-
Cybersecurity SME - Incident Response & Threat…
- NTT America, Inc. (Merrifield, VA)
-
**Req ID:** 343177
NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.
We are currently seeking a Cybersecurity SME - Incident Response & Threat Hunting to join our team in Merrifield, Virginia (US-VA), United States (US).
The Cybersecurity Incident Response & Threat Hunting SME leads efforts to mature enterprise-wide detection, response, and threat hunting capabilities, with a focus on cloud-native environments, enterprise systems, networks, applications, containers, services, processes and advanced adversary activity. Acting as a senior advisor, this role directs complex incident response operations, develops detection strategies, and integrates threat intelligence into proactive defense measures. The SME provides strategic oversight to SOC teams, threat analysts, other teams and leadership, ensuring alignment with the organization’s security vision and regulatory requirements.
This position emphasizes proactive identification of sophisticated threats, forensic analysis of security incidents, payloads, and threat actor attack strategies/vectors, and architectural recommendations to improve defense-in-depth strategy and effectiveness. Working across organizational boundaries, the SME advises on detection engineering, automation, and process improvements, while mentoring analysts and guiding threat hunting initiatives. The role is essential to enhancing resilience, closing detection gaps, and driving continuous security posture improvement.
Duties and Responsibilities:
1. Lead advanced incident response operations and provide strategic direction for containment, eradication, and recovery.
1. Direct enterprise-level coordination for high-severity cloud and hybrid incidents.
2. Advise on incident prioritization, escalation, and cross-team communication.
3. Review post-incident findings and recommend remediation and resilience actions
4. Ensure incident response processes align with federal and organizational standards.
2. Oversee proactive threat hunting initiatives to identify advanced adversary tactics and emerging threats.
1. Guide hypothesis-driven hunts leveraging telemetry, behavioral analytics, and threat intel.
2. Recommend detection rule development using frameworks such as MITRE ATT&CK, Sigma, and YARA.
3. Identify anomalous activity and advise on investigative next steps.
4. Integrate findings into detection engineering and security monitoring strategies.
3. Integrate threat intelligence into defensive operations to improve detection, attribution, and prediction.
1. Correlate external and internal intelligence to refine alerting logic.
2. Advise on operationalizing intelligence feeds into SOC workflows.
3. Provide assessments on potential adversary campaigns targeting the enterprise.
4. Recommend adjustments to monitoring and response based on evolving threat landscapes.
4. Direct digital forensics and malware analysis to inform remediation and prevention strategies.
1. Oversee forensic acquisition and analysis of disk, memory, and network data.
2. Interpret artifacts to determine root cause and adversary objectives.
3. Recommend process improvements for evidence handling and analysis workflows.
4. Validate and guide malware reverse engineering efforts for high-impact cases.
5. Recommend enhancements to detection, monitoring, and defensive tooling to close visibility gaps.
1. Evaluate SIEM, EDR, SOAR, and cloud-native security tool configurations for optimization.
2. Advise on automation opportunities for repetitive detection and response activities.
3. Recommend integrations between monitoring platforms and operational workflows.
4. Review performance metrics for deployed defensive technologies and suggest improvements.
6. Maintain and refine incident response and threat hunting documentation and processes.
1. Oversee creation and maintenance of playbooks, SOPs, smart books, TTPs, and escalation workflows.
2. Ensure procedures reflect evolving threats, compliance mandates, and best practices.
3. Recommend and Approve changes to incident categorization, prioritization, and handling protocols.
4. Align documentation with audit and regulatory requirements.
7. Mentor and develop SOC and incident response personnel to strengthen organizational capability.
1. Provide expert guidance during live incidents and tabletop exercises.
2. Advise on analyst skill development and threat hunting methodology.
3. Share lessons learned from incidents to promote continuous improvement.
4. Support recruitment and retention of high-caliber cybersecurity talent.
8. Collaborate across business, technical, and compliance teams to embed security into operations.
1. Partner with IT, cloud engineering, and DevOps teams on security integration.
2. Advise program management and leadership on emerging risks and mitigation strategies.
3. Contribute to cross-functional reviews of architecture changes impacting security.
4. Participate in enterprise planning for security budget and capability roadmaps.
Basic Qualifications:
+ A Master’s degree in any of the following disciplines (Information Technology, Cybersecurity, Data Science, Information Systems, or Computer Science), from an ABET accredited or CAE designated institution fulfills the educational requirement for this WRC.
+ One-and-one half (1.5) years of additional experience can substitute for one (1) year of a typical degree program.
+ Minimum 10 years of experience in Information Technology (IT) / Information Security (IS).
+ DoD 8140 certification for their respective area or the ability to obtain certification within six (6) months of onboarding.
+ Active Secret Security Clearance
Preferred Qualifications:
+ Cyber Defense Analyst advanced certifications:
+ CBROPS
+ CFR, or OSCP
+ CySA+ FITSP-O
+ SANS: GCFA, GCIA, GDSA, GCIH or GICSP
+ Experience in cloud environments (AWS, Azure, GCP) and knowledge of cloud-native security tools.
+ Experience working in a 24x7 Security Operations Center (SOC) or supporting national security/cyber defense missions.
About NTT DATA
NTT DATA is a $30 billion trusted global innovator of business and technology services. We serve 75% of the Fortune Global 100 and are committed to helping clients innovate, optimize and transform for long term success. As a Global Top Employer, we have diverse experts in more than 50 countries and a robust partner ecosystem of established and start-up companies. Our services include business and technology consulting, data and artificial intelligence, industry solutions, as well as the development, implementation and management of applications, infrastructure and connectivity. We are one of the leading providers of digital and AI infrastructure in the world. NTT DATA is a part of NTT Group, which invests over $3.6 billion each year in R&D to help organizations and society move confidently and sustainably into the digital future. Visit us at us.nttdata.com (http://us.nttdata.com/en)
Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us .
_NTT DATA endeavors to make_** **_https://us.nttdata.com_** **_accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at_** **_https://us.nttdata.com/en/contact-us_** **_._** **_This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here (http://us.nttdata.com/en/compliance#eeos) . If you'd like more information on your EEO rights under the law, please click here (http://us.nttdata.com/en/compliance#know-your-rights) . For Pay Transparency information, please click here (http://us.nttdata.com/en/compliance#ppnp) ._
-
Recent Searches
- Hiring Production Operators (California)
- HVAC Refrigeration Tech (Michigan)
- Senior Advanced Analytics Analyst (United States)
- Associate Operator Production 1st (United States)
Recent Jobs
-
Cybersecurity SME - Incident Response & Threat Hunting
- NTT America, Inc. (Merrifield, VA)