Senior Analyst: Information Security Incident Response

NTT Ltd.

Sydney

On-site

AUD 150,000 - 190,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

NTT DATA in Sydney, Australia, seeks an experienced Senior Cloud Security Incident Response Analyst to strengthen security across AWS and Azure environments. This hands-on role focuses on cloud security engineering, incident response, SIEM operations, and DevSecOps integration.

You will mentor L1/L2 staff, develop detection rules, integrate security into CI/CD, and ensure continuous security improvements across modern workloads.

Qualifications

  • Bachelor's degree in Information Technology, Cyber Security, Engineering, or equivalent experience.

Responsibilities

  • Implement and manage Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP/CWP) solutions.
  • Secure and support AWS and Azure cloud environments.
  • Configure and maintain compliance, workload protection, vulnerability management, and cloud security monitoring capabilities.
  • Perform L3 troubleshooting and root cause analysis.
  • Lead cloud security incident response and investigations.
  • Implement and review cloud security controls including identity and access management, network security, logging, and monitoring.
  • Support SIEM platforms including Splunk, Microsoft Sentinel, and Palo Alto Cortex XSIAM.
  • Develop and maintain detection rules, correlation searches, analytics content, dashboards, and alerting capabilities.
  • Onboard and integrate log sources across cloud, endpoint, network, identity, and application environments.
  • Support threat hunting, security monitoring, and incident investigations.
  • Integrate security into CI/CD pipelines and Infrastructure-as-Code deployments.
  • Secure Kubernetes, Docker, and other modern cloud workloads.
  • Develop automation using Python, PowerShell, and APIs.
  • Support governance, compliance, and audit activities.
  • Mentor junior team members and maintain operational documentation and runbooks.
  • Engage with stakeholders to support security improvement initiatives.

Skills

Cloud Security
AWS Security
Azure Security
CSPM/CWPP
IaC Security
DevSecOps
Kubernetes Security
Python/PowerShell
Threat Detection
SIEM

Education

Bachelor's degree in Info Tech / Cyber Security

Tools

Terraform
CloudFormation
Splunk
Microsoft Sentinel
Palo Alto Cortex XSIAM
Qualys/Tenable

Job description

Make an impact with NTT DATA
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.

We are seeking an experienced Senior Cloud Security Incident Response Analyst to support and enhance security across AWS and Azure environments.

This is a senior hands-on role focused on cloud security engineering, incident response, SIEM operations, DevSecOps integration, security automation, and continuous security improvement. You will work across cloud security platforms, cloud-native security controls, security monitoring, and modern workload protection while mentoring L1 and L2 team members.

Key Responsibilities
  • Implement and manage Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP/CWP) solutions.
  • Secure and support AWS and Azure cloud environments.
  • Configure and maintain compliance, workload protection, vulnerability management, and cloud security monitoring capabilities.
  • Perform L3 troubleshooting and root cause analysis.
  • Lead cloud security incident response and investigations.
  • Implement and review cloud security controls including identity and access management, network security, logging, and monitoring.
  • Support SIEM platforms including Splunk, Microsoft Sentinel, and Palo Alto Cortex XSIAM.
  • Develop and maintain detection rules, correlation searches, analytics content, dashboards, and alerting capabilities.
  • Onboard and integrate log sources across cloud, endpoint, network, identity, and application environments.
  • Support threat hunting, security monitoring, and incident investigations.
  • Integrate security into CI/CD pipelines and Infrastructure-as-Code deployments.
  • Secure Kubernetes, Docker, and other modern cloud workloads.
  • Develop automation using Python, PowerShell, and APIs.
  • Support governance, compliance, and audit activities.
  • Mentor junior team members and maintain operational documentation and runbooks.
  • Engage with stakeholders to support security improvement initiatives.
Skills & Experience

Required

  • 7-10 years of experience in IT, Cyber Security, or related disciplines.
  • Minimum 3 years’ experience in Cloud Security Engineering.
  • Strong hands-on experience with AWS and Azure security.
  • Experience with CSPM and CWPP/CWP platforms.
  • Experience with Terraform, CloudFormation, or Infrastructure-as-Code security.
  • Experience with DevSecOps and CI/CD security practices.
  • Experience securing Kubernetes and containerised environments.
  • Strong understanding of cloud architecture, IAM, cloud networking, segmentation, and vulnerability management.
  • Experience with incident response and cloud threat detection.
  • Scripting and automation experience using Python and/or PowerShell.

