Cyber Security Incident Handler and Threat Hunter

2 weeks ago


Bucharest, Bucureşti, Romania NTT DATA North America Full time €60,000 - €80,000 per year

NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now At NTT DATA we know that with the right people on board, anything is possible. The quality, integrity, and commitment of our employees have been key factors in our company's growth and market presence. By hiring the best people and helping them grow both professionally and personally, we ensure a bright future for NTT DATA Services and for the people who work here.

Overview
NTT DATA is seeking a dynamic and detail-oriented Cyber Security Incident Handler to join our Computer Security Incident Response Team (CSIRT). You will respond to security incidents and threats in accordance with OIS policies and standards, with the goal of reducing risk while supporting NTT DATA's global business operations. In this role, you will be at the forefront of our global incident response operations, performing rapid triage, forensic analysis, and proactive threat hunting across diverse environments. Utilizing cutting-edge tools, you will collaborate closely with business stakeholders to manage security incidents and neutralize threats to our systems and data. Whether addressing routine alerts or high-profile, nation-state attacks, your expertise will be crucial in safeguarding our digital infrastructure and driving the continuous improvement of our IT security posture, thereby reducing risk to NTT DATA and its customers.

Job Responsibilities Include:

  • Handle the entire incident response lifecycle by conducting initial triage, performing detailed analysis of security alerts, and executing actions such as live response, containment, and escalation until the incident is resolved.
  • Serve as an incident coordinator by operating security tools, ingesting incident data, tracking incident status, coordinating with internal and external teams, and promptly responding to customer queries and requests related to security events.
  • Manage incident handling procedures across Windows, Mac, and Linux platforms, ensuring effective containment and remediation.
  • Adapt and document procedures for security operations and incident response, ensuring efficient tactical process development tailored to specific incident requirements.
  • Conduct digital forensic investigations using industry-standard tools (e.g., Falcon, X-Ways).
  • Proactively hunt for threats in SIEM and other security platforms by analyzing log files, network telemetry, and digital artifacts to detect indicators of compromise.
  • Perform basic malware analysis to identify and understand malicious activities.
  • Develop, refine, and maintain incident response playbooks, runbooks, and technical documentation.
  • Integrate threat intelligence with forensic findings to build a comprehensive understanding of emerging attacker tactics and context.
  • Collaborate with cross-functional teams, providing mentorship and expert guidance during high-pressure incidents and on-call rotations.
  • Participate in on-call rotation support, including weekends, holidays, and after-business hours as required to meet business needs.

Basic Qualifications:

  • 2+ years of hands-on experience in Cybersecurity, Incident Response, Digital Forensics, Threat Hunting, or similar technical roles.
  • Proficiency with SOC workflows, including threat hunting, detection, response, and threat intelligence.
  • Strong understanding of Windows, and Unix-like operating systems, as well as enterprise authentication technologies (e.g., Active Directory, Entra ID; Okta - nice to have).
  • Experience with endpoint, identity, cloud application, infrastructure, email, network, and other threat detection and prevention technologies, along with a comprehensive background in network, host, and application security.
  • Experience in network security monitoring and IT operations, including familiarity with firewalls, proxies, IDS/IPS, WAFs, and other common network protocols and services.
  • Great analytical skills with meticulous attention to detail, problem solver with an investigative mindset and with a curious, proactive approach to learning and adapting to evolving threats and technologies.
  • Engaged teamplayer with strong written and oral communication skills (fluency in English).
  • Willingness to work non-standard hours, including evenings, weekends, and occasional travel (although the job is fully remote and Romanian business hours based).

Preferred Skills:

  • Experience with cloud forensics and investigating incidents in Azure and AWS cloud platforms.
  • Demonstrated ability in scripting or programming (e.g., Python, PowerShell, Bash) for workflow automation and analysis.
  • Exposure to advanced malware analysis and remediation strategies for targeted attacks.
  • Degree in Cybersecurity, Information Systems, Computer Science, or a related field, or has equivalent relevant professional experience. (Recent graduates are encouraged to apply as well.)
  • Any security certification (e.g., GIAC, OSCP, CEH, CCFR).
  • Demonstrated thought leadership through published research, industry presentations, or active community engagement.

