Search

Data Security Engineer

PublishedPublished: 6/14/2022
Real Estate

Job Description

Security assessment of GCP-based conversational AI, telephony, API, and backend integration architecture.

\n


\n

Responsibilities:

\n


\n

    \n
  • Assess the end-to-end architecture from a data security and privacy standpoint.
  • \n

  • Review security controls for GCP Shared VPC, interconnects, service accounts, IAM, and network segmentation.
  • \n

  • Implement Sentinel policies for enforcing encryption standards and data access standards.
  • \n

  • Implement database activity monitoring and blocking rules in GCP.
  • \n

  • Assess AI-specific risks, including prompt/context leakage, model input/output handling, and knowledge store access.
  • \n

  • Produce findings report with risk ratings, gaps, and remediation recommendations.
  • \n

  • Review data flows across:
  • \n

  • GCP service projects
  • \n

  • Virtual agents / conversational AI
  • \n

  • Telephony platforms
  • \n

  • API proxies
  • \n

  • Datastore, BigQuery, Cloud Storage
  • \n

  • On-prem / Amex systems of record
  • \n

  • Identify risks related and implement controls related to:
  • \n

  • Blocking Customer data exposure
  • \n

  • PII handling
  • \n

  • Encryption in transit and at rest
  • \n

  • Secrets and key management, Users and NHI authentication.
  • \n

  • Database activity Logging, monitoring, and auditability
  • \n

  • Data retention and deletion
  • \n

\n


\n

Required Skills:

\n


\n

    \n
  • Strong experience in cloud security architecture, preferably Google Cloud Platform.
  • \n

  • Hands-on knowledge of:
  • \n

  • GCP IAM
  • \n

  • VPC / Shared VPC
  • \n

  • Cloud Run / GKE
  • \n

  • BigQuery
  • \n

  • Cloud Storage
  • \n

  • Datastore / Firestore
  • \n

  • Cloud KMS / Secret Manager
  • \n

  • Experience assessing data protection controls for PII, PCI, or regulated customer data.
  • \n

  • Knowledge of API security, including OAuth, mTLS, token handling, gateways, and service-to-service authentication.
  • \n

  • Familiarity with network security, private connectivity, firewalls, segmentation, and hybrid cloud interconnects.
  • \n

  • Understanding of logging, SIEM integration, audit trails, and security monitoring.
  • \n

  • Experience with threat modeling and architecture risk reviews.
  • \n

\n


\n

Preferred Skills

\n


\n

    \n
  • Experience with conversational AI / virtual agent platforms.
  • \n

  • Knowledge of telephony/SIP integrations and contact center platforms.
  • \n

  • Experience with PCI DSS, NIST, ISO 27001, SOC 2, or financial services security standards.
  • \n

  • Familiarity with AI data governance, model safety, and GenAI security risks.
  • \n

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...