Information Security Incident Response Analyst
NTT
Information Security Incident Response Analyst
Make an impact with NTT DATA. Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.
The Information Security Incident Response Analyst supports clients during security incidents by performing technical investigations, analyzing digital forensic evidence, and assisting with containment and remediation activities. This role focuses on identifying indicators of compromise, reconstructing attacker activity, and communicating clear, actionable findings.
The analyst works as part of a global DFIR team, handling a variety of incident types across diverse environments. They contribute to process improvements, maintain strong client communication, and continue building advanced DFIR skills through hands-on investigations and internal project work.
Key Responsibilities
- Investigates security incidents by performing host, disk, memory, network, and cloud forensic analysis under established processes and guidance.
- Analyzes artifacts across Windows, Linux, and macOS systems, helping reconstruct timelines and determine root cause.
- Supports clients through containment and recovery efforts by providing technical recommendations and clear communication.
- Participates in the team's on-call rotation for urgent incident response needs.
- Completes internal and client tasks such as tabletop exercises, IR readiness assessments, basic forensic reviews, and environment hardening support.
- Identifies observable gaps and risks within client environments and recommends improvements to strengthen security posture.
- Produces accurate documentation—including investigation notes, status updates, and final reports.
- Collaborates with global DFIR and other teams and stays current on threats, attacker techniques, and emerging forensic tools.
Knowledge and Attributes
- Solid understanding of digital forensics fundamentals, including host-based analysis across major operating systems.
- Working knowledge of network forensics, cloud log analysis (e.g., Azure, AWS, GCP), and common forensic tools.
- Ability to clearly communicate technical findings to both technical and non-technical audiences.
- Strong analytical and problem-solving skills, especially during time-sensitive investigations.
- Motivated to continuously learn deeper DFIR techniques and methodologies.
Required Experience
- Proven experience in incident response and digital forensics, with capability in host-based, image, and log analysis.
- Experience using SIEM, EDR, IDS/IPS, and other security tools to triage, investigate, and respond to incidents.
- Ability to perform network analysis using tools such as Wireshark, tcpdump, and other tools.
- Experience in cybersecurity operations, consulting, DFIR services, or related technical security roles.
Academic Qualifications, Certifications
- Bachelor's degree or equivalent experience in Information Technology, Computer Science, Cybersecurity, or a related discipline (preferred).
- Relevant certifications such as:
- SANS GIAC Security Essentials (GSEC) or equivalent preferred.
- SANS GIAC Certified Intrusion Analyst (GCIA) or equivalent preferred.
- SANS GIAC Certified Incident Handler (GCIH) or equivalent preferred.
- GICSP – GIAC Global Industrial Cyber Security Professional
- GRID – GIAC Response and Industrial Defense
- GCIP – GIAC Critical Infrastructure Protection
- ISA/IEC 62443 Cybersecurity Certificates (ISA/IEC 62443 Cybersecurity Fundamentals, etc.)
- IC32/IC33/IC34
- Any additional DFIR-related certifications.
Additional UK-Specific Role Requirements
UK Security Clearance
- Active UK Security Clearance is required to deliver services within sensitive or regulated client environments.
Operational Technology (OT) Incident Response & Digital Forensics
- Background and hands-on experience in OT environments.
- Experience investigating ICS/SCADA systems and industrial sectors such as manufacturing, energy, utilities, or critical infrastructure.
- Ability to collect and analyze OT forensic artifacts, interpret OT protocols and system behavior, and assess the impact of cyber incidents on physical processes.
- Experience with any of the following tools: Claroty CTD, Nozomi Guardian, Dragos Platform, Tenable.ot and/or Forescout/SCADAfence.
Workplace type: Remote Working
About NTT DATA NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. Our consulting and industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 70 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each year in R&D.
Equal Opportunity Employer NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, color, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.
Third parties fraudulently posing as NTT DATA recruiters
NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters whether in writing or by phone in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @nttdata.com email address. If you suspect any fraudulent activity, please contact us.
- ...As a SOC Analyst (m/f/d), you will strengthen our clients’ information security through your expertise and passion for IT security... ...analyzing security-critical incidents but also helping to further develop... .... With a sense of personal responsibility and team spirit, you will be...SuggestedWork from homeFlexible hours
- Gulf Coast Automation Group is seeking an Information Security Analyst (SOC) for a fully remote Direct Hire role. You will join a growing security operations team, lead incident response activities, hunt threats, and help design detection capabilities across a large enterprise...SuggestedRemote job
$104.49k - $159.88k
...: Position Details Position Information Recruitment/Posting Title Senior Incident Response Analyst Job Category Staff & Executive - Information Technology Department... ...processes as well as monitoring of information security incidents throughout Rutgers' computing...SuggestedFull timeTemporary workSeasonal workWork at officeFlexible hoursShift work- ...Cortek, Inc. is seeking a Senior Analyst-CBRN in Washington, DC, to support the Office of WMD Response and Planning. This position involves coordinating interagency... ...and enhancing foreign capabilities against CBRN incidents. Applicants must have an active Top-Secret...SuggestedWork at office
- ...MDAEdge is seeking a cybersecurity professional to handle incidents and strengthen enterprise security while working remotely from the U.S. The role involves managing incident response, collaborating with teams, and ensuring compliance with security standards. Ideal candidates...SuggestedRemote work
- ...solutions provider is seeking a Remote SOC Analyst to join their team in Atlanta, Georgia.... ...cybersecurity operations and hold relevant security certifications. Responsibilities include investigating alerts, conducting incident response, and correlating data to identify...Remote work
$120k - $135k
...for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in support of a... ...critical government program. As part of the Security Operations Center, you will help... ...degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a...Permanent employmentContract workRemote work2 days per week- ...are seeking a highly skilled Senior Incident Response Analyst to lead advanced threat detection, investigation... ..., and remediation efforts within our Security Operations program. This role is... ...or expression, pregnancy, genetic information, protected military and veteran...Worldwide
- ...Sentar is seeking a Tier 3 Incident Response Senior Analyst in Quantico, VA! Role Description Sentar is... ...defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions.... ...to disrupt, exploit and attack the information technology (IT) services provided to...Contract workTemporary workWork experience placementRemote workFlexible hoursWeekend work
- ...Description Continue to develop the company's incident response program. Utilize and adhere to defined... ...processes. Collect supporting information and/or relevant artifacts to support Incident... ..., SMTP), system administration, and security architecture. Excellent verbal and...Work at officeLocal areaRemote workRelocationVisa sponsorship
- ...increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first... ...security on a global scale, this is the place to do it. Key Responsibilities Responsible for daily incident management of customer incidents Perform incident...Worldwide
- ...Trace3 is looking for a SOC Analyst located in Kansas City, KS. In this role, you will be responsible for monitoring, detecting, and responding to cybersecurity incidents. Key tasks include analyzing security events from various technologies, documenting incidents, and...
