CyberSecurity Consultant
Datamatics Technologies Karachi Division, Sindh, Pakistan
IT Services and IT Consulting · 51-200 employees
About the role
The consultant will translate security baselines into platform control requirements and oversee security design reviews for cloud environments. They are also responsible for defining data handling procedures, managing IAM designs, and coordinating penetration testing activities.
What they look for
Requirements
Candidates must have over 8 years of experience in information security, including at least 3 years in cloud security architecture. A professional certification such as CISSP or CISM is required, along with deep knowledge of GCP security controls and relevant regulatory frameworks.
Full description
Responsibilities
- Translate security baseline and the applicable NCA ECC/CCC controls into platform control requirements, and maintain the control-to-evidence mapping.
- Review and approve the security design: VPC-SC perimeters, organisation policy residency constraints, CMEK key hierarchy and rotation, Secret Manager usage, private connectivity, egress controls.
- Own the data-residency assurance position.
- Define PDPL handling for personal data
- Review IAM design: AD federation, RBAC/ABAC, privileged access management, segregation of duties, break-glass procedure.
- Specify audit logging, retention and SIEM export; verify coverage of data access and change events.
- Prepare for the independent penetration: hardening checklist, pre-test review, and coordination of remediation of critical and high findings before acceptance.
- Conduct security reviews.
Required skills and experience
- 8+ years in information security, with 3+ in cloud security architecture.
- Direct working knowledge of NCA ECC and CCC, PDPL and SDAIA/NDMO requirements.
- GCP security controls in depth: IAM conditions, VPC Service Controls, organisation policy constraints, CMEK/Cloud KMS, Cloud DLP, Assured Workloads concepts, audit logging.
- Data protection technique: classification, masking and tokenisation, row- and column-level security models.
- Experience preparing an environment for third-party penetration testing and closing findings under time pressure.
- Ability to produce compliance evidence that survives a client security function's review.
Certifications
- Required: CISSP or CISM.
- Preferred: Google Cloud Professional Cloud Security Engineer; ISO/IEC 27001 Lead Implementer or Lead Auditor; CDPSE.
Similar roles
-
Teamlead Data & Cybersecurity
Cosun Dinteloord, North Brabant, Netherlands · €56K–€74K/yr
-
Cybersecurity GRC Consultant - Categoria protetta L.68/99
BIP Consulting Palermo, Sicily, Italy · €28K–€34K/yr
-
OT Engineer Cybersecurity
Cosun Dinteloord, North Brabant, Netherlands · €54K–€71K/yr
-
Working Student, Security Engineer
GetYourGuide Zurich, Zurich, Switzerland
-
AI Cybersecurity Researcher
Check Point Software Technologies Tel-Aviv, Tel-Aviv District, Israel
-
Three SG - Apprentice Fire and Security Engineer
Apprenticeships at Skills for Security Castle Point, England, United Kingdom · £17K/yr