< Back to search
Mott MacDonald • Bengaluru, KA, IN

IT Specialist - Cyber Intelligence

Employment type:  Full time
10

/10

Transparency ranking
Apply now

Job Description

Mott MacDonald is a global engineering, management, and development consultancy committed to delivering impactful work that shapes the future.


We are a team of over 20,000 experts working across the world in more than 50 countries.
We are proud to be part of an ever-changing global industry, delivering transformative work that’s defining our future. It’s our people who power that performance. As an employee-owned business, we invest in creating a space for everyone to feel safe and valued and empowered with the right tools and support.


Whether you want to pursue excellence in your specialism or broaden your experience with flexible roles across our business, you’ll be connected to a community of global experts championing you to be your best. Join us and shape your story with Mott MacDonald, where everyone has the opportunity to be brilliant.

Job Description:

As an IT Specialist in SOC and SIEM, you will play a vital role in strengthening the organisation’s detection and response capabilities. Reporting to the IT Manager – SOC and SIEM, you will deliver technical processes and controls across SOC operations, SIEM optimisation, Vulnerability & Patch Management, Incident Response & Disaster Recovery, and Asset & Threat Discovery.

You will work collaboratively with SOC analysts, IT operations, engineering, and risk teams to ensure rapid detection and timely remediation of security incidents. This role requires strong technical expertise, meticulous attention to detail, and a proactive approach to improving operational resilience.

We are committed to building a diverse, inclusive, and high-performing security function. In this role, you will be supported and empowered to develop your skills, contribute to innovation, and help protect the organisation.

Key Responsibilities

  • Maintain and optimise SIEM platforms for accurate log ingestion, parsing, and correlation.

  • Develop and tune detection rules, dashboards, and automated alerts to improve threat visibility and reduce false positives.

  • Integrate threat intelligence feeds and ensure alignment with frameworks such as MITRE ATT&CK for comprehensive detection coverage.

  • Support SOC operations by improving triage workflows and operational efficiency.

  • Automate vulnerability scanning across endpoints, servers, and cloud workloads; coordinate patch deployment processes with IT teams to minimise exposure windows.

  • Track remediation progress and verify fixes through re-scan and compliance reporting.

  • Assist in developing and maintaining incident response and disaster recovery playbooks for common attack scenarios.

  • Participate in planning and executing tabletop exercises and simulations to validate readiness and response times.

  • Support containment, eradication, and recovery activities during live incidents, providing technical input for root cause analysis and corrective actions.

  • Implement continuous asset discovery tools to maintain an accurate inventory of systems and services; ensure asset data feeds into CMDB and SIEM for correlation and reporting.

  • Deploy threat discovery solutions to identify emerging risks and anomalous behaviours proactively.

  • Maintain accurate records of incidents, vulnerabilities, and remediation status; support audit preparation for Cyber Essentials, ISO 27001, and internal governance reviews.

  • Contribute to the development and update of security policies, standards, and operational procedures.

  • Proactively identify opportunities to improve detection and response workflows and strengthen the organisation’s security posture.

Personal Attributes

  • Demonstrates meticulous attention to detail in all aspects of detection, configuration, and documentation.

  • Applies strong analytical thinking to interpret complex alerts and prioritise effective remediation.

  • Collaborates effectively with colleagues across SOC, IT, engineering, and risk teams, building positive working relationships.

  • Communicates clearly and confidently, adapting technical information for both technical and non-technical audiences.

  • Proactively identifies and acts on opportunities to improve operational resilience and reduce risk.

  • Maintains the highest standards of integrity, confidentiality, and professional conduct at all times.

  • Adapts positively to changing priorities and remains resilient under pressure.

Key Performance Indicators

  • Reduction in Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).

  • Timely closure of vulnerabilities and patch compliance within SLA.

  • Successful completion of incident response and disaster recovery exercises, with improvement in readiness scores.

  • Accuracy of asset inventory and threat discovery coverage.

