Cyber Defense & Incident Responder

NTT DATA, Inc.

Merrifield (VA)

On-site

USD 101,000 - 152,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
401(k) with company match
Paid time off
Employee assistance
Life and AD&D insurance
Short/long term disability

Job summary

NTT DATA, Inc. in Merrifield, Virginia is seeking a Cyber Defense & Incident Responder to monitor, analyze, and respond to cybersecurity incidents. You will triage, investigate, contain, and recover while leveraging SIEM/EDR tools and threat intelligence to minimize impact.

The role requires 6+ years IT/IS experience, DoD 8140 certification (or ability to obtain within 6 months), and interim Secret clearance with Top-Secret eligibility. Competitive pay and comprehensive benefits offered.

Qualifications

  • Bachelor's degree in information technology, cybersecurity, data science, information systems, or computer science.
  • Education Equivalency: 1.5 years of additional experience can substitute for one year of a typical degree program.
  • Minimum 6 years of experience in IT and/or IS.
  • DoD 8140 certification or ability to obtain within six months of onboarding.
  • Ability to obtain a interim Secret Security Clearance and be eligible for a Top-Secret clearance if requested.

Responsibilities

  • Monitor enterprise security systems and analyze alerts to identify potential cybersecurity incidents.
  • Review SIEM, IDS/IPS, EDR, and related tool alerts for IOAs/IOCs.
  • Validate alerts to reduce false positives and prioritize by severity and impact.
  • Perform initial triage and analysis of security events to determine scope and urgency.
  • Examine logs, network telemetry, and endpoints to identify malicious activity.
  • Correlate event details with internal and external threat intel.
  • Execute incident response actions per procedures.
  • Contain affected systems and assist in recovery.
  • Escalate complex incidents to Senior SOC Analysts or SOC Leads.
  • Document incident findings and support resolution and improvements.
  • Prepare incident tickets, timelines, and investigative notes.
  • Contribute to AARs and post-incident reporting.
  • Create incident tickets and upload evidence artifacts.
  • Communicate clearly and concisely about findings.
  • Maintain SOC processes, tools, and playbooks for effective handling.
  • Recommend SOP refinements and escalation improvements.
  • Identify opportunities to streamline analysis workflows and improve detection.
  • Participate in training, exercises, and knowledge-sharing for readiness.
  • Support red/blue/purple team exercises when directed.
  • Share lessons learned with SOC team members.
  • Stay informed on current threats and TTPs relevant to the environment.

Education

Bachelor's degree in information technology, cybersecurity, data science, information systems, or computer science
Education Equivalency: 1.5 years of additional experience can substitute for one year of a typical degree program

Tools

SIEM
IDS/IPS
EDR

Job description

We are currently seeking a Cyber Defense & Incident Responder to join our team in Merrifield, Virginia (US-VA), United States (US).


Job Summary:

The Cyber Defense & Incident Responder is responsible for monitoring, analyzing, and responding to assigned cybersecurity incidents in accordance with established procedures. This role focuses on incident triage, investigation, containment, and recovery to minimize impact and restore normal operations. Analysts leverage security tools, event logs, correlation data, and threat intelligence to determine the nature and scope of incidents, document findings, and recommend remediation steps.


Job Duties:


  • Monitor enterprise security systems and analyze alerts to identify potential cybersecurity incidents.

    • Review SIEM, IDS/IPS, EDR, and other related tool alerts for anomalous activity and indicators of compromise/attacks (IOCs/IOAs).

    • Validate alerts to reduce false positives and prioritize based on severity and potential impact.



  • Perform initial triage and analysis of security events to determine scope, severity, and urgency.

    • Examine log data, network telemetry, and endpoint information to identify possible malicious activity.

    • Correlate event details with internal and external threat intelligence.



  • Execute incident response actions in accordance with established procedures.

    • Contain affected systems, remove malicious artifacts, and assist in system recovery.

    • Escalate complex or critical incidents to Senior SOC Analysts or SOC Leads.



  • Document and communicate incident findings to support resolution and improvement efforts.

    • Prepare incident tickets, timelines, and investigative notes.

    • Contribute to after-action reviews (AARs) and post-incident reporting.

    • Create incident tickets

    • Upload supporting evidence, draw sound conclusions and upload artifacts

    • Communicate effectively, providing clear, accurate, and concise information

    • Exercise sound analytical skills to derive correct conclusions associated with incident investigations.



