Security Engineer

Company: NTT DATA
Apply for the Security Engineer
Location: Birmingham
Job Description:

Overview

In this SOC Engineer role at NTT DATA, you defend clients against evolving cyber threats by configuring and optimizing SIEM platforms and building automated detection and response workflows. You will work across cloud and on-prem environments, integrating threat intelligence and developing playbooks to reduce incident response times. You’ll collaborate with cross-functional teams to deliver measurable improvements in security posture and incident handling. This opportunity offers hands-on security engineering at scale, shaping how the SOC operates in a fast-paced, real-time environment.

Pay / Benefits

  • flexible work options
  • learning and development opportunities
  • wellbeing and financial wellbeing support
  • inclusive and diverse workplace

Responsibilities

  • Deploy, configure, and maintain SIEM platforms (Splunk, QRadar, Sentinel, Chronicle) and onboard log sources
  • Develop and refine SIEM rules and queries for advanced threat detection
  • Design incident response playbooks and integrate SOAR automation (XSOAR, Azure Logic Apps)
  • Refine playbooks using threat intel and simulated incidents
  • Monitor alerts, investigate incidents, and coordinate cross-team response
  • Collaborate with threat intelligence to improve detection logic and resolution processes
  • Perform root-cause analysis of recurring incidents and define corrective actions
  • Perform threat modeling using MITRE ATT&CK, STRIDE, or Cyber Kill Chain; design use cases and workflows
  • Develop dashboards and metrics-driven reports for leadership; document procedures and runbooks
  • Support pre-sales by demonstrating SOC tools and benchmarking new solutions against client expectations

Key requirements

  • Hands-on experience with SIEM platforms (Splunk, QRadar, Sentinel, Microsoft Defender, Chronicle)
  • Proficiency with SIEM query languages (KQL, SPL, AQL) and log normalization/parsing
  • Scripting skills (Python, PowerShell) for automation
  • Knowledge of threat detection techniques aligned with MITRE ATT&CK and vulnerability management
  • Experience with ITIL processes (Incident, Problem, Change Management)
  • Certifications preferred: CISSP, GIAC, SC-200, Splunk Power User/Admin, QRadar Specialist, or Chronicle Security Engineer
  • Eligible for UK SC clearance
  • Strong analytical and communication skills; mentoring ability
  • analytical thinking
  • clear communication to technical and non-technical stakeholders
  • collaborative teamwork
  • SIEM platforms: Splunk, QRadar, Sentinel, Chronicle, Microsoft Defender
  • SOAR platforms: XSOAR
  • Automation: Python, PowerShell

…

Posted: September 15th, 2026