  • Audit readiness and successful evidence submission.

Candidate Specification

Essential

  • Demonstrable hands-on experience with SIEM platforms and SOC operations within a complex enterprise environment.

  • Strong knowledge of detection engineering, vulnerability management, patching processes, and incident response/disaster recovery frameworks.

  • Practical experience with asset discovery tools, threat detection methodologies, and remediation processes.

  • Experience supporting or preparing for security audits and maintaining compliance evidence.

  • Ability to interpret and apply security policies, standards, and regulatory requirements.

  • Strong problem-solving skills, with the ability to analyse technical issues and recommend effective solutions.

  • Excellent written and verbal communication skills, able to document findings and engage with both technical and non-technical stakeholders.

  • Proven ability to work independently and as part of a team, managing multiple priorities in a fast-paced environment.

Desirable

  • Industry certifications such as CISSP, CCSP, or equivalent.

  • Experience with automation tools, vulnerability scanners, and EDR/XDR platforms.

  • Exposure to frameworks and standards such as MITRE ATT&CK, ISO 27001, NIST CSF.

  • Experience participating in incident response activities and post-incident reviews.

  • Awareness of automation and scripting for security operations.

Flexible working
At Mott MacDonald, we support our staff to create work-life balance which works for them and welcome candidates looking for career flexibility. We are open to discussing flexible working at interview stage.

Our benefits package is designed to enhance your experience:

  • Agile working
  • Critical illness and compassionate leave
  • Paternity Leave
  • Group term life insurance, and Group medical insurance coverage
  • Career mobility options
  • Short and Long-term global employment opportunities
  • Global collaboration and knowledge sharing

Company benefits

Accrued annual leave
Adoption leave – 26 weeks full pay
Annual bonus
Annual pay rises
Bank holiday swaps
Bike parking
Book swaps
Buddy scheme
Buy or sell annual leave
Carer’s leave – up to 5 days, two of which are paid
Compassionate leave
Critical Illness Insurance
Cycle to work scheme
Dental coverage
Employee assistance programme
Employee discounts
Enhanced maternity leave – 26 weeks full pay
Enhanced paternity leave – 2 weeks
Enhanced pension match/contribution – matched up to 7%
Enhanced sick pay
Ergonomic workstations
Eye Care Support – Eyecare vouchers
Faith rooms
Fully stocked snack cupboard
Further education support
Health assessment
In house training
Income protection
L&D budget
Learning platform
Life assurance
Life insurance – 4 x salary
Lunch and learns
Meditation space
Meditation space
Mentoring
Modern office
On-site shower
On-site yoga classes
Open to part time work for some roles
Open to part-time employees
Pregnancy loss leave
Pregnancy support
Private booths
Private GP service – Private Medical care for all UK staff
Professional subscriptions – We pay for your primary professional annual subscription
Referral bonus
Religious celebration leave
Returnship
Salary sacrifice
Share options
Shared parental leave – We match up to 24 weeks full pay
Study support
Tax-free childcare
Teambuilding days
Theme park discounts
Travel loan
Women’s health leave
Reservist leave – 10 days leave

Working at Mott MacDonald

Company employees:

18,000 worldwide

Gender diversity (m:f:n-b):

0:35:65

Hiring in countries

Australia

Bulgaria

Canada

Czechia

France

Germany

Hong Kong

India

Indonesia

Ireland

Italy

Japan

Malaysia

New Zealand

Singapore

South Korea

Spain

Taiwan

Thailand

United Arab Emirates

United Kingdom

United States

Office Locations

Awards & Accreditations

2nd – Career Progression

2nd – Career Progression

Flexa awards 2025
3rd – Family Friendly

3rd – Family Friendly

Flexa awards 2025
Work-Life Balance

Work-Life Balance

Flexa awards 2025
Flexible

Flexible

Flexa awards 2025
Culture

Culture

Flexa awards 2025

Other jobs you might like