- Location
- Karachi, Sindh
- Type
- Full-time
- Department
- Security
- Closing date
- Today
- Source
- ApplyToJob
Description
Responsibilities
- Translate security baseline and the applicable NCA ECC/CCC controls into platform control requirements, and maintain the control-to-evidence mapping.
- Review and approve the security design: VPC-SC perimeters, organisation policy residency constraints, CMEK key hierarchy and rotation, Secret Manager usage, private connectivity, egress controls.
- Own the data-residency assurance position.
- Define PDPL handling for personal data
- Review IAM design: AD federation, RBAC/ABAC, privileged access management, segregation of duties, break-glass procedure.
- Specify audit logging, retention and SIEM export; verify coverage of data access and change events.
- Prepare for the independent penetration: hardening checklist, pre-test review, and coordination of remediation of critical and high findings before acceptance.
- Conduct security reviews.
Required skills and experience
- 8+ years in information security, with 3+ in cloud security architecture.
- Direct working knowledge of NCA ECC and CCC, PDPL and SDAIA/NDMO requirements.
- GCP security controls in depth: IAM conditions, VPC Service Controls, organisation policy constraints, CMEK/Cloud KMS, Cloud DLP, Assured Workloads concepts, audit logging.
- Data protection technique: classification, masking and tokenisation, row- and column-level security models.
- Experience preparing an environment for third-party penetration testing and closing findings under time pressure.
- Ability to produce compliance evidence that survives a client security function's review.
Certifications
- Required: CISSP or CISM.
- Preferred: Google Cloud Professional Cloud Security Engineer; ISO/IEC 27001 Lead Implementer or Lead Auditor; CDPSE.