Now hiring

Information Security Incident Response Analyst @ NTT

King William Street 1, LondonOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Salary: £63,000 - 103,000 per year

Requirements: We require solid understanding of digital forensics fundamentals, including host-based analysis across major operating systems.We require working knowledge of network forensics, cloud log analysis (e.g., Azure, AWS, GCP), and common forensic tools.We require the ability to clearly communicate technical findings to both technical and non-technical audiences.We require strong analytical and problem-solving skills, especially during time-sensitive investigations.We require motivation to continuously learn deeper DFIR techniques and methodologies.We require proven experience in incident response and digital forensics, with capability in host-based, image, and log analysis.We require experience using SIEM, EDR, IDS/IPS, and other security tools to triage, investigate, and respond to incidents.We require the ability to perform network analysis using tools such as Wireshark, tcpdump, and other tools.We require experience in cybersecurity operations, consulting, DFIR services, or related technical security roles.We prefer a bachelors degree or equivalent experience in Information Technology, Computer Science, Cybersecurity, or a related discipline.We prefer relevant certifications such as SANS GIAC Security Essentials (GSEC), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH), GICSP, GRID, GCIP, ISA/IEC 62443 Cybersecurity Certificates, IC32/IC33/IC34, or other DFIR-related certifications.For UK-based services in sensitive or regulated client environments, active UK Security Clearance is required.For OT incident response and digital forensics, we require background and hands-on experience in OT environments.For OT work, we require experience investigating ICS/SCADA systems and industrial sectors such as manufacturing, energy, utilities, or critical infrastructure.For OT work, we require the ability to collect and analyze OT forensic artifacts, interpret OT protocols and system behavior, and assess the impact of cyber incidents on physical processes.For OT work, experience with tools such as Claroty CTD, Nozomi Guardian, Dragos Platform, Tenable.ot, and/or Forescout/SCADAfence is preferred. Responsibilities: We investigate security incidents by performing host, disk, memory, network, and cloud forensic analysis under established processes and guidance.We analyze artifacts across Windows, Linux, and macOS systems, helping reconstruct timelines and determine root cause.We support clients through containment and recovery efforts by providing technical recommendations and clear communication.We participate in the teams on-call rotation for urgent incident response needs.We complete internal and client tasks such as tabletop exercises, IR readiness assessments, basic forensic reviews, and environment hardening support.We identify observable gaps and risks within client environments and recommend improvements to strengthen security posture.We produce accurate documentation, including investigation notes, status updates, and final reports.We collaborate with global DFIR and other teams and stay current on threats, attacker techniques, and emerging forensic tools. Technologies: AIAWSAzureCloudGCPSupportLinuxmacOSNetworkSecurityWindows More:

We are NTT DATA, a $30+ billion business and technology services leader serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the worlds leading AI and digital infrastructure providers, with capabilities across enterprise-scale AI, cloud, security, connectivity, data centers, and application services. Our consulting and industry solutions help organizations move confidently and sustainably into the digital future, and our global team spans more than 70 countries. We are proud to be an equal opportunity employer with a global culture that embraces diversity and inclusion. This role is remote working and focused on supporting clients during security incidents as part of our global DFIR team.

last updated 36 week of 2026

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores