About this role
Salary: £55,000 - 95,000 per year
Requirements: We are looking for someone with awareness and understanding of industry security frameworks and guidance such as NIST CSF, NIST 800-53, NCSC CAF and other NCSC guidelines.We need good knowledge of networking, including switching, routing and firewalls.We are looking for awareness or limited experience with cloud platform design concepts, including AWS and/or Microsoft Azure.We need understanding of native security capabilities and some practical experience within AWS and/or Microsoft Azure.We are looking for understanding of modern security concepts, common attack vectors, malware, security analytics and threat intelligence.We need understanding of security testing and vulnerability management, including pen testing, ITHC, CVSS and CVE.We are looking for some experience working with security standards such as ISO 27001, 27002, 27017 and 27108.We would like a minimum of 5 years of experience in cyber security.We would like one of the following certifications, or equivalent experience: CISSP, CISM, CCSP or CRISC.We need good knowledge covering at least two of the following: AD, cryptography, end user computing, IAM, PKI, server hardening, SIEM, SOAR, virtualization (VMware).We are looking for strong teamwork skills and attention to detail.We need excellent written and verbal communication skills.We are looking for self-motivation and the ability to take responsibility.We value a persuasive communicator who uses logic to win support and change views. Responsibilities: We contribute to the design, implementation and ongoing development of the security architecture of client IT systems.We identify business objectives, user needs, risk appetite and cyber security obligations.We identify vulnerabilities, perform threat modelling, undertake risk assessments and evaluate the effectiveness of security controls.We verify and evidence alignment to Secure by Design principles, corporate security policy and standards, and industry recognised frameworks and best practice.We deliver and continually enhance a coherent approach to the design of secure end-to-end client solutions.We contribute to secure conceptual, logical and high level designs by identifying appropriate security controls that meet business requirements and target risk appetite.We contribute to the design and articulate and justify design recommendations at security architecture assurance gates.We contribute to design documentation, options papers, risk assessments and stakeholder presentations, and communicate these to senior technical and non-technical stakeholders.We contribute to reference architectures, established patterns, principles and guidelines.We contribute to the development of our Security Practice skills and capabilities, including coaching and mentoring junior team members.We contribute to collateral supporting Security Consulting go-to-market propositions and service offerings.We contribute to client proposals and collaborate with teams across our business.We contribute to documented Information Security Management Plans covering regulatory, legal and compliance considerations.We identify risks and emerging cyber security vulnerabilities and threats, analyse them and help lead risk mitigation plans.We work with Service Management to ensure partners and suppliers adhere to agreed standards and policies and to verify compliance and security KPIs.We work closely with our 1st, 2nd and 3rd lines of defence on cyber security, information assurance, cyber risk, data privacy and compliance considerations.We contribute to governance, risk and compliance development and enhancement aligned to policy, standards and industry good practice.We continuously assess, identify, analyse and report useful metrics to support informed risk-based decisions.We constructively challenge established processes and controls to drive continuous improvement.We ensure personnel, including senior stakeholders, understand their responsibilities in relation to security risk mitigation and remediation.We review and verify that documentation relating to process and technical security controls is maintained.We thrive as consultants engaging with different clients, technologies and solution types.We develop security vulnerability techniques and apply effective controls.We contribute to the development of secure systems without close supervision.We contribute to security requirements for new systems or changes to existing systems without close supervision.We execute technical management tasks in respect of ongoing client projects. Technologies: AIAWSAzureCloudCryptographyIAMSupportSecurityVMwareArchitectEmbeddedNetwork More:
We are NTT DATA, a business and technology services, AI and digital infrastructure leader with global reach and a focus on co-innovation, experimentation and impact. We support clients and partners worldwide, serve a large share of the Fortune Global 100, and invest heavily in research and development. We offer tailored benefits that support physical, emotional and financial wellbeing, ongoing learning and development opportunities, and flexible work options. We are an equal opportunities employer and a proud Disability Confident Committed Employer, committed to fair treatment, diversity, inclusion and reasonable adjustments throughout the recruitment process.
last updated 36 week of 2026