Security Consultant

NTT DATA

Kuala Selangor

On-site

MYR 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

NTT DATA seeks a Security Consultant to lead cyber resilience and security advisory workstreams. You will shape assessments, recover design, and MVC engagements for regulated clients, while guiding security architecture and policy implementation across infrastructure programs.

You will drive threat and vulnerability assessments, create recovery plans, and present findings to executive audiences, leveraging blueprints like NIST CSF and ISO/IEC 27001.

Qualifications

  • Bachelor’s degree or diploma in IT, CS, Engineering, or related field.
  • Industry certs such as CISSP, CISM, CISA are essential.
  • Certifications like CRISC, SABSA, ISO/IEC 27001 Lead Auditor/Lead Implementer, CCSP are advantageous.

Responsibilities

  • Lead security and resilience assessments using frameworks (NIST CSF, CIS Controls, ISO/IEC 27001).
  • Define MVC scope, recovery priorities, and dependencies for clients.
  • Develop proposals and SOWs with clear methodology, deliverables, and acceptance criteria.
  • Present findings and recommendations to CISO-level and board audiences.
  • Conduct threat and vulnerability assessments and determine policy deviations.
  • Design cyber recovery architectures including isolated environments and vaulting.
  • Develop BIA, BCP, DRP, and CIRP/CRP documents and tabletop exercise playbooks.
  • Advise on security architecture within infra programs and network segmentation.

Skills

Verbal communication
Written communication
Requirements gathering
Proposal development
Stakeholder interviews
Security architecture
Cyber resilience
Threat assessment
Business continuity planning
Incident response

Education

Bachelor’s degree in IT/CS/Engineering
CISSP
CISM
CISA
CRISC
SABSA
ISO/IEC 27001 Lead Auditor/Lead Implementer
CCSP
PCNSE, Fortinet NSE 4+
CBCP or ISO 22301

Job description

Continue to make an impact with a company that is pushing the boundaries of what is possible. At NTT DATA, we are renowned for our technical excellence, leading innovations, and making a difference for our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can continue to grow, belong, and thrive.

Your career here is about believing in yourself and seizing new opportunities and challenges. It’s about expanding your skills and expertise in your current role and preparing yourself for future advancements. That’s why we encourage you to take every opportunity to further your career within our great global team.

The Security Consultant leads the practice’s cyber resilience and security advisory portfolio. The role shapes and delivers security assessments, cyber recovery and minimum viable company (MVC) advisory engagements, and security architecture workstreams within broader infrastructure programs, helping regulated clients withstand, respond to, and recover from destructive cyber events.

