DAI Consultancy

Data Security Consultant

DAI Consultancy

Doha, Doha Municipality, Qatar · Full Time

Be the first to apply

Experience
4–8 yrs
Salary
Openings
1
Posted
il y a 3 heures
Work mode
In office
Education
Bachelor's degree in cybersecurity or related field
Resume
Required to apply

Where you'll work

Job description

Role Overview

The Data Security Consultant evaluates risks related to data security and aids in designing, executing, and verifying security measures for client data systems, platforms, integrations, and analytical solutions. This role transforms approved requirements concerning security, privacy, and data classification into actionable technical and operational safeguards, covering aspects such as identity management, access controls, encryption, monitoring, incident handling, and system resilience.

The consultant collaborates with security leaders, architects, engineers, platform teams, compliance officers, and client system owners. While they may implement or test authorized controls within client environments, ultimate authority, ownership, and risk responsibility lie with the client. They are tasked with producing clear documentation for requirements, evidence, remediation steps, and handover, as well as articulating technical findings in terms of business impact and operational recommendations.

Primary Responsibilities

  • Conduct assessments of data security risks, threat exposures, control designs, configurations, and operational evidence.
  • Convert security, privacy, and classification mandates into detailed technical and procedural control specifications.
  • Analyze identity, authentication, authorization, role design, privileged access, and segregation of duties.
  • Evaluate encryption methods, key management, secrets handling, secure data transfer, and data masking approaches.
  • Review security measures for APIs, integrations, data pipelines, storage, analytics platforms, and shared datasets.
  • Assess logging, monitoring, alerting systems, vulnerability management, and incident response mechanisms.
  • Assist with security testing, collecting evidence, defect assessment, and confirmation of remediation efforts.
  • Maintain risk records, control matrices, implementation plans, exceptions, and summaries of residual risks.
  • Coordinate security requirements with architecture, engineering, platform, privacy, audit, and operations teams.
  • Support controls relating to backup, recovery, business continuity, and secure disposal of client data.
  • Prepare security guidelines, configuration standards, test evidence, and materials for operational handover.
  • Conduct security walkthroughs and deliver role-based knowledge transfer sessions to client teams.

Qualifications and Experience

  • Bachelor's degree in cybersecurity, computer science, information systems, or a related discipline. Equivalent combinations of relevant education and practical consulting or implementation experience may be considered.
  • Four to eight years of experience in information security, security engineering, or technology risk roles.
  • Demonstrated background in cybersecurity, information security, or related fields with experience assessing or implementing controls for data platforms, cloud services, APIs, or enterprise systems.
  • Knowledge of identity management, encryption, logging, vulnerability management, and incident response processes.
  • Proficiency in documenting findings and effectively communicating remediation priorities to both technical and business audiences.

Technical and Domain Expertise

  • Security assessment, threat identification, and risk analysis.
  • Identity and access management, including privileged-access controls.
  • Encryption technologies, key management, secure data transfer, and data masking techniques.
  • Security of APIs, integrations, data pipelines, platforms, and cloud environments.
  • Capabilities in logging, system monitoring, vulnerability handling, and incident management.
  • Understanding of classification, data privacy, retention policies, and secure disposal procedures.
  • Backup, recovery strategies, system resilience, and business continuity planning.
  • Experience with security evidence collection, testing processes, remediation, and exception tracking.

Core Professional Competencies

  • Expertise in Identity and Access Management (IAM).
  • Risk evaluation and assessment skills.
  • Proficiency in monitoring security environments.
  • Incident response management capabilities.
  • Understanding of secure architecture principles.
  • A strong security mindset and technical judgment.
  • Ability to stay aware of incidents and conduct security discovery and control walkthroughs.
  • Communicating complex technical vulnerabilities in terms of business risks.
  • Producing clear and actionable requirements, findings, and remediation recommendations.
  • Working safely and effectively within controlled, privileged client environments.
  • Collaborating across multidisciplinary teams including security, data, technology, and compliance.
  • Maintaining confidentiality and comprehensive evidence records.
  • Supporting client risk decision-making without assuming risk acceptance authority.

Preferred Certifications

  • CISSP (Certified Information Systems Security Professional) for senior roles.
  • CISM (Certified Information Security Manager).
  • Relevant cloud security certifications.

Focus Areas

  • Security controls
  • Identity and Access Management (IAM)
  • Risk assessment

Work styles they’re looking for

Collaboration Communication Skills Technical Judgment Confidentiality maintenance
🤖
Online · instant AI help