Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
NTT DATA is seeking an IT Security Officer to support a customer’s information security program across hybrid on-prem and AWS environments. You will drive vulnerability management, manage the risk register, and oversee day-to-day security operations including signature updates and vendor vulnerability notices.
You will coordinate with SMEs and stakeholders to assess risks using CVSS, track remediation, and deliver risk-based recommendations for prioritization.
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.
The IT Security Officer will support the customer's information security program across a hybrid infrastructure consisting of on-premises systems and AWS cloud services. This role is responsible for driving the vulnerability management lifecycle, maintaining the organizational Risk Register, coordinating risk acceptance and remediation activities with stakeholders, and overseeing day‑to‑day security operations related to signature updates and vendor vulnerability notifications.
Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)
Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership
Follow up with Subject Matter Experts (SMEs) on outstanding vulnerability findings to ensure timely remediation or documented exceptions
Track remediation status and elevate overdue items per defined SLAs
Own and maintain the organization's Risk Register, ensuring it reflects current, accurate risk data
Draft Risk Acceptance forms for identified risks that cannot be immediately remediated
Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign‑off on risk acceptances
Periodically review accepted risks for continued validity and reassessment
Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment
Review vendor security bulletins and vulnerability notifications to determine applicability to the customer's environment
Ensure timely triage and action on vendor‑disclosed vulnerabilities affecting in‑scope systems
Perform impact analysis on identified vulnerabilities using CVSS (Common Vulnerability Scoring System) scores
Contextualize CVSS base scores against the actual environment (asset criticality, exposure, compensating controls) to determine real‑world risk and prioritization
Provide risk‑based recommendations to stakeholders to support remediation prioritization decisions
Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review
Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding
Execute and manage regular vulnerability scans across on-premises infrastructure and AWS services (EC2, S3, RDS, and other relevant services)
Generate, review, and distribute vulnerability scan reports to relevant technical teams and leadership
Follow up with Subject Matter Experts (SMEs) on outstanding vulnerability findings to ensure timely remediation or documented exceptions
Track remediation status and elevate overdue items per defined SLAs
Own and maintain the organization's Risk Register, ensuring it reflects current, accurate risk data
Draft Risk Acceptance forms for identified risks that cannot be immediately remediated
Coordinate with business and technical stakeholders to review, negotiate, and obtain formal approval/sign‑off on risk acceptances
Periodically review accepted risks for continued validity and reassessment
Monitor and verify that security signature updates (AV/EDR, IDS/IPS, etc.) are applied consistently across the environment
Review vendor security bulletins and vulnerability notifications to determine applicability to the customer's environment
Ensure timely triage and action on vendor‑disclosed vulnerabilities affecting in‑scope systems
Perform impact analysis on identified vulnerabilities using CVSS (Common Vulnerability Scoring System) scores
Contextualize CVSS base scores against the actual environment (asset criticality, exposure, compensating controls) to determine real‑world risk and prioritization
Provide risk‑based recommendations to stakeholders to support remediation prioritization decisions
Prepare periodic status reports/dashboards on vulnerability management, risk register status, and outstanding risk acceptances for leadership review
Communicate effectively with technical SMEs, business stakeholders, and management across varying levels of technical understanding
Bachelor's degree in information security, Computer Science, or related field (or equivalent work experience)
3–5+ years of experience in IT security operations, vulnerability management, or risk management
Hands‑on experience with vulnerability scanning tools (e.g., Tenable/Nessus, Qualys, Rapid7)
Working knowledge of AWS security services and shared responsibility model (e.g., Security Hub, GuardDuty, Inspector, IAM)
Solid understanding of on‑premises infrastructure security (servers, network devices, endpoints)
Strong understanding of CVSS scoring methodology and practical risk‑based prioritization
Experience developing and managing Risk Registers and Risk Acceptance documentation
Excellent stakeholder management and communication skills, with ability to work cross‑functionally
Relevant certifications: Security+, CySA+, CISSP, CRISC, AWS Security Specialty, or similar
Experience with GRC tools (e.g., ServiceNow GRC, Archer)
Familiarity with frameworks such as NIST 800‑53, NIST CSF, or ISO 27001
Experience working in a hybrid on-prem/cloud environment supporting external customers
Strong analytical and problem‑solving skills
Detail‑oriented with strong documentation habits
Ability to influence and drive accountability without direct authority
Comfortable working with ambiguity and competing priorities
This is a 1 year fixed term contract role. Candidates must be open to work from client site
NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune
Global 100. We are committed to accelerating client success and positively impacting society through
responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with
unmatched capabilities in enterprise‑scale AI, cloud, security, connectivity, data centers and
application services. Our consulting and industry solutions help organizations and society move
confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more
than 70 countries. We also offer clients access to a robust ecosystem of innovation centers as well as
established and start‑up partners. NTT DATA is part of NTT Group, which invests over $3 billion each
year in R&D.
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us.