About NTT DATA
NTT DATA is a $30 billion trusted global innovator of business and technology services. We serve 75% of the Fortune Global 100 and are committed to helping clients innovate, optimize and transform for long term success. As a Global Top Employer, we have diverse experts in more than 50 countries and a robust partner ecosystem of established and start-up companies. Our services include business and technology consulting, data and artificial intelligence, industry solutions, as well as the development, implementation and management of applications, infrastructure and connectivity. We are one of the leading providers of digital and AI infrastructure in the world. NTT DATA is a part of NTT Group, which invests over $3.6 billion each year in R&D to help organizations and society move confidently and sustainably into the digital future. Visit us at

NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here . If you'd like more information on your EEO rights under the law, please click here . For Pay Transparency information, please click here .


  • Cyber Threat Hunter

    2 weeks ago


    Bucharest, Bucureşti, Romania Dell Technologies Full time $125,000 - $175,000 per year

    Cyber Threat Hunter ConsultantThe Dell Security & Resiliency organization manages the security risk across all aspects of Dell's business. You will have an excellent opportunity to influence the security culture at Dell and further develop your career. Join us as a senior Cyber Threat Hunter on our Cyber Threat Intelligence team in Bucharest to do the best...


  • Bucharest, Bucureşti, Romania Worldline Full time €60,000 - €80,000 per year

    Job DescriptionCyber Security EngineerBucharest, RomaniaThis is Worldline.We are the innovators at the heart of the payments technology industry, shaping how the world pays and gets paid. The solutions our people build today power the growth of millions of businesses tomorrow. From your local coffee shop to unicorns and international banks. From San...


  • Bucharest, Bucureşti, Romania Worldline Full time €104,000 - €130,878 per year

    This is Worldline.Worldline helps businesses of all shapes and sizes to accelerate their growth journey - quickly, simply, and securely. We are the innovators at the heart of the payments technology industry, shaping how the world pays and gets paid. Our technology powers the growth of millions of businesses across 5 continents. And just as we help our...


  • Bucharest, Bucureşti, Romania Innoviz Technologies Full time €90,000 - €120,000 per year

    Innoviz Technologies is shaping the future of autonomous driving with our cutting-edge LiDAR systems – among the most advanced sensors in the automotive industry. Our technology brings together expertise in hardware and software to deliver breakthrough solutions for safety and reliability. We're looking for a Cyber Security Architect to drive the security...


  • Bucharest, Bucureşti, Romania Innoviz Technologies Full time 60,000 - 80,000 per year

    DescriptionInnoviz Technologies is shaping the future of autonomous driving with our cutting-edge LiDAR systems – among the most advanced sensors in the automotive industry. Our technology brings together expertise in hardware and software to deliver breakthrough solutions for safety and reliability.We're looking for aCyber Security Architectto drive the...


  • Bucharest, Bucureşti, Romania Orange Full time €104,000 - €130,878 per year

    Locul de muncă: BucharestHow would you like to work in IT & Communication, toying with cutting edge technologies and enjoying your life? Come closer to #LifeAtOrange.What we're looking forWe are looking for a Security Incident Operations Analyst to join our Information Security department. The right candidate is analytical, responsive, and committed to...


  • Bucharest, Bucureşti, Romania ManpowerGroup Full time €104,000 - €130,878 per year

    Manpower Romania, technical & engineering division is curently looking for aCyber Security Managerfor one of our clients located in Bucharest.In this role, you will drive the development and implementation of the cybersecurity strategy, manage key security resources, and ensure alignment with organizational objectives. You will act as a leader, mentor, and...


  • Bucharest, Bucureşti, Romania Inetum Full time €40,000 - €80,000 per year

    Managing Cyber Security projects (planning, architecture, deployment and maintenance). Develop and implement cybersecurity strategies, policies, and procedures to safeguard company systems and data. Ensure compliance with relevant industry standards, regulations, and legal requirements. Design and implement appropriate security controls and measures to...


  • Bucharest, Bucureşti, Romania JT International S.A. Full time €90,000 - €120,000 per year

    At JTI we celebrate differences, and everyone truly belongs. 46,000 people from all over the world are continuously building their unique success story with us. 83% of employees feel happy working at JTI.To make a difference with us, all you need to do is bring your human best.What will your story be? Apply now  Learn more: Cyber Security DevOps...


  • Bucharest, Bucureşti, Romania JTI Full time €90,000 - €120,000 per year

    At JTI we celebrate differences, and everyone truly belongs.46,000 people from all over the worldare continuously building their unique success story with us.83% of employees feel happyworking at JTI.To make a difference with us, all you need to do is bring yourhuman best.What will your story be? Apply nowLearn more Cyber Security DevOps ManagerWhat This...