- Company Name
- NTT DATA
- Job Title
- Security Engineer
- Job Description
-
Job Title: Security Tooling Engineer
Role Summary:
Design, operate, and maintain enterprise security platforms (SIEM, EDR, SOAR, threat intelligence, vulnerability scanners, PKI, SAST, DAST, SCA, CSPM) to support global security services. Ensure high availability, performance, governance compliance, and seamless integration with client infrastructure and ticketing systems.
Expectations:
• Deliver secure, reliable tooling aligned with SLA/KPI targets.
• Proactively monitor, upgrade, patch, and document all security systems.
• Manage data source ingestion, normalization, and visualization for effective threat monitoring.
• Enforce role‑based access controls, perform quarterly reviews, and maintain audit logs.
• Lead incident, problem, and vulnerability management with timely reporting.
• Coordinate tooling replacement, migration, and hyper‑care activities.
• Maintain an up‑to‑date security tool portfolio and configuration baselines.
Key Responsibilities:
- Operate and maintain security platforms in line with SLAs, ensuring high availability and performance.
- Monitor platform health, address performance issues, apply upgrades/patches, and produce monthly health reports.
- Onboard and configure data sources to SIEM; design dashboards and integrations with CMDB, ticketing, and client environments.
- Implement SSO/MFA, enforce RBAC, conduct access reviews, and log all changes.
- Manage configuration changes per change control procedures, document baselines, and support audits.
- Perform vulnerability scans, apply patches within defined timelines, report remediation status, and elevate critical findings.
- Report tooling incidents, support third‑party vendor cases, log vulnerabilities, and provide trend analyses.
- Facilitate tooling replacement and migration, participate in hyper‑care, and retire legacy tools.
- Oversee the security tooling portfolio across operations, architecture, and engineering categories.
Required Skills:
- Platform operations (SIEM, EDR, SOAR, threat intel, vulnerability scanners, PKI).
- Data ingestion, parsing, enrichment, and dashboard design.
- Integration with Splunk, CMDB, ticketing systems, SSO, MFA, and IAM.
- RBAC, access review, provisioning/deprovisioning, and audit logging.
- Change control, configuration management, CMDB updates.
- Vulnerability scanning, patch management, incident/problem management, and reporting.
- Tooling migration, hyper‑care support, and retraining.
- Strong analytical, documentation, and communication abilities.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Industry certifications: CISSP, CISM, Security+, CEH, Splunk Certified User/Administrator, or equivalent.
- Experience with SIEM (e.g., Splunk), EDR, SOAR, threat intelligence platforms, vulnerability scanners (Qualys/Tenable), PKI, SAST/DAST/SCA tools.
Birmingham, United kingdom
Hybrid
09-01-2026