Security Engineer

The Nippon Telegraph and Telephone Corporation (NTT)

Birmingham

On-site

GBP 60,000 - 90,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

NTT DATA is seeking a SOC Engineer in the UK to strengthen security operations by deploying and tuning SIEM platforms, developing automated playbooks, and coordinating incident response in a fast-paced environment.

You will collaborate with threat intelligence teams, build detection rules, and contribute to ongoing security enhancements. The role offers exposure to leading SOC tooling and a chance to mentor junior staff.

Qualifications

  • Hands-on experience with SIEM platforms and log sources onboarding.
  • Ability to develop and tune SIEM use cases and rules.

Responsibilities

  • Deploy, configure, and maintain SIEM platforms for threat detection.
  • Design and implement incident response playbooks and automation.
  • Monitor alerts, investigate incidents, and coordinate cross-team response.
  • Perform threat modeling and develop SIEM use cases aligned with risk priorities.
  • Create dashboards and reports to show security posture and trends.
  • Mentor junior analysts and support pre-sales demonstrations.

Skills

SIEM platforms experience
Threat detection techniques
Incident response
Scripting automation
ITIL processes

Education

CISSP
GIAC
SC-200
Splunk Power User/Admin
QRadar Specialist
Chronicle Security Engineer

Tools

Splunk
QRadar
Sentinel
Microsoft Defender
Chronicle
KQL
SPL
AQL
Python
PowerShell

Job description

What you'll be doing:

Join NTT DATA as a SOC Engineer and play a pivotal role in defending clients against evolving cyber threats. You will leverage your expertise in SIEM platforms, threat detection, and incident response to strengthen security operations center (SOC) capabilities. Collaborating with cross-functional teams, you'll develop automated playbooks, engineering use cases, and deploying advanced detection systems to ensure robust protection in a fast-paced, real-time environment.

Core Responsibilities
SIEM Engineering & Analytics
  • Deploy, configure, and maintain SIEM platforms such as Splunk, QRadar, Sentinel, and Chronicle to enable robust threat detection.
  • Normalize and onboard diverse log sources from cloud and on-premises environments for seamless monitoring.
  • Develop and continually refine SIEM rules and queries for use cases involving advanced threat behaviours and anomaly detection.
Playbook Automation & Incident Response
  • Design and implement incident response playbooks for threats such as phishing, lateral movement, malware infections, and more.
  • Integrate response automation into SOAR platforms (e.g., XSOAR, Azure Logic Apps), reducing response times and manual overhead.
  • Use feedback from simulated incidents and threat intelligence to refine existing playbooks and workflows.
Threat Detection & Response
  • Monitor security alerts for potential threats, investigate incidents, and coordinate cross-team response activities.
  • Collaborate with threat intelligence teams to enhance detection logic and fine-tune resolution processes.
  • Perform root-cause analysis (RCA) of recurring incidents and help define corrective actions to reduce future risks.
Threat Modelling & Use Case Development
  • Perform threat modeling using industry frameworks such as MITRE ATT&CK, STRIDE, or the Cyber Kill Chain.
  • Design actionable SIEM use cases, detection rules, and workflows aligned with risk prioritization.
  • Evaluate use-case effectiveness through continual testing and KPIs, prioritizing iteration based on business relevance.
Reporting & Documentation
  • Develop dashboards and metrics-driven reports to showcase security posture and incident trends for leadership.
  • Maintain detailed documentation of incident procedures, runbooks, playbooks, and analysis reports for audit or team use.
  • Support monthly managerial reporting packs to present SOC effectiveness metrics (e.g., incident response times, detection improvements).
Training, Mentorship, & Pre-Sales Support
  • Provide mentorship to junior SOC analysts, transferring technical expertise on threat detection and response best practices.
  • Assist pre-sales teams by demonstrating SOC tools to prospective clients and refining operational delivery proposals.
  • Scope, deploy, and operationalize new SOC solutions, benchmarking against industry and client expectations.
What experience you'll bring:
Required Qualifications
Technical Skills
  • Proven hands‑on experience with SIEM platforms such as Splunk, QRadar, Sentinel, Microsoft Defender, or Chronicle.
  • Expertise with SIEM query languages (e.g., KQL, SPL, AQL) and strong knowledge of log normalization and parsing.
  • Proficiency in scripting (e.g., Python, PowerShell) to automate tasks and build SOC efficiencies.
  • Deep familiarity with cyber threat detection techniques related to frameworks like MITRE ATT&CK and vulnerability management.
  • Experience managing ITIL processes, including Incident, Problem, and Change Management.
Certifications Required
  • CISSP, GIAC, SC-200, Splunk Power User/Admin, QRadar Specialist, or Chronicle Security Engineer certifications preferred.
  • Candidates must be eligible to obtain UK SC clearance.
Professional Skills
  • Strong analytical and communication skills to present complex information to technical and non-technical stakeholders.
  • Experienced in collaborative team dynamics and independent problem-solving.
  • Proven ability to transfer knowledge and mentor junior SOC team members effectively.
Who we are:

