Role Overview:This role focuses on conducting comprehensive data security assessments for various applications and projects, including Finance, Supply Chain, and Human Capital Management (HCM). The successful candidate will be responsible for reviewing application architecture, integrations, APIs, and data flows to identify security risks, assessing sensitive data handling, and evaluating identity and access management controls. Collaboration with cross-functional teams and supporting security audits are also key aspects of this position.
Key Responsibilities:- Conduct data security assessments for Finance, Supply Chain, and HCM applications and projects.
- Review application architecture, integrations, APIs, and data flows to identify security risks.
- Assess sensitive data handling, including Personally Identifiable Information (PII), financial, payroll, and supplier information.
- Evaluate identity and access management (IAM), role-based access controls (RBAC), segregation of duties (SoD), and privileged access.
- Collaborate with cybersecurity, enterprise architecture, infrastructure, and application teams during project implementation.
- Review encryption standards for data at rest and in transit.
- Assess third-party vendors and cloud solutions for security and compliance requirements.
- Track remediation activities and verify implementation of security recommendations.
- Prepare assessment reports, risk documentation, and executive summaries.
- Support internal and external security audits.
Required Skills:- Experience conducting security architecture or application security reviews.
- Understanding of cloud platforms such as AWS, Azure, or Google Cloud.
- Hands-on experience with security automation using Java or Python.
- Knowledge of ERP security models and Segregation of Duties (SoD).
- Familiarity with vulnerability management and risk assessment methodologies.
- Strong analytical, documentation, and communication skills.
- Ability to work effectively with cross-functional business and technical teams.
- Strong understanding of Identity and Access Management (IAM).
- Strong understanding of Data classification.
- Strong understanding of Encryption technologies.
- Strong understanding of Authentication and authorization.
- Strong understanding of Secure SDLC.
- Strong understanding of Cloud security principles.
Qualifications:- Bachelor's degree in computer science, Information Security, Information Systems, or a related field.
- 3-8+ years of experience in information security, cybersecurity, governance, risk, compliance (GRC), or ERP security.
- Experience with security assessments of SaaS platforms, preferred- Finance, Supply Chain, and Oracle HCM.
Preferred Skills:- Oracle HSM integrations
- Application security reviews
- GCP
- IAM