About the Role
The Security Managed Services Engineer (L2) is a developing engineering role, responsible for providing a managed service to clients to ensure that their security infrastructures and systems remain operational. Through proactive monitoring, identifying, investigating, and resolving technical incidents and problems, this role restores service to clients while meeting service level agreements. The primary objective is to review client requests or tickets and apply technical and process knowledge to resolve them without breaching SLAs, focusing on second‑line support for incidents and requests of medium complexity. The role may also support project work as required.
Key Responsibilities
- Minimum 4+ years of experience in Security Operations Center and SIEM (Splunk).
- Minimum 2 years of hands‑on experience with Splunk.
- Configure and maintain the SIEM system, ensuring proper setup for collecting and analyzing security event data; develop, customize, and manage security rules to detect and respond to threats.
- Monitor SIEM alerts, investigate them, and take appropriate actions based on severity; oversee collection, normalization, and storage of log data from various sources.
- Develop and document incident response procedures, lead or assist in incident response efforts, and manage incidents through all response phases to closure.
- Utilize SIEM, SOAR, UEBA, EDR, NBAD, PCAP, vulnerability scanning, and malware analysis technologies for event detection and analysis.
- Update tickets, write incident reports, and document actions to reduce false positives; fine‑tune detective capabilities and develop knowledge of attack types.
- Identify log sources, examine system logs, and reconstruct event histories using forensic techniques.
- Align SIEM rules and alerts with the organization’s security policies and compliance requirements.
- Conduct computer forensic investigations, including examining running processes, identifying network connections, and disk imaging.
- Maintain operational integrity of SOC toolsets and support vendor updates, patches, and support.
- Maintain thorough documentation of SIEM configuration, procedures, and incident response plans.
- Proactively identify and report system security loopholes, infringements, and vulnerabilities to the Security Operations Centre Manager in a timely manner.
- Work closely with other IT and security teams during incident response, coordinating efforts and sharing information.
- Ensure SIEM helps the organization meet regulatory compliance requirements and is ready for security audits.
- Continuously optimize SIEM performance to handle data volume and remain responsive.
- Develop automation scripts and workflows to streamline security response tasks and enhance efficiency.
Knowledge and Attributes
- Ability to communicate and work across different cultures and social groups.
- Ability to plan activities and projects well in advance, taking into account possible changing circumstances.
- Ability to maintain a positive outlook at work.
- Ability to work well in a pressurized environment.
- Willingness to work hard and put in longer hours when necessary.
- Ability to apply active listening techniques such as paraphrasing, probing relevant information, and refraining from interrupting.
- Ability to adapt to changing circumstances.
- Ability to place clients at the forefront of all interactions and create a positive client experience throughout the client journey.
Academic Qualifications and Certifications
- Bachelor’s degree or equivalent qualification in IT/Computing (or demonstrated equivalent work experience).
- Active CEH certification is required.
Required Experience
- Moderate level of relevant managed services experience handling security infrastructure.
- Moderate level of knowledge in ticketing tools, preferably ServiceNow.
- Moderate level of working knowledge of ITIL processes.
- Moderate level of experience working with vendors and/or third parties.
Workplace Type
On‑site Working
Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category.