Security Engineer
5 hours ago
Security Tooling Engineer
About Us
NTT DATA is one of the world's largest global security services providers, with over 7,500 security SMEs. We work with leading security technology vendors and pride ourselves on delivering innovative and effective solutions. Our people, clients, and communities are at the core of what we do. We're seeking individuals passionate about building a more secure and sustainable world.
What you';ll be doing:The Security Tooling Engineer is responsible for the operation, maintenance, integration, and optimization of security platforms and tools that support the delivery of security services across NTT DATA and Service Recipients. This role ensures that security tooling operates reliably, integrates seamlessly with enterprise infrastructure, and complies with governance requirements outlined.
Key Responsibilities
Platform Operations & Maintenance
- Operate and maintain security platforms in accordance with agreed Service Level Agreements (SLAs) as defined in Service Levels and KPIs
- Ensure high availability, performance, and reliability of all security tooling
- Monitor platform health and proactively address performance issues
- Manage platform upgrades, patches, and version control
- Provide monthly health and performance reports for all managed security platforms
Data Source Management & Integration
- Manage onboarding of data sources to security platforms (e.g., log sources to SIEM)
- Configure data parsing, normalization, and enrichment to ensure data quality
- Design and maintain dashboards and visualizations for security monitoring and reporting
- Ensure integration with other Security Services and Tooling across the ecosystem
- Integrate security tools with recipients clients or Global';s Splunk SIEM, CMDB, and ticketing systems
- Implement SSO (Single Sign-On) and MFA (Multi-Factor Authentication) integration with recipient clients or Global';s identity and access management systems
Access Management & Governance
- Enforce Role-Based Access Control (RBAC) across all security platforms
- Conduct quarterly access reviews to ensure least-privilege access
- Manage user provisioning and deprovisioning for Global, Service Recipients, and authorized Supplier personnel
- Maintain auditable logs of all access changes
- Ensure all access changes are logged and auditable per clients requirements
Configuration & Change Management
- Manage security tool configurations in accordance with the Change Control Procedure
- Document all configuration changes and maintain configuration baselines
- Ensure configuration changes are approved by Global and/or Service Recipients before implementation
- Maintain configuration management database (CMDB) entries for all security tooling
- Support configuration audits and compliance reviews
Vulnerability & Patch Management
- Perform vulnerability scans of security tooling platforms in line with Vulnerability Management Service requirements
- Apply patches within timelines defined by recipient clients or Global policies and standards
- Report remediation status monthly
- Escalate unpatched critical vulnerabilities immediately to recipient clients or Global service
- Ensure security tooling platforms comply with recipient client or Global';s patching policies
Incident & Problem Management
- Report tooling-related incidents (outages, performance issues, security events) to Global and or Service Recipients immediately
- Support Third Party vendor cases where Supplier actions affect system availability, integrity, or confidentiality
- Provide written notice of vulnerability disclosures and critical defects in tooling without undue delay
- Provide impact assessments and work-around proposals for tooling issues
- Log all tooling-related incidents and vulnerabilities in the agreed ticketing system
- Provide monthly reports detailing incident trends, vulnerability status, and remediation progress
Tooling Replacement & Migration
- Support tooling replacement activities when recipient clients or Global decides to replace existing tools
- Participate in hypercare activities for Replacement Tooling up to and including implementation date
- Ensure seamless migration of configurations, data, and integrations to new platforms
- Retrain on new tooling as required clients
- Cease use of Replaced Tooling by the specified replacement date
Security Tooling Portfolio Management
Manage and maintain the following categories of security tools:
Security Operations Tools
- SIEM (Security Information and Event Management) - e.g., Splunk
- EDR (Endpoint Detection and Response)
- SOAR (Security Orchestration, Automation and Response)
- Threat Intelligence Platforms
- Vulnerability Scanners (e.g., Qualys, Tenable)
- Brand Protection and Domain Monitoring Tools
- Certificate Authority (CA) and PKI Management Platforms
