Role Overview:This role is for a Data Security Assessor with deep expertise in GCP-based conversational AI. The primary focus is on reviewing and implementing robust security controls across GCP infrastructure, assessing AI-specific risks, and ensuring compliance with sensitive data handling regulations. The assessor will be responsible for identifying security gaps, recommending remediation strategies, and collaborating with various technical and architectural teams throughout project implementations.
Key Responsibilities:- Review security controls for GCP Shared VPC, interconnects, service accounts, IAM, and network segmentation.
- Implement Sentinel policies for enforcing encryption standards.
- Implement database activity monitoring and blocking rules in GCP.
- Assess AI-specific risks, including prompt/context leakage, model input/output handling, and knowledge store access.
- Produce findings reports with risk ratings, gaps, and remediation recommendations.
- Review application architecture, integrations, APIs, and data flows to identify security risks.
- Assess sensitive data handling, including Personally Identifiable Information (PII), financial, payroll, and supplier information.
- Evaluate identity and access management (IAM), role-based access controls (RBAC), segregation of duties (SoD), and privileged access.
- Collaborate with cybersecurity, enterprise architecture, infrastructure, and application teams during project implementation.
- Review encryption standards for data at rest and in transit.
- Assess third-party vendors and cloud solutions for security and compliance requirements.
- Track remediation activities and verify implementation of security recommendations.
- Prepare assessment reports, risk documentation, and executive summaries.
- Support internal and external security audits.
Required Skills:- Strong hands-on GCP data security experience, with expertise in assessing and implementing encryption, DLP, and DAM controls.
- Proficiency in security assessment of GCP-based conversational AI, telephony, API, and backend integration architecture.
- Strong experience in cloud security architecture, preferably Google Cloud Platform.
- Hands-on knowledge of GCP IAM/VPC/Shared VPC/Cloud Run/GKE/BigQuery/Cloud Storage/Datastore/Firestore/Cloud KMS/Secret Manager.
- Experience assessing data protection controls for PII, PCI, or regulated customer data.
- Understanding of logging, SIEM integration, audit trails, and security monitoring.
- Experience with threat modeling and architecture risk reviews.
Qualifications:Preferred Skills:- Experience conducting security architecture or application security reviews.
- Understanding of cloud platforms such as Google Cloud.
- Hands-on experience with security automation using Java or Python.
- Knowledge of ERP security models and Segregation of Duties (SoD).
- Familiarity with vulnerability management and risk assessment methodologies.
- Strong analytical, documentation, and communication skills.
- Ability to work effectively with cross-functional business and technical teams.