At a Glance
- Tasks: Investigate security incidents and analyse digital forensic evidence to support clients.
- Company: Join NTT DATA, a leader in technical excellence and innovation.
- Benefits: Remote work, diverse culture, and opportunities for career growth.
- Other info: Be part of a global team and stay ahead of emerging threats.
- Why this job: Make a real impact in cybersecurity while expanding your skills.
- Qualifications: Experience in incident response and digital forensics is essential.
The predicted salary is between 45000 - 60000 £ per year.
Continue to make an impact with a company that is pushing the boundaries of what is possible. At NTT DATA, we are renowned for our technical excellence, leading innovations, and making a difference for our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can continue to grow, belong, and thrive. Your career here is about believing in yourself and seizing new opportunities and challenges. It’s about expanding your skills and expertise in your current role and preparing yourself for future advancements. That’s why we encourage you to take every opportunity to further your career within our great global team.
Job Description Summary
The Information Security Incident Response Analyst supports clients during security incidents by performing technical investigations, analyzing digital forensic evidence, and assisting with containment and remediation activities. This role focuses on identifying indicators of compromise, reconstructing attacker activity, and communicating clear, actionable findings. The analyst works as part of a global DFIR team, handling a variety of incident types across diverse environments. They contribute to process improvements, maintain strong client communication, and continue building advanced DFIR skills through hands‑on investigations and internal project work.
Key Responsibilities
- Investigates security incidents by performing host, disk, memory, network, and cloud forensic analysis under established processes and guidance.
- Analyzes artifacts across Windows, Linux, and macOS systems, helping reconstruct timelines and determine root cause.
- Supports clients through containment and recovery efforts by providing technical recommendations and clear communication.
- Participates in the team’s on‑call rotation for urgent incident response needs.
- Completes internal and client tasks such as tabletop exercises, IR readiness assessments, basic forensic reviews, and environment hardening support.
- Identifies observable gaps and risks within client environments and recommends improvements to strengthen security posture.
- Produces accurate documentation—including investigation notes, status updates, and final reports.
- Collaborates with global DFIR and other teams and stays current on threats, attacker techniques, and emerging forensic tools.
Knowledge and Attributes
- Solid understanding of digital forensics fundamentals, including host‑based analysis across major operating systems.
- Working knowledge of network forensics, cloud log analysis (e.g., Azure, AWS, GCP), and common forensic tools.
- Ability to clearly communicate technical findings to both technical and non‑technical audiences.
- Strong analytical and problem‑solving skills, especially during time‑sensitive investigations.
- Motivated to continuously learn deeper DFIR techniques and methodologies.
Required Experience
- Proven experience in incident response and digital forensics, with capability in host‑based, image, and log analysis.
- Experience using SIEM, EDR, IDS/IPS, and other security tools to triage, investigate, and respond to incidents.
- Ability to perform network analysis using tools such as Wireshark, tcpdump, and other tools.
- Experience in cybersecurity operations, consulting, DFIR services, or related technical security roles.
Academic Qualifications, Certifications
- Bachelor’s degree or equivalent experience in Information Technology, Computer Science, Cybersecurity, or a related discipline (preferred).
- Relevant cybersecurity certifications such as:
- SANS GIAC Security Essentials (GSEC) or equivalent preferred.
- SANS GIAC Certified Intrusion Analyst (GCIA) or equivalent preferred.
- SANS GIAC Certified Incident Handler (GCIH) or equivalent preferred.
- Additional DFIR‑related certifications are considered a plus.
Additional UK‑Specific Role Requirements
- Active UK Security Clearance is required to deliver services within sensitive or regulated client environments.
- Background and hands‑on experience in OT environments.
- Experience investigating ICS/SCADA systems and industrial sectors such as manufacturing, energy, utilities, or critical infrastructure.
- Ability to collect and analyze OT forensic artifacts, interpret OT protocols and system behavior, and assess the impact of cyber incidents on physical processes.
- SANS OT/ICS certifications such as GICSP or GRID, IEC 62443 or equivalent required.
Workplace type: Remote Working
Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Accelerate your career with us. Apply today.
Information Security Incident Response Analyst employer: NTT
At NTT DATA, we are dedicated to fostering a dynamic and inclusive work environment where every employee can thrive. As an Information Security Incident Response Analyst, you will not only engage in cutting-edge technical investigations but also benefit from extensive career development opportunities within our global team. Our commitment to diversity, continuous learning, and innovation makes NTT DATA an exceptional employer for those looking to make a meaningful impact in the cybersecurity field.
StudySmarter Expert Advice🤫
We think this is how you could land Information Security Incident Response Analyst
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your incident response projects or any relevant work you've done. This gives potential employers a taste of what you can bring to the table.
✨Tip Number 3
Prepare for interviews by brushing up on common incident response scenarios. Practice explaining your thought process and how you tackle challenges. Confidence is key, so let your passion for cybersecurity shine through!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Information Security Incident Response Analyst
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Information Security Incident Response Analyst role. Highlight your relevant experience in incident response and digital forensics, and don’t forget to mention any specific tools or techniques you’ve used that align with the job description.
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your skills can contribute to NTT DATA's mission. Be sure to mention your understanding of digital forensics and your eagerness to grow within the team.
Showcase Your Communication Skills:Since this role involves communicating technical findings to various audiences, make sure your application reflects your ability to convey complex information clearly. Use straightforward language and examples that demonstrate your communication prowess.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details you need about the role and our company culture there!
How to prepare for a job interview at NTT
✨Know Your Forensics
Brush up on your digital forensics fundamentals. Be ready to discuss host-based analysis across Windows, Linux, and macOS systems. Familiarise yourself with common forensic tools and be prepared to explain how you've used them in past incidents.
✨Communicate Clearly
Since this role involves communicating technical findings to both technical and non-technical audiences, practice explaining complex concepts in simple terms. Think of examples where you successfully communicated findings or recommendations to clients or team members.
✨Stay Current on Threats
Make sure you're up-to-date with the latest threats and attacker techniques. Research recent incidents in the cybersecurity landscape and be ready to discuss how they relate to the role. This shows your commitment to continuous learning and staying ahead in the field.
✨Demonstrate Problem-Solving Skills
Prepare to showcase your analytical and problem-solving skills, especially in time-sensitive situations. Think of specific examples from your experience where you had to think on your feet during an incident response and how you approached the problem.