Hiring.Camp

Security Consultant

Nttlimited

·

Today

Location
Petaling Jaya, Malaysia
Type
Full-time
Department
Security
Source
Workday

Description

Make an impact with NTT DATA
Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.

1.1. Role purpose

The Security Consultant leads the practice’s cyber resilience and security advisory portfolio. The role shapes and delivers security assessments, cyber recovery and minimum viable company (MVC) advisory engagements, and security architecture workstreams within broader infrastructure programs, helping regulated clients withstand, respond to, and recover from destructive cyber events.

1.2. Key responsibilities

  • Works on strategic engagements that ensure the efficient and effective reaction to security breaches to mitigate immediate and potential threats.
  • Uses mitigation, preparedness, response, and recovery approaches to minimize business disruptions and commercial consequences.
  • Shapes and scopes security advisory opportunities, including cyber resilience assessments, minimum viable company definition, cyber recovery design, and security posture assessments.
  • Develops proposals and statements of work with clearly defined methodology stages, deliverables, stakeholder models, and acceptance criteria.
  • Leads security and resilience assessments using recognized frameworks (NIST CSF, CIS Controls, ISO/IEC 27001) and regulatory baselines (BNM RMiT, MAS TRM, NACSA/NCII requirements, PDPA).
  • Conducts regular threat and vulnerability assessments and determines deviations from acceptable configurations or policies.
  • Participates in the assessment of the level of risk and supports the development of appropriate mitigation countermeasures in operational and non-operational situations.
  • Defines minimum viable company scope for clients by identifying critical business services, mapping supporting applications and infrastructure, and establishing recovery priorities and dependencies.
  • Designs cyber recovery architectures, including isolated recovery environments, cleanroom recovery, immutable vaulting, and recovery validation processes.
  • Leads data protection and resilience assessments (ransomware recovery readiness) and supports the design and build of disaster recovery sites and cyber resilience third sites.
  • Develops business impact analyses (BIA), business continuity plans (BCP), disaster recovery plans (DRP), and cyber incident recovery plans (CIRP/CRP).
  • Develops incident response and recovery playbooks and designs and facilitates tabletop exercises with client executive and technical teams.
  • Participates in the implementation of policies, processes, and guidelines to ensure the standardization of security management throughout client organizations.
  • Advises on security architecture within infrastructure programs, including network segmentation and micro segmentation, identity and privileged access management, endpoint and workload protection, and security monitoring integration.
  • Presents security findings and recommendations to CISO-level and board-level audiences.

1.3. To thrive in this role, you need to have

  • Excellent verbal and written communication skills are a must, including confident presentation to IT management and C-level audiences
  • Proven ability to gather business requirements and translate them into technical requirements
  • Proven ability to translate technical requirements into a compelling solution proposal
  • A solution-centric rather than product-centric mindset, recommending the approach that best meets the client’s requirements
  • Strong document authoring capability, covering assessment reports, proposal documents, requirements documents, and solution specifications
  • Proven ability to conduct workshops and stakeholder interviews, gather and structure information, and produce assessment reports and findings from raw data such as logs, configurations, and inventory
  • Strong understanding of information technology and information security
  • Solid understanding of security risks and preventative controls
  • Excellent understanding of security operational processes and controls
  • Good knowledge of security frameworks and standards such as NIST, ISO/IEC 27001, and CIS
  • Good ability to assess and manage cybersecurity risks at both organisational and project levels
  • Strong understanding of cyber resilience and recovery concepts, including business impact analysis, recovery objectives, immutability, air-gapped vaulting, and clean recovery
  • Service consulting aptitude, focusing on the business, service, and sales aspects
  • Ability to translate technical risk into business language and defensible recommendations
  • Up-to-date knowledge of security threats, countermeasures, security tools, and network technologies
  • High level of drive and the ability to work under pressure
  • Ability to build and maintain cross-functional relationships with a variety of stakeholders
  • Understanding of relevant laws, regulations, and compliance frameworks affecting regulated industries in ASEAN, including BNM RMiT, MAS TRM, and PDPA

1.4. Academic qualifications and certifications

  • Bachelor’s degree or diploma, or equivalent, in Information Technology, Computer Science, Engineering, or a related field.
  • Industry relevant certifications such as CISSP, CISM, or CISA essential.
  • CRISC, SABSA, ISO/IEC 27001 Lead Auditor/Lead Implementer, CCSP, vendor certifications (Palo Alto Networks PCNSE, Fortinet NSE 4+), and business continuity certifications (CBCP, ISO 22301) advantageous.

