Security Consultant

Location
Karachi
Workplace
On-site

About this role

Responsibilities

  • Translate security baseline and the applicable NCA ECC/CCC controls into platform control requirements, and maintain the control-to-evidence mapping.
  • Review and approve the security design: VPC-SC perimeters, organisation policy residency constraints, CMEK key hierarchy and rotation, Secret Manager usage, private connectivity, egress controls.
  • Own the data-residency assurance position.
  • Define PDPL handling for personal data
  • Review IAM design: AD federation, RBAC/ABAC, privileged access management, segregation of duties, break-glass procedure.
  • Specify audit logging, retention and SIEM export; verify coverage of data access and change events.
  • Prepare for the independent penetration: hardening checklist, pre-test review, and coordination of remediation of critical and high findings before acceptance.
  • Conduct security reviews.

Required skills and experience

  • 8+ years in information security, with 3+ in cloud security architecture.
  • Direct working knowledge of NCA ECC and CCCPDPL and SDAIA/NDMO requirements.
  • GCP security controls in depth: IAM conditions, VPC Service Controls, organisation policy constraints, CMEK/Cloud KMS, Cloud DLP, Assured Workloads concepts, audit logging.
  • Data protection technique: classification, masking and tokenisation, row- and column-level security models.
  • Experience preparing an environment for third-party penetration testing and closing findings under time pressure.
  • Ability to produce compliance evidence that survives a client security function's review.

Certifications

  • Required: CISSP or CISM.
  • Preferred: Google Cloud Professional Cloud Security Engineer; ISO/IEC 27001 Lead Implementer or Lead Auditor; CDPSE.

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?