Data Security Assessor (GCP-based conversational AI)
Must have
• Candidates with strong hands-on GCP data security, with experience in assessing and implementing encryption, DLP and DAM controls.
• Security assessment of GCP-based conversational AI, telephony, API, and backend integration architecture.
• Strong experience in cloud security architecture, preferably Google Cloud Platform.
• Hands-on knowledge of: GCP IAM/VPC/Shared VPC/Cloud Run/GKE/ BigQuery/ Cloud Storage/ Datastore/ Firestore/ Cloud KMS/ Secret Manager
• Experience assessing data protection controls for PII, PCI, or regulated customer data.
• Understanding of logging, SIEM integration, audit trails, and security monitoring.
• Experience with threat modeling and architecture risk reviews.
Nice to have
• Experience conducting security architecture or application security reviews.
• Understanding of cloud platforms such as Google Cloud.
• Hands-on experience with security automation using Java or Python.
• Knowledge of ERP security models and Segregation of Duties (SoD).
• Familiarity with vulnerability management and risk assessment methodologies.
• Strong analytical, documentation, and communication skills.
• Ability to work effectively with cross-functional business and technical teams.
Roles & Responsibilities
• Review security controls for GCP Shared VPC, interconnects, service accounts, IAM, and network segmentation.
• Implement Sentinel policies for enforcing encryption standards.
• Implement database activity monitoring and blocking rules in GCP.
• Assess AI-specific risks, including prompt/context leakage, model input/output handling, and knowledge store access.
• Produce findings report with risk ratings, gaps, and remediation recommendations.
• Review application architecture, integrations, APIs, and data flows to identify security risks.
• Assess sensitive data handling, including Personally Identifiable Information (PII), financial, payroll, and supplier information.
• Evaluate identity and access management (IAM), role-based access controls (RBAC), segregation of duties (SoD), and privileged access.
• Collaborate with cybersecurity, enterprise architecture, infrastructure, and application teams during project implementation.
• Review encryption standards for data at rest and in transit.
• Assess third-party vendors and cloud solutions for security and compliance requirements.
• Track remediation activities and verify implementation of security recommendations.
• Prepare assessment reports, risk documentation, and executive summaries.
• Support internal and external security audits.
Generic Managerial Skills, If any
• 38+ years of experience in information security, cybersecurity, governance, risk, compliance (GRC), or ERP security.
• Experience with security assessments of SaaS platforms, preferred- Finance, Supply Chain, and Oracle HCM.
• Strong understanding of:
• Identity and Access Management (IAM)
• Data classification
• Encryption technologies
• Authentication and authorization
• Secure SDLC
• Cloud security principles
Salary Range- $100,000-$110,000 a year