Data Security Consultant
Listed on 2026-08-09
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Role Purpose
The Data Security Consultant assesses data-security risks and supports the design, implementation and validation of security controls for client data, platforms, integrations and analytics solutions. The role converts approved security, privacy and classification requirements into practical technical and operational measures covering identity, access, encryption, monitoring, incident response and resilience.
The consultant works alongside security leadership, architects, engineers, platform teams, compliance specialists and client system owners. It may implement or test authorised controls within client environments, but privileged authority, production ownership and risk acceptance remain with the client. The role is expected to produce clear requirements, evidence, remediation guidance and handover documentation, and to communicate technical findings in terms of business exposure and operational action.
Key Responsibilities- Assess data-security risks, threat exposure, control design, configurations and available operational evidence.
- Translate security, privacy and classification requirements into technical and procedural control specifications.
- Review identity, authentication, authorisation, role design, privileged access and segregation of duties.
- Assess encryption, key management, secrets handling, secure transfer and data-masking requirements.
- Review security for APIs, integrations, pipelines, storage, analytics platforms and shared datasets.
- Evaluate logging, monitoring, alerting, vulnerability management and incident-response arrangements.
- Support security testing, evidence collection, defect triage and remediation validation.
- Develop risk records, control matrices, implementation actions, exceptions and residual-risk summaries.
- Coordinate security requirements with architecture, engineering, platform, privacy, audit and operations teams.
- Support backup, recovery, continuity and secure-disposal controls affecting client data.
- Prepare security guidance, configuration standards, test evidence and operational handover material.
- Deliver security walkthroughs and role-based knowledge transfer to client teams.
- Bachelor's degree in cybersecurity, computer science, information systems or a related field.
- An equivalent combination of relevant education and directly applicable consulting or implementation experience may be considered.
- Typically 4-8 years in information security, security engineering or technology risk.
- Experience in cybersecurity, information security, security engineering, technology risk or related roles.
- Experience assessing or implementing controls for data platforms, cloud services, APIs or enterprise systems.
- Experience with identity, encryption, logging, vulnerability management and incident response.
- Experience documenting findings and communicating remediation priorities to technical and business stakeholders.
- Security assessment, threat and risk analysis.
- Identity and access management and privileged-access controls.
- Encryption, key management, secure transfer and data masking.
- API, integration, pipeline, platform and cloud security.
- Logging, monitoring, vulnerability and incident management.
- Classification, privacy, retention and secure-disposal controls.
- Backup, recovery, resilience and continuity safeguards.
- Security evidence, testing, remediation and exception management.
- IAM.
- Risk assessment.
- Monitoring.
- Incident response.
- Secure architecture.
- Security mindset.
- Technical judgement.
- Incident awareness.
- Conducting security discovery and control walkthroughs.
- Explaining technical vulnerabilities in business-impact language.
- Writing clear requirements, findings and remediation guidance.
- Working safely within privileged and controlled client environments.
- Collaborating across security, data, technology and compliance teams.
- Maintaining confidentiality and complete evidence records.
- Supporting client risk decisions without assuming risk-acceptance authority.
- CISSP for senior positions
- CISM
- Relevant cloud-security certification
Security controlsIAMRisk assessment
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).