Director, Incident Response and Threat Hunting
NTT DATAAbout the role
Make an impact with NTT DATA
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.
Your day at NTT DATA
The Director of Incident Response and Threat Intelligence is a senior leadership position responsible for overseeing and managing all aspects of an organization’s security incidents and preventing events from becoming incidents. This role is crucial for safeguarding the organization’s data, systems, and infrastructure from cyber threats. The individual has direct and indirect management responsibility across cross-functional teams to respond to security incidents, sets strategic direction, and ensures the effective implementation of security measures to protect the confidentiality, integrity, and availability of the organization’s information assets.What you'll be doing
Key Responsibilities:
Act as Global Incident response Commander:
- Global Incident Response Commander’s key responsibilities include leading and coordinating the response to major incidents across a global organization, prioritizing incidents based on severity, managing resources, facilitating communication with stakeholders, developing and implementing an incident action plan, assigning roles and responsibilities within the team, and ensuring a timely and efficient response to minimize impact. This role also requires maintaining effective communication across different time zones and cultures.
Cybersecurity Incident Response (CSIRT):
- Leads and manages the organization’s CSIRT team.
- Develops and maintains incident response plans, playbooks, and procedures.
- Attack Surface Management: Monitor and maintain ASM alerting and implement processes to mitigate external threats.
- Coordinates and responds to security incidents, breaches, and vulnerabilities.
- Conducts post-incident analysis and continuous improvement.
Digital Forensics and Cybersecurity Investigations:
- Collects, processes, preserves, analyzes, and presents digital-related evidence to support vulnerability mitigation and/or investigations.
- Applies tactics, techniques, and procedures to a full range of tools and processes related to administrative, criminal, and counterintelligence gathering.
- Coordinate with law enforcement and emergency services when necessary
Collaboration with Cross-Functional Teams:
- Work closely with IT, HR, facilities management, and other departments to ensure physical security measures are aligned with overall organizational security strategies.
Acts as Global Threat Intelligence Commander:
- Whose primary responsibility is to oversee the collection, analysis, and dissemination of threat intelligence on a global scale, including identifying emerging threats, coordinating intelligence gathering across different regions, and providing actionable insights to decision-makers to proactively mitigate risks and respond to potential incidents.
- Key responsibilities include:
- Overseeing the implementation and maintenance of threat intelligence platforms and tools to effectively collect, analyze, and distribute intelligence data.
- Leading intelligence operations: Manage intelligence sources across regions, including open-source data, human intelligence, and technical sensors.
- Threat analysis: Identify emerging threats, threat actors, TTPs, and their impact on global operations.
- Strategic intelligence production: Develop high-level threat assessments and reports for executive decision-making.
- Share threat intelligence within the organization and with external partners.
- Incident response support: Provide real-time intelligence during security incidents.
- Threat mitigation: Work with security teams on proactive measures, including security controls and training.
- Talent management: Recruit, train, and mentor threat intelligence analysts.
- Technology management: Implement and maintain threat intelligence platforms and tools.
- Staying informed: Monitor evolving threats and adapt strategies accordingly
Key considerations:
- Global perspective: Understanding the geopolitical landscape and how different regions may be impacted by specific threats.
- Data integration: Combining intelligence from diverse sources, including technical, human, and open-source data, to create a holistic picture of threats.
- Communication skills: Effectively communic
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s