Security Architecture & Engineering Tools
- SAST (Static Application Security Testing) - e.g., Checkmarx, Fortify
- DAST (Dynamic Application Security Testing) - e.g., Burp Suite, OWASP ZAP
- SCA (Software Composition Analysis) - e.g., Snyk, Black Duck
- CSPM (Cloud Security Posture Management) - e.g., Prisma Cloud, Wiz
- Container Scanning Tools
- Penetration Testing Tools
Information Security Tools
- Third Party Risk Management Platforms
- Case Management Systems for Third Party Security Assessments
Service Support Tools
- Security Service Desk Ticketing Systems (e.g., Jira, ServiceNow)
- Reporting and Dashboard Platforms
Exit & Offboarding Support
- Upon expiry/termination of tooling contracts or at Global';s request:
- Return all configurations, runbooks, and artifacts
- Ensure orderly transfer of Supplier-created content
- Support account de-provisioning
- Return/destroy data per Global/Service Recipient policies
- Provide detailed handover plans for tooling transition to Global, Service Recipients, or Replacement Suppliers
Certifications (Required)
At least one of the following:
- Splunk Certified Admin / Splunk Certified Architect
- Certified Information Systems Security Professional (CISSP)
- GIAC Security Essentials (GSEC)
- CompTIA Security+
Certifications (Preferred)
- Vendor-specific certifications for managed tools (e.g., Qualys, Tenable, Palo Alto Networks)
- ITIL Foundation or higher
- Cloud certifications (AWS, Azure, GCP)
- Automation certifications (Ansible, Terraform)
Experience
- Minimum 4 years of experience in security operations, security engineering, or IT systems administration
- Minimum 2 years of hands-on experience with SIEM platforms (preferably Splunk)
- Proven experience managing security tooling in enterprise environments
- Experience with integration of security tools with enterprise infrastructure (IAM, CMDB, ticketing)
- Demonstrated experience with access management and RBAC implementation
- Experience with vulnerability management and patch management processes
Technical Skills
Security Platforms
- SIEM: Splunk (required), QRadar, ArcSight, LogRhythm, Sentinel
- EDR: CrowdStrike, Carbon Black, SentinelOne, Microsoft Defender
- SOAR: Splunk Phantom, Palo Alto Cortex XSOAR, IBM Resilient
- Vulnerability Management: Qualys, Tenable, Rapid7
- Threat Intelligence: Recorded Future, ThreatConnect, MISP
Integration & Automation
- REST APIs and API integration
- Scripting: Python, PowerShell, Bash
- Automation tools: Ansible, Terraform, Jenkins
- Data formats: JSON, XML, CSV, Syslog, CEF
Infrastructure & Networking
- Linux and Windows server administration
- Networking fundamentals (TCP/IP, DNS, firewalls, proxies)
- Cloud platforms: AWS, Azure, GCP
- Containerization: Docker, Kubernetes
Identity & Access Management
- SSO protocols: SAML, OAuth, OpenID Connect
- MFA solutions: Duo, Okta, Azure MFA
- LDAP/Active Directory integration
- RBAC design and implementation
Data & Reporting
- Log management and parsing
- Data normalization and enrichment
- Dashboard and visualization design (Splunk, Grafana, Kibana)
- Reporting and metrics
Frameworks & Standards
- Clients Global Security Control Framework
- ISO 27001, NIST Cybersecurity Framework, CIS Benchmarks
- ITIL service management practices
- Change management and configuration management
Soft Skills
- Strong problem-solving and troubleshooting abilities
- Excellent attention to detail
- Effective communication skills (written and verbal)
- Ability to work collaboratively across teams
- Customer service orientation
- Ability to manage multiple priorities and deadlines
- Proactive and self-motivated
Key Performance Indicators (KPIs)
- Platform uptime and availability (per SLA targets)
- Incident response time for tooling issues
- Monthly health report delivery timeliness and quality
- Access review completion rate (quarterly)
- Vulnerability remediation timeliness
- Integration success rate (new data sources, new tools)
- User satisfaction with tooling performance
- Compliance with stated requirements
We're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.
Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation. We are also proud to share that we have a range of Inclusion Networks such as: the Women's Business Network, Cultural and Ethnicity Network, LGBTQ+ & Allies Network, Neurodiversity Network and the Parent Network.
For more information on Diversity, Equity and Inclusion please click here: Creating Inclusion Together at NTT DATA UK | NTT DATA
what we';ll offer you:We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.
You can find more information about NTT DATA UK & Ireland here:
We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a proud Disability Confident Committed Employer - we are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.
