Security Consultant

Datamatics TechnologiesKarachi, SindhOn-siteFull-timeStaff, 8–12 yearsListed 3 days ago

Apply now

About this role

Responsibilities

- Translate security baseline and the applicable NCA ECC/CCC controls into platform control requirements, and maintain the control-to-evidence mapping.
- Review and approve the security design: VPC-SC perimeters, organisation policy residency constraints, CMEK key hierarchy and rotation, Secret Manager usage, private connectivity, egress controls.
- Own the data-residency assurance position.
- Define PDPL handling for personal data
- Review IAM design: AD federation, RBAC/ABAC, privileged access management, segregation of duties, break-glass procedure.
- Specify audit logging, retention and SIEM export; verify coverage of data access and change events.
- Prepare for the independent penetration: hardening checklist, pre-test review, and coordination of remediation of critical and high findings before acceptance.
- Conduct security reviews.

Required skills and experience

- 8+ years in information security, with 3+ in cloud security architecture.
- Direct working knowledge of  NCA ECC and CCC ,  PDPL  and SDAIA/NDMO requirements.
- GCP security controls in depth: IAM conditions, VPC Service Controls, organisation policy constraints, CMEK/Cloud KMS, Cloud DLP, Assured Workloads concepts, audit logging.
- Data protection technique: classification, masking and tokenisation, row- and column-level security models.
- Experience preparing an environment for third-party penetration testing and closing findings under time pressure.
- Ability to produce compliance evidence that survives a client security function's review.

Certifications

- Required:  CISSP  or  CISM.
- Preferred:  Google Cloud Professional Cloud Security Engineer; ISO/IEC 27001 Lead Implementer or Lead Auditor; CDPSE.