1.2. Key responsibilities
  • Works on strategic engagements that ensure the efficient and effective reaction to security breaches to mitigate immediate and potential threats.
  • Uses mitigation, preparedness, response, and recovery approaches to minimize business disruptions and commercial consequences.
  • Shapes and scopes security advisory opportunities, including cyber resilience assessments, minimum viable company definition, cyber recovery design, and security posture assessments.
  • Develops proposals and statements of work with clearly defined methodology stages, deliverables, stakeholder models, and acceptance criteria.
  • Leads security and resilience assessments using recognized frameworks (NIST CSF, CIS Controls, ISO/IEC 27001) and regulatory baselines (BNM RMiT, MAS TRM, NACSA/NCII requirements, PDPA).
  • Conducts regular threat and vulnerability assessments and determines deviations from acceptable configurations or policies.
  • Participates in the assessment of the level of risk and supports the development of appropriate mitigation countermeasures in operational and non-operational situations.
  • Defines minimum viable company scope for clients by identifying critical business services, mapping supporting applications and infrastructure, and establishing recovery priorities and dependencies.
  • Designs cyber recovery architectures, including isolated recovery environments, cleanroom recovery, immutable vaulting, and recovery validation processes.
  • Leads data protection and resilience assessments (ransomware recovery readiness) and supports the design and build of disaster recovery sites and cyber resilience third sites.
  • Develops business impact analyses (BIA), business continuity plans (BCP), disaster recovery plans (DRP), and cyber incident recovery plans (CIRP/CRP).
  • Develops incident response and recovery playbooks and designs and facilitates tabletop exercises with client executive and technical teams.
  • Participates in the implementation of policies, processes, and guidelines to ensure the standardization of security management throughout client organizations.
  • Advises on security architecture within infrastructure programs, including network segmentation and micro segmentation, identity and privileged access management, endpoint and workload protection, and security monitoring integration.
  • Presents security findings and recommendations to CISO-level and board-level audiences.
1.3. To thrive in this role, you need to have
  • Excellent verbal and written communication skills are a must, including confident presentation to IT management and C-level audiences
  • Proven ability to gather business requirements and translate them into technical requirements
  • Proven ability to translate technical requirements into a compelling solution proposal
  • A solution-centric rather than product-centric mindset, recommending the approach that best meets the client’s requirements
  • Strong document authoring capability, covering assessment reports, proposal documents, requirements documents, and solution specifications
  • Proven ability to conduct workshops and stakeholder interviews, gather and structure information, and produce assessment reports and findings from raw data such as logs, configurations, and inventory
  • Strong understanding of information technology and information security
  • Solid understanding of security risks and preventative controls
  • Excellent understanding of security operational processes and controls
  • Good knowledge of security frameworks and standards such as NIST, ISO/IEC 27001, and CIS
  • Good ability to assess and manage cybersecurity risks at both organisational and project levels
  • Strong understanding of cyber resilience and recovery concepts, including business impact analysis, recovery objectives, immutability, air-gapped vaulting, and clean recovery
  • Service consulting aptitude, focusing on the business, service, and sales aspects
  • Ability to translate technical risk into business language and defensible recommendations
  • Up-to-date knowledge of security threats, countermeasures, security tools, and network technologies
  • High level of drive and the ability to work under pressure
  • Ability to build and maintain cross-functional relationships with a variety of stakeholders
  • Understanding of relevant laws, regulations, and compliance frameworks affecting regulated industries in ASEAN, including BNM RMiT, MAS TRM, and PDPA
1.4. Academic qualifications and certifications
  • Bachelor’s degree or diploma, or equivalent, in Information Technology, Computer Science, Engineering, or a related field.
  • Industry relevant certifications such as CISSP, CISM, or CISA essential.
  • CRISC, SABSA, ISO/IEC 27001 Lead Auditor/Lead Implementer, CCSP, vendor certifications (Palo Alto Networks PCNSE, Fortinet NSE 4+), and business continuity certifications (CBCP, ISO 22301) advantageous.
The following experience is advantageous rather than mandatory:
  • Demonstrable experience in the information security industry, with substantial experience in security consulting or advisory roles, ideally serving financial services or other regulated industries.
  • Experience with security architecture design principles.
  • Experience with industry compliance and standards such as ISO/IEC 27001, NIST, BNM RMiT, MAS TRM, and PDPA, including support for audit or regulator interactions.
  • Experience leading security maturity or gap assessments and presenting findings to senior stakeholders.
    Equal Opportunity Employer

    NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Consultant
Security Consultant

NTT DATA, Inc. • Petaling Jaya

On-site
MYR 120,000 - 180,000
Security Consultant
Security Consultant

NTT Limited • Petaling Jaya

On-site
MYR 150,000 - 230,000
Principal Consultant-Cybersecurity
Principal Consultant-Cybersecurity

NTT MSC Sdn Bhd • Selangor

Hybrid
MYR 180,000 - 300,000
Hybrid Working
Principal Consultant-Cybersecurity
Principal Consultant-Cybersecurity

NTT Limited • Petaling Jaya

Hybrid
MYR 180,000 - 280,000
Information Security Governance, Risk and Compliance Specialist
Information Security Governance, Risk and Compliance Specialist

NTT DATA Asia Pacific • Cyberjaya

On-site
MYR 90,000 - 130,000
Junior Security Solutions Consultant
Junior Security Solutions Consultant

UniQ Consulting & Services Sdn Bhd • Petaling Jaya

On-site
MYR 60,000 - 120,000
Cyber Resilience & Security Advisory Lead
Cyber Resilience & Security Advisory Lead

NTT Ltd. • Petaling Jaya

On-site
MYR 180,000 - 320,000
Intern, Technology & Cyber Risk
Intern, Technology & Cyber Risk

NTT DATA eCommerce Solutions Sdn. Bhd. • Kuala Lumpur

On-site
MYR 22,000 - 45,000
IT Infrastructure Security Specilaist
IT Infrastructure Security Specilaist

NTT DATA, Inc. • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Security & Resilience Advisory Lead
Security & Resilience Advisory Lead

NTT Limited • Petaling Jaya

On-site
MYR 150,000 - 230,000