Job Description
We are seeking a highly skilled Security Assessment Consultant with strong expertise in Google Cloud Platform (GCP) Data Security to conduct security assessments for enterprise applications supporting Finance, Supply Chain, and HCM business functions. The ideal candidate will have hands-on experience implementing and assessing encryption, Data Loss Prevention (DLP), Database Activity Monitoring (DAM), IAM controls, and cloud security architectures. Experience with Oracle Cloud security assessments is preferred but not mandatory.
Must Have Technical/Functional Skills
- Strong hands-on experience with GCP Data Security
- Experience implementing and assessing:
- Encryption controls (data at rest and in transit)
- Data Loss Prevention (DLP)
- Database Activity Monitoring (DAM)
- Data classification and protection controls
- Experience performing Application Security Reviews and Security Architecture Assessments
- Strong understanding of Identity & Access Management (IAM), RBAC, privileged access management, and authentication/authorization
- Experience with cloud security frameworks and risk assessment methodologies
- Hands-on scripting/automation experience using Python or Java
- Experience reviewing APIs, integrations, and enterprise application data flows
- Strong documentation, analytical, stakeholder management, and communication skills
Preferred Skills
- Experience conducting security assessments of Oracle Cloud applications, especially Oracle Fusion ERP, SCM, Finance, and HCM
- Knowledge of Oracle security models, roles, and Segregation of Duties (SoD)
- Experience with Oracle HSM integrations and key management solutions
- Exposure to AWS and Azure security controls
- Experience supporting compliance, audit, and governance initiatives
Roles & Responsibilities
- Conduct security assessments of cloud-hosted Finance, Supply Chain, ERP, and HCM applications.
- Perform detailed reviews of application architecture, APIs, integrations, and data flows to identify security risks.
- Evaluate implementation of:
- Encryption controls
- DLP solutions
- DAM controls
- IAM and privileged access controls
- Assess handling of sensitive data including PII, financial, payroll, supplier, and employee information.
- Review cloud-native security controls within GCP environments.
- Evaluate role-based access controls, Segregation of Duties (SoD), and user provisioning processes.
- Conduct risk assessments and provide remediation recommendations.
- Partner with Cybersecurity, Enterprise Architecture, Infrastructure, and Application teams throughout project lifecycles.
- Assess third-party vendors and SaaS platforms against security and compliance standards.
- Track remediation efforts and validate security control implementation.
- Prepare security assessment reports, risk registers, executive summaries, and audit documentation.
- Support internal and external audits and regulatory reviews.