Your day at NTT DATA
The Security Managed Services Engineer (L2) is a developing engineering role, responsible for providing a managed service to clients to ensure that their Security Infrastructures and systems remain operational.
Through the proactive monitoring, identifying, investigating, and resolving of technical incidents and problems, this role is able to restore service to clients.
Primary objective is to proactively review client requests or tickets and apply technical/process knowledge to resolve them without breaching SLA and focuses on second‑line support for incidents and requests with a medium level of complexity.
The Security Managed Services Engineer (L2) may also contribute to / support on project work as and when required.
Responsibilities
- Monitors client infrastructure and solutions.
- Identifies problems and errors prior to or when they occur.
- Routinely identifies common incidents and opportunities for avoidance as well as general opportunities for incident reduction.
- Investigates first line incidents assigned and identifies the root cause of incidents and problems.
- Provides telephonic or chat support to clients when required.
- Schedules maintenance activity windows for patching and configuration changes.
- Follows required handover procedures for shift changes to ensure service continuity.
- Reports and escalates incidents where necessary.
- Ensures efficient and comprehensive resolutions of incidents and requests.
- Updates existing knowledge articles or creates new ones.
- Identifies opportunities for work optimization including automation and process improvement.
- May also support on project work as and when required.
- May work on implementing and delivering Disaster Recovery functions and tests.
- Performs any other related task as required.
Qualifications
- Academic Qualifications: BE/BTech in Electronics/EC/EE/CS/IT Engineering or MCA.
- At least one security certification such as CCNA Security, CCSA, CEH, CompTIA, GCIH/GCIA.
- At least one SIEM solution certification with one or more SIEM/ Security solutions (RSA NetWitness, Splunk ES, Elastic ELK, HP ArcSight, IBM QRadar Log Rhythm).
- Minimum overall 5 years of experience in handling security related products & services; 3 years in SIEM solution.
- Knowledge of security devices: firewalls, IPS, WAF, DDOS, EDR, Incident response, SOAR.
- Administration of SIEM environment: deployment, user management, license management, upgrades, patch deployment, log source management, configuration, change, report management, backup and recovery.
- Construction of SIEM content: filters, active lists, correlation rules, reports, templates, queries, trends, variables.
- Integration of customized threat intelligence content feeds from Threat Intelligence & Analytics service.
- Identifies sensor improvements, collects/updates threat intelligence feeds, creates situational awareness briefings, coordinates incident analysis, containment, remediation.
- Liaises with Security monitoring team to discover repeatable processes leading to new content development.
- Provides engineering analysis and architectural design of technical solutions.
- Knowledge of networking protocols, technologies and network security.
- Sound analytical and troubleshooting skills.
Workplace Type
On‑site Working
Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category.