incident investigations.Integrate security into CI/CD pipelines and Infrastructure-as-Code deployments.Secure Kubernetes, Docker, and other modern cloud workloads.Develop automation using Python, PowerShell, and APIs.Support governance, compliance, and audit activities.Mentor junior team members and maintain operational documentation and runbooks.Engage with stakeholders to support security improvement initiatives.Skills & ExperienceRequired7-10 years of experience in IT, Cyber Security, or related disciplines.Minimum 3 years' experience in Cloud Security Engineering.Strong hands-on experience with AWS and Azure security.Experience with CSPM and CWPP/CWP platforms.Experience with Terraform, CloudFormation, or Infrastructure-as-Code security.Experience with DevSecOps and CI/CD security practices.Experience securing Kubernetes and containerised environments.Strong understanding of cloud architecture, IAM, cloud networking, segmentation, and vulnerability management.Experience with incident response and cloud threat detection.Scripting and automation experience using Python and/or PowerShell.Highly DesirableExperience with Splunk Enterprise Security, Microsoft Sentinel, or Palo Alto Cortex XSIAM.Experience in SIEM administration, security monitori...

Read the full posting on Nttlimited →