IT Security Analyst
NTT DATA Business Solutions
IT Security Analyst
Supports the enterprise-wide implementation of the Secrets & Credential Management project by analyzing current-state processes, identifying security and control gaps, defining requirements, and driving the secure governance of technical and workforce secrets. Ensures that secrets such as passwords, SSH keys, API keys, certificates, tokens and non-personal credentials are identified, classified, documented, and prepared for controlled lifecycle management in line with security, compliance, and operational requirements.
Conduct end-to-end analysis of existing secret and credential management practices across applications, infrastructure, platforms, and operational processes. Identify, classify and document technical and workforce secrets, including ownership, usage, storage location, criticality, lifecycle stage, access model, and associated risks. Assess current-state control weaknesses such as unmanaged SSH keys, hardcoded credentials, shared accounts, undocumented secret usage, insufficient rotation, and weak auditability. Define and document detailed functional and non-functional requirements for centralized secrets management capabilities. Support the design of compliant lifecycle processes for creation, storage, access, usage, rotation, revocation, emergency access and decommissioning of secrets. Analyze dependencies across systems, applications, service accounts, technical users, and operational teams to support onboarding and migration planning. Prepare clear and defensible security analysis deliverables, including gap assessments, process documentation, risk assessments, control requirements, and remediation recommendations. Facilitate and document workshops with technical, operational, and business stakeholders to gather requirements, validate findings and resolve ambiguities. Contribute to tool evaluation activities by translating operational and security needs into concrete assessment criteria and use cases. Validate whether proposed solution approaches meet defined security, compliance, and operational expectations. Support reporting and governance activities by maintaining traceability of findings, risks, requirements, remediation items, and implementation dependencies. Ensure analysis outputs are audit-ready, internally consistent, and suitable for decision-making at project and stakeholder governance level.
At least 5 years of experience in a similar position. At least 2 years of experience in working with IAM projects. Strong experience in IT security analysis, security requirements engineering, control assessment, or security governance in complex enterprise environments. Proven knowledge of secrets and credential types, including passwords, SSH keys, API keys, tokens, certificates, service accounts and privileged credentials. Experience in analyzing IT processes, identifying control gaps, and translating findings into implementable security requirements. Strong understanding of IAM, PAM, least privilege, segregation of duties, auditability, and secure access governance. Ability to work across technical and non-technical stakeholder groups and drive structured analysis in ambiguous environments. Strong documentation, workshop facilitation, and communication skills in English. Experience in regulated, global, or highly controlled environments.
The opportunity to participate in a variety of projects. Remote work from any location. B2B cooperation with a stable, long-term project environment. Competitive daily rate aligned with your experience and market standards. Access to modern technologies and challenging, impactful assignments. Supportive, collaborative team culture focused on knowledge exchange and innovation.
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security Analyst. Be the first to apply!
- bond analyst United States
- rate analyst United States
- network security analyst United States
- information security compliance analyst United States
- security analyst intern United States
- entry level information security analyst United States
- security analyst remote United States
- entry level security analyst United States
- physical security analyst United States
- security operations analyst United States