At NTT DATA, you have endless opportunities to think big, act bold and take ownership. As a $30+ billion business and technology services, AI and digital infrastructure leader, we co-innovate solutions with clients and partners globally for business and societal impact. Serving 75% of the Fortune Global 100, with experts in over 70 countries, we encourage experimentation and recognize great work. Proudly a Global Top Employer, NTT DATA is part of NTT Group, which invests over $3 billion annually in R&D. Make this the place where you belong, learn, and build your network. Make this the place where you grow.

what we’ll offer you:

We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.

You can find more information about NTT DATA UK & Ireland here: https://uk.nttdata.com/

We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a proud Disability Confident Committed Employer - we are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Analyst Level 1
SOC Analyst Level 1

The Nippon Telegraph and Telephone Corporation (NTT) • Birmingham

On-site
GBP 27,000 - 36,000
Learning and development opportunities
Flexible work options
SOC Analyst Level 1
SOC Analyst Level 1

NTT DATA • Birmingham

On-site
GBP 28,000 - 38,000
SOC Analyst Level 1
SOC Analyst Level 1

NTT DATA UK Ltd. • Birmingham

On-site
GBP 40,000 - 56,000
Flexible work options
Learning & Development opportunities
Disability Confident Employer
Senior Security Architect Consultant
Senior Security Architect Consultant

The Nippon Telegraph and Telephone Corporation (NTT) • City Of London

On-site
GBP 90,000 - 120,000
Security Engineer – Endpoint & Data Protection
Security Engineer – Endpoint & Data Protection

NTT America, Inc. • Greater London

Hybrid
GBP 65,000 - 95,000
Senior Security Consultant - Public Sector
Senior Security Consultant - Public Sector

NTT America, Inc. • Greater London

Hybrid
GBP 70,000 - 110,000
Senior Enterprise Security Architect - Telecoms Design
Senior Enterprise Security Architect - Telecoms Design

The Nippon Telegraph and Telephone Corporation (NTT) • City Of London

On-site
GBP 75,000 - 110,000
Business Information Security officer (BISO)
Business Information Security officer (BISO)

The Nippon Telegraph and Telephone Corporation (NTT) • City Of London

On-site
GBP 90,000 - 130,000
Senior AI Security Architect Consultant
Senior AI Security Architect Consultant

The Nippon Telegraph and Telephone Corporation (NTT) • City Of London

Hybrid
GBP 120,000 - 180,000
Flexible work options
Learning & development programs
Diversity & inclusion commitment
Chief Information Security Officer
Chief Information Security Officer

The Nippon Telegraph and Telephone Corporation (NTT) • City Of London

On-site
GBP 150,000 - 190,000
Flexible work options
Learning and development opportunities
Inclusive, diverse workforce