Datamatics Technologies

CyberSecurity Consultant

Datamatics Technologies Karachi Division, Sindh, Pakistan

IT Services and IT Consulting · 51-200 employees

Yesterday
security Senior (5-10 yrs) Full-time Pakistan
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The consultant will translate security baselines into platform control requirements and oversee security design reviews for cloud environments. They are also responsible for defining data handling procedures, managing IAM designs, and coordinating penetration testing activities.

What they look for

Cloud Security Architecture NCA ECC NCA CCC PDPL GCP Security IAM VPC Service Controls CMEK Cloud KMS Cloud DLP Assured Workloads Data Protection Penetration Testing Compliance Evidence CISSP CISM

Requirements

Candidates must have over 8 years of experience in information security, including at least 3 years in cloud security architecture. A professional certification such as CISSP or CISM is required, along with deep knowledge of GCP security controls and relevant regulatory frameworks.

Full description

Responsibilities

  • Translate security baseline and the applicable NCA ECC/CCC controls into platform control requirements, and maintain the control-to-evidence mapping.
  • Review and approve the security design: VPC-SC perimeters, organisation policy residency constraints, CMEK key hierarchy and rotation, Secret Manager usage, private connectivity, egress controls.
  • Own the data-residency assurance position.
  • Define PDPL handling for personal data
  • Review IAM design: AD federation, RBAC/ABAC, privileged access management, segregation of duties, break-glass procedure.
  • Specify audit logging, retention and SIEM export; verify coverage of data access and change events.
  • Prepare for the independent penetration: hardening checklist, pre-test review, and coordination of remediation of critical and high findings before acceptance.
  • Conduct security reviews.

Required skills and experience

  • 8+ years in information security, with 3+ in cloud security architecture.
  • Direct working knowledge of NCA ECC and CCC, PDPL and SDAIA/NDMO requirements.
  • GCP security controls in depth: IAM conditions, VPC Service Controls, organisation policy constraints, CMEK/Cloud KMS, Cloud DLP, Assured Workloads concepts, audit logging.
  • Data protection technique: classification, masking and tokenisation, row- and column-level security models.
  • Experience preparing an environment for third-party penetration testing and closing findings under time pressure.
  • Ability to produce compliance evidence that survives a client security function's review.

Certifications

  • Required: CISSP or CISM.
  • Preferred: Google Cloud Professional Cloud Security Engineer; ISO/IEC 27001 Lead Implementer or Lead Auditor; CDPSE.

Similar roles