Role Responsibilities
- Ensure the delivery of information security services to the customer is in compliance with the contract and any applicable standards and regulatory requirements (e.g., PCI, SOX).
- Collaborate with the client in defining and implementing information security policies, strategies, procedures, and configurations to ensure the confidentiality, integrity, and availability of the client’s environment and data.
- Participate with the customer in the strategic design process to translate security and business requirements into processes and systems.
- Evaluate new/emerging security products and technologies and provide recommendations to customer leadership regarding their impact on the organization’s security posture.
- Identify, review, and recommend information security improvements aligned with the customer’s business goals and objectives.
- Manage and drive information security remediation efforts arising from incidents, penetration tests, vulnerability scans, internal/external audits, and Critical Practice assessments.
- Identify information security weaknesses and gaps in the customer’s current operations and work with the customer to bring security operations up to required standards.
- Participate in and represent IT Security during delivery and operational meetings. Conduct information security operational reviews with account leadership and key customer stakeholders, including CISOs, covering security status and performance.
- Review service-management reports to ensure information-security incidents, problems, requests, and changes are acknowledged, handled, and completed within Service-Level Agreements. Provide direction on ticket remediation and ensure completion.
- Conduct an ongoing security-awareness program for NTT DATA personnel supporting the customer, ensuring compliance with relevant information-security obligations. The program should cover appropriate security topics, policies, and supporting documentation.
- Cultivate trusted relationships with account and customer stakeholders and maintain consistent, open communication to uncover issues, challenges, and risks.
- Maintain a forward-looking information-security strategy and roadmap for the customer, aligning services and portfolio components with the strategy.
Required Qualifications
- 12+ years of IT security experience.
- Bilingual fluency in Japanese and English.
Preferences
- Strong knowledge of information-security standards and regulations, including NIST, ISO, and PCI.
- Experience with internal and external information-security audits, contract compliance, and quality initiatives.
- Significant experience identifying and using a global, risk-based management model.
- At least one certification: CISSP, CISM, SSCP, CEH, or CSSLP.
- Undergraduate or graduate degree.
- Senior-level security/consulting experience in a customer-facing role, including customer security relationship management.
- Familiarity with information-security technologies and issues across multiple platforms.
- Experience with network-perimeter security technologies, including firewalls, intrusion detection/prevention systems, and content-filtering technologies.
- Working knowledge of security-monitoring technologies and processes, including monitoring architectures, log aggregation, SOC/SIEM capabilities, and incident response.
- Significant experience applying and integrating globally accepted security standards.