  • Maintain SOC processes, tools, and playbooks to ensure effective incident handling.

    • Recommend refinements to SOPs and escalation procedures.

    • Identify opportunities to streamline analysis workflows and improve detection capabilities.



  • Participate in training, exercises, and knowledge-sharing to strengthen response readiness.

    • Support red, blue, or purple team exercises when directed.

    • Share lessons learned and best practices with SOC team members.



  • Stay informed on current and emerging cyber threats relevant to the organization’s environment.

    • Track evolving tactics, techniques, and procedures (TTPs) of threat actors.

    • Incorporate relevant intelligence into incident analysis and response.




Basic Qualifications:


  • Bachelor's degree in information technology, cybersecurity, data science, information systems, or computer science.

    • Education Equivalency: One-and-one- half (1.5) years of additional experience can substitute for one (1) year of a typical degree program.



  • Minimum 6 years of experience in Information Technology (IT) and/or Information Security (IS).

  • DoD 8140 certification for their respective area or the ability to obtain certification within six (6) months of onboarding.

  • Ability to obtain a interim Secret Security Clearance and must be eligible for a Top-Secret clearance if requested.


Compensation and Benefits:

The starting pay range for this role is $101,376 - $152,064.


NTT DATA provides a reasonable range of compensation for specific roles. Actual compensation will depend on a number of factors, including the candidate’s relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance. If the position offered in temporary, the position will not be eligible for incentive compensation. This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits.



  • medical, dental, and vision insurance with an employer contribution

  • flexible spending or health savings account

  • life and AD&D insurance

  • short and long term disability coverage

  • paid time off

  • employee assistance

  • participation in a 401k program with company match

  • additional voluntary or legally-required benefits


About NTT DATA

NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners.NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.


NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us . This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here . If you'd like more information on your EEO rights under the law, please click here . For Pay Transparency information, please click here .


Nearest Major Market: Washington DC
Job Segment: Computer Science, Information Security, Consulting, Information Systems, Technology

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Assurance Lead
Information Assurance Lead

NTT DATA, Inc. • Arlington (VA)

Hybrid
USD 103,000 - 210,000
Medical insurance
Dental insurance
Vision insurance
+5
Cybersecurity and Risk Analyst
Cybersecurity and Risk Analyst

NTT DATA, Inc. • Arlington (VA)

On-site
USD 110,000 - 184,000
Medical, dental, and vision coverage
401(k) with company match
Life and AD&D insurance
+1
Security Analysis Specialist Advisor- Night Shift
Security Analysis Specialist Advisor- Night Shift

NTT DATA, Inc. • Tempe (AZ)

Hybrid
USD 90,000 - 125,000
IT Desktop Support Technician II
IT Desktop Support Technician II

NTT DATA, Inc. • Bethesda (MD)

On-site
USD 60,000 - 81,000
Medical, dental, and vision insurance
401(k) with company match
Paid time off
Assessment and Authorization (A&A) Lead
Assessment and Authorization (A&A) Lead

NTT DATA North America • Rockville (MD)

On-site
USD 110,000 - 184,000
Medical insurance
401k with company match
Paid time off
Security / Compliance Engineering
Security / Compliance Engineering

NTT DATA North America • Jersey City (NJ)

On-site
USD 105,000 - 182,000
Medical insurance
Dental insurance
Vision insurance
+2
Senior Java Spring Boot Developer (FTE / Hybrid)
Senior Java Spring Boot Developer (FTE / Hybrid)

NTT America, Inc. • Town of Charlotte (NY)

Hybrid
USD 97,000 - 145,000
Incident Response Security Analysis Specialist Advisor-Night Shift
Incident Response Security Analysis Specialist Advisor-Night Shift

NTT DATA, Inc. • Tempe (AZ)

Hybrid
USD 130,000 - 165,000
Public Cloud Windows Engineer
Public Cloud Windows Engineer

NTT DATA North America • Plano (TX)

On-site
USD 68,000 - 78,202
Medical, dental, and vision insurance
Flexible spending or health savings account
Life and AD&D insurance
+1
ITSM Service Delivery Manager
ITSM Service Delivery Manager

NTT DATA, Inc. • Washington

Hybrid
USD 97,000 - 162,000
Medical, dental, vision insurance
Employer contributions
401k with company match
+5