Summary
NTT DATA Europe & Latam is seeking an IT Security Business Analyst to support a strategic insurance-sector project focused on enterprise software solutions and integrations. The role analyzes secret and credential management practices, defines security requirements, supports compliant lifecycle processes, and produces audit-ready assessments and governance deliverables.
Responsibilities
- Conduct end-to-end analysis of existing secret and credential management practices across applications, infrastructure, platforms and operational processes
- Identify, classify and document technical and workforce secrets, including ownership, usage, storage location, criticality, lifecycle stage, access model and associated risks
- Assess current-state control weaknesses such as unmanaged SSH keys, hardcoded credentials, shared accounts, undocumented secret usage, insufficient rotation and weak auditability
- Define and document detailed functional and non-functional requirements for centralized secrets management capabilities
- Support the design of compliant lifecycle processes for creation, storage, access, usage, rotation, revocation, emergency access and decommissioning of secrets
- Analyze dependencies across systems, applications, service accounts, technical users and operational teams to support onboarding and migration planning
- Prepare clear and defensible security analysis deliverables, including gap assessments, process documentation, risk assessments, control requirements and remediation recommendations
- Facilitate and document workshops with technical, operational and business stakeholders to gather requirements, validate findings and resolve ambiguities
- Contribute to tool evaluation activities by translating operational and security needs into concrete assessment criteria and use cases
- Validate whether proposed solution approaches meet defined security, compliance and operational expectations
- Support reporting and governance activities by maintaining traceability of findings, risks, requirements, remediation items and implementation dependencies
- Ensure analysis outputs are audit-ready, internally consistent and suitable for decision-making at project and stakeholder governance level
Skills
- Bachelor's degree in Informatics or similar field of study or equivalent working experience is required
- Strong experience in IT security analysis, security requirements engineering, control assessment or security governance in complex enterprise environments
- Proven knowledge of secrets and credential types, including passwords, SSH keys, API keys, tokens, certificates, service accounts and privileged credentials
- Experience in analyzing IT processes, identifying control gaps and translating findings into implementable security requirements
- Strong understanding of IAM, PAM, least privilege, segregation of duties, auditability and secure access governance
- Ability to work across technical and non-technical stakeholder groups and drive structured analysis in ambiguous environments
- Experience in regulated, global or highly controlled environments
- Experience with CyberArk, HashiCorp Vault, Azure Key Vault, AWS Secrets Manager, GCP Secret Manager or similar platforms
- Knowledge of ISO 27001, NIST, CIS Controls or enterprise security governance frameworks
- Experience in transformation or migration projects involving credential centralization and legacy cleanup
- Strong documentation, workshop facilitation and communication skills in English
- Excellent command of both spoken and written English
Qualifications
Must Haves
- Bachelor's degree in Informatics or similar field of study or equivalent working experience is required
- Strong experience in IT security analysis, security requirements engineering, control assessment or security governance in complex enterprise environments
- Proven knowledge of secrets and credential types, including passwords, SSH keys, API keys, tokens, certificates, service accounts and privileged credentials
- Experience in analyzing IT processes, identifying control gaps and translating findings into implementable security requirements
- Strong understanding of IAM, PAM, least privilege, segregation of duties, auditability and secure access governance
- Ability to work across technical and non-technical stakeholder groups and drive structured analysis in ambiguous environments
- Experience in regulated, global or highly controlled environments
- Experience with CyberArk, HashiCorp Vault, Azure Key Vault, AWS Secrets Manager, GCP Secret Manager or similar platforms
- Knowledge of ISO 27001, NIST, CIS Controls or enterprise security governance frameworks
- Experience in transformation or migration projects involving credential centralization and legacy cleanup
- Strong documentation, workshop facilitation and communication skills in English
- Excellent command of both spoken and written English