Highly Desirable

  • Experience with Splunk Enterprise Security, Microsoft Sentinel, or Palo Alto Cortex XSIAM.
  • Experience in SIEM administration, security monitoring, detection engineering, and alert tuning.
  • Experience onboarding and troubleshooting log ingestion pipelines.
  • Familiarity with SPL, KQL, XQL, or similar query languages.
  • Experience with SOC operations, threat hunting, and incident investigation.
  • Experience with Qualys, Tenable, Rapid7, or similar vulnerability management tools.
  • Experience in Managed Security Services or Cloud Security Operations environments.
Qualifications
  • Bachelor’s degree in Information Technology, Cyber Security, Engineering, or equivalent experience.
Preferred Certifications
  • AWS Security Specialty
  • Microsoft Azure Security Engineer
  • CISSP or CCSP
  • Kubernetes or DevSecOps certifications
  • Splunk certifications
  • Microsoft SC-200
  • Palo Alto Cortex XSIAM certifications

Workplace type:

About NTT DATA

NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune

Global 100. We are committed to accelerating client success and positively impacting society through

responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with

unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and

application services. Our consulting and industry solutions help organizations and society move

confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more

than 70 countries. We also offer clients access to a robust ecosystem of innovation centers as well as

established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each

year in R&D.

Equal Opportunity Employer

NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us.

Third parties fraudulently posing as NTT DATA recruiters

NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters whether in writing or by phone in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @nttdata.com email address. If you suspect any fraudulent activity, please contact us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Analyst: Information Security Incident Response
Senior Analyst: Information Security Incident Response

NTT DATA, Inc. • Council of the City of Sydney

On-site
AUD 140,000 - 190,000
Senior Analyst: Information Security Incident Response
Senior Analyst: Information Security Incident Response

NTT DATA, Inc. • City of Melbourne

On-site
AUD 180,000 - 230,000
Senior Analyst: Information Security Incident Response
Senior Analyst: Information Security Incident Response

NTT Limited • Sydney

On-site
AUD 170,000 - 210,000
Principle Analyst Cybersecurity Incident
Principle Analyst Cybersecurity Incident

NTT DATA, Inc. • City of Melbourne

On-site
AUD 100,000 - 130,000
Security Operations Lead
Security Operations Lead

NTT America, Inc. • Canberra

Hybrid
AUD 180,000 - 240,000
Flexible and hybrid working
Leave options to contribute to the社区
Parental leave policy
+2
Cyber Security Sales Specialist
Cyber Security Sales Specialist

NTT DATA, Inc. • City of Melbourne

On-site
AUD 120,000 - 180,000
Senior Cloud Security & Incident Response Engineer
Senior Cloud Security & Incident Response Engineer

NTT Limited • Sydney

On-site
AUD 170,000 - 210,000
Platform Engineer - NOC Level 2
Platform Engineer - NOC Level 2

NTT America, Inc. • Canberra

On-site
AUD 110,000 - 150,000
Senior Cloud Security & Incident Response Engineer
Senior Cloud Security & Incident Response Engineer

NTT DATA, Inc. • City of Melbourne

On-site
AUD 180,000 - 230,000
Senior Cloud Security Incident Response Engineer
Senior Cloud Security Incident Response Engineer

NTT DATA, Inc. • Council of the City of Sydney

On-site
AUD 140,000 - 190,000