- ...Responsibilities Lead high‑fidelity alert investigations, performing deep... ...remediate threats. Own complex incident investigations, driving... ...excellence. Mentor and uplift junior analysts, providing guidance,... ...holistically and drive enterprise‑wide security improvements. Apply strong...
- ...A cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management for federal contracts. The role includes event triage, incident investigations, and close coordination with federal cybersecurity teams. Ideal candidates will have experience...Remote work
- Trace3 is seeking a SOC Analyst to monitor, detect, analyze, and respond to cybersecurity incidents in Fargo, North Dakota. The ideal candidate will have... ...2 years of experience in a SOC or IT security operations role. Responsibilities include monitoring security alerts,...
- ...Mindlance is seeking a highly skilled Incident Response Analyst to detect and respond to security incidents. The role involves monitoring security alerts, conducting in-depth analyses, and leading response efforts for client security breaches. The ideal candidate should...
- Job Description Responsible for daily incident management of customer incidents Perform incident response and forensic analysis of compromised systems... ...on system compromise analysis. Experience of performing security reviews/vulnerability risk assessments of network...
- ...Koniag Government Services company, seeks a Mid-Level Security Operations Center Analyst to support SBA in Washington, DC. The role requires the... ...Trust and will involve monitoring, analysis, and incident response within a federal government context. The position emphasizes...
- ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of security-focused AI systems - and we need real incident responders to help get it right. As an Incident Response Analyst, you'...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Senior Incident Response Analyst Location: Remote (USA-based, on-call support required) Employment Type: Full-time The Senior Incident... ...cloud (AWS/Azure) environments, contributing to scalable security enhancements and threat detection. This individual will...Full timeRemote workShift work
- ...Purpose: Resolve security incidents and recommend improvements... .... Execute incident response plans and contribute to scalable... .... Coordinate with Information Security Architects, Engineers... ..., GIAC Certified Intrusion Analyst (GCIA), or GIAC Certified...Remote work
- ...Incident Response Analyst (Task 4 – Federal Cybersecurity Contract) Location: Remote with occasional on-site (Washington, D.C. Metro Area) Employment... ...services contract. This role provides front-line security event triage, investigation, reporting, and coordination across...Full timeContract workRemote workMonday to Friday
- ...Incident Response Analyst Salisbury, NC (Remote) 90% Remote: must be within driving distance... ...response experience # MS Security Tools Suite Experience (Defender)... ...for managing threats, disseminating information, and handling, responding to, and investigating...Contract workWork experience placementRemote work
- ...Executing the enterprise-wide Incident Response Plan, the full-time Principal Incident Response Analyst will recommend security enhancements, manage incident response processes, and collaborate with various stakeholders in a remote work environment. Key responsibilities...Full timeRemote work
- ..., and experienced cyber forensic and incident response analyst to work as part of the cyber defense... ...will be expected to dive into cyber security incidents, investigate new attacks and... ...technical depth, practical experience in information security, excellent written and...Remote work
$131.3k - $237.35k
...Leidos has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program. The Department of Homeland Security (DHS), Security Operations Center (SOC)... ...degree in Computer Science, Engineering, Information Technology, Cyber Security, or related field...Flexible hours- Qualifications At least 2 years of incident response experience Experience with Crowdstrike... ...measures, evaluate system changes for security implications, recommend enhancements,... ...Xcode, SWASP Checker, SoapUI. Additional Information The end client is unable to sponsor or...Remote workVisa sponsorship
- ...A national financial institution is seeking an Intermediate SOC Analyst for a remote night shift position to perform security event triage and manage incidents. Ideal candidates will understand information technologies and security threats, with opportunities to develop...Remote workNight shift
- ...The Clearing House in North Carolina is seeking an Incident Management Analyst to coordinate the incident management process, particularly during major incidents. The successful applicant will analyze incident data, support resolution efforts, and assist in managing processes...Work at office2 days per week3 days per week
- ...Description cFocus Software seeks a Incident Response Analyst (Tier 2) to join our program supporting... ...clearance ~ B.S. Computer Science, Information Technology, or a related field ~3+... ...29: CSF, and NIST SP-800-61 Computer Security Incident Handling Guide. ~ Active...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Incident Response Analyst. Be the first to apply!
- data analyst excel United States
- data visualization analyst United States
- entry level information security analyst United States
- talent data analyst United States
- regulatory reporting analyst United States
- senior healthcare data analyst United States
- compliance data analyst United States
- junior healthcare data analyst United States
- clinical data analyst United States
- data analyst no experience United States