1.5. Desirable experience

The following experience is advantageous rather than mandatory:

  • Demonstrable experience in the information security industry, with substantial experience in security consulting or advisory roles, ideally serving financial services or other regulated industries.
  • Experience with security architecture design principles.
  • Experience with industry compliance and standards such as ISO/IEC 27001, NIST, BNM RMiT, MAS TRM, and PDPA, including support for audit or regulator interactions.
  • Experience leading security maturity or gap assessments and presenting findings to senior stakeholders.
  • Experience with enterprise security technologies, including next-generation firewalls (Palo Alto Networks, Fortinet, Check Point), SIEM/SOAR, EDR/XDR, PAM/IAM, and data protection controls.

Workplace type:


About NTT DATA
NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune

Global 100. We are committed to accelerating client success and positively impacting society through

responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with

unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and

application services. Our consulting and industry solutions help organizations and society move

confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more

than 70 countries. We also offer clients access to a robust ecosystem of innovation centers as well as

established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each

year in R&D.


Equal Opportunity Employer
NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.


Third parties fraudulently posing as NTT DATA recruiters 

NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters whether in writing or by phone in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @nttdata.com email address. If you suspect any fraudulent activity, please contact us.

Skills

CybersecuritySIEMComplianceCISSP

Similar Jobs

30

Consultant, Security

Aurecongroup · Singapore · Hybrid

2 days ago

Security Consultant

Eurofins Scientific · Bogotá, Bogota, Colombia

1 week ago

Consultant - Security

WSP · Bengaluru, Karnataka, India

1 week ago

Security Consultant

M&G · Edinburgh, United Kingdom +1

2 weeks ago

Security Consultant

GHD · CHANTILLY, VA, United States, US

1 month ago

Security Consultant

Nttlimited · Prague, Czech Republic, Czechia · Hybrid

1 month ago

Security Consultant

Nttlimited · Mumbai, India +2 · Hybrid

2 months ago

Security Consultant

Zeus Fire and Security · Overland, MO, US

2 months ago

Security Consultant

Version 1 · London, Birmingham, Manchester, Newcastle upon Tyne, Edinburgh, Belfast, England, United Kingdom · Hybrid

2 months ago

Security Consultant

Ericsson · SG

2 months ago

Security Consultant

Endava · Bucharest, Bucharest, Romania · Hybrid

4 months ago

Security Consultant

Nttlimited · Ho Chi Minh, Vietnam +1

5 months ago

Security Consultant

AppGate · Mexico DF, MX, Mexico

9 months ago

Security Consultant

Verisure · UK - North West London Branch, United Kingdom

1+ year ago

Security Consultant

Verisure · UK - North West London Branch, United Kingdom

1+ year ago

Security Consultant

OB1 Security & Surveillance · Houston, TX, United States

1+ year ago

Security Consultant

IPsoft Inc. · Dallas, TX, United States

1+ year ago

SAP HANA Security Consultant

Robert Bosch · coimbatore, India

Today

SAP Security Consultant

TELUS Digital · Noida · Hybrid

Today

Sr Advisory Solution Consultant– Security, Identity & Exposure Management (Armis/Veza) West Coast

ServiceNow · Omaha, Nebraska, United States · Remote

Today

Sr Advisory Solution Consultant– Security, Identity & Exposure Management (Armis/Veza) West Coast

ServiceNow · Minneapolis, Minnesota, United States · Remote

Today

Sr Advisory Solution Consultant– Security, Identity & Exposure Management (Armis/Veza) West Coast

ServiceNow · Des Moines, Iowa, United States · Remote

Today

Sr Advisory Solution Consultant– Security, Identity & Exposure Management (Armis/Veza) West Coast

ServiceNow · Kansas City, Missouri, United States · Remote

Today

Sr Advisory Solution Consultant– Security, Identity & Exposure Management (Armis/Veza) West Coast

ServiceNow · Phoenix, Arizona, United States · Remote

Today

Sr Advisory Solution Consultant– Security, Identity & Exposure Management (Armis/Veza) West Coast

ServiceNow · Denver, Colorado, United States · Remote

Today

Sr Advisory Solution Consultant– Security, Identity & Exposure Management (Armis/Veza) West Coast

ServiceNow · San Francisco, CALIFORNIA, United States · Remote

Today

Sr Advisory Solution Consultant– Security, Identity & Exposure Management (Armis/Veza) West Coast

ServiceNow · Los Angeles, CALIFORNIA, United States · Remote

Today

SAP S/4HANA Security Consultant (Security Weaver / Pathlock) - REMOTE

Freelancer Career · Hyderabad

Yesterday

Senior Network & Security Consultant

Malleum · Ottawa, ON · Remote, Hybrid, Onsite

Yesterday

Security Consultant – Architect - Financial Services

Accenture · London, 30 Fenchurch Street, United Kingdom

Yesterday
Security Consultant at Nttlimited | Hiring.Camp