Back to search Email to a friend
-
Birmingham, Birmingham, United Kingdom Macaw Security Solutions Full timeMacaw Security Solutions are a Security Systems Installation and Maintenance Company based in the West Midlands.Macaw Security are leading UK Security specialists based in the West Midlands.We are SSAIB accredited in Intruder Alarm Systems, Detector Activated CCTV Systems and Access Control Systems.We are seeking an experienced Security Installation Engineer...
-
Experienced Fire and Security Engineer
6 days ago
Birmingham, Birmingham, United Kingdom Sator Fire and Security Full timeFire & Security Engineer Full Time and PermanentA vacancy has arisen in our well established family owned Fire and Security Company for both fully qualified and trainee engineers.Our work is varied and includes; installations, maintenance and servicing for Fire (addressable and non-addressable), Intruder, Access Control, CCTV and Emergency Lighting.Our...
-
Security Engineer
6 days ago
Birmingham, Birmingham, United Kingdom Midas Full timeSecurity Engineer / InstallerMidlands Based | Up to £42,000 + Excellent Package | PermanentWe're partnering with a growing and well-established security solutions provider who are looking to recruit an experienced Security Engineer / Installer into their engineering team. This is a remote, Midlands-based role with no travel outside your region, offering...
-
Senior Security Consultant
13 hours ago
Birmingham, Birmingham, United Kingdom Forfend Information Security Full timeCompany DescriptionForfend is a penetration testing company founded by experienced testers. We believe in creating an environment where technical talent thrives and meaningful security work happens. Our passion for cyber security helps us build safer digital environments and empower organisations to grow securely. Founded in 2022, we have already gained...
-
Security Operations Engineer
1 week ago
Birmingham, Birmingham, United Kingdom Context Recruitment Full time £50,000 - £60,000 per yearIT Security Operations EngineerBirmingham (hybrid – 3 days per week onsite, 37.5hr week)£55,000 - £60,000 plus outstanding, high-value benefits packageOur client, a public facing and well-known organisation with a people-first approach to both customers and employees is seeking an ambitious IT Security Engineer to join their well established IT...
-
Security Engineer
6 days ago
Birmingham, Birmingham, United Kingdom NTT DATA Full timeSecurity Tooling EngineerAbout UsNTT DATA is one of the world's largest global security services providers, with over 7,500 security SMEs. We work with leading security technology vendors and pride ourselves on delivering innovative and effective solutions. Our people, clients, and communities are at the core of what we do. We're seeking individuals...
-
Service Engineer
1 week ago
Birmingham, Birmingham, United Kingdom Complete Security Recruitment Full time £24,000 - £36,000 per yearFire & Security Role:Are you aSecurity Service Engineerworking with CCTV, Intruder, Access Control and Fire?Paying up to£36kWhat can you expect as an employee:Company Vehicle/Fuel CardPDA/Laptop/Mobile PhoneOvertime and call outsCompany Life InsuranceUniform provided(Must have own hand and power tools)The ideal candidate would have:Experience of CCTV,...
-
Security Service Engineer
1 week ago
Birmingham, Birmingham, United Kingdom Tech Recruits Here To Connect Full time £32,000 - £34,000 per yearJob DescriptionSecurity Systems Service Engineer - Intruder, CCTV & AccessLocation: MidlandsContract Type: PermanentSalary: £32,000.00-£34,000.00 per yearJoin a growing security specialist with a strong reputation.Receive a new company van with all private mileage covered.Benefit from a culture of trust, autonomy, and no micro-management.Earn a standby...
-
Security Design Engineer
6 days ago
Birmingham, Birmingham, United Kingdom NTT DATA Full timePlease note, you will need to be eligible for SC clearanceNTT DATAis one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.Working under direct supervision, you will apply your developing expertise...
-
Senior Cyber Security Engineer
2 weeks ago
Birmingham, Birmingham, United Kingdom SYSTRA Full time £60,000 - £1,100,000 per yearAround the world, SYSTRA's specialists plan, design, integrate, test, commission, project manage and deliver mass transit and mobility solutions that are relied on by more than 50 million people every day.For more than 60 years, the Group has been committed to helping cities and regions contribute to their development by creating, improving and modernising...