Data Security Architect
· Assess the end-to-end architecture from a data security and privacy standpoint.
· Review security controls for GCP Shared VPC, interconnects, service accounts, IAM, and network segmentation.
· Implement Sentinel policies for enforcing encryption standards and data access standards.
· Implement database activity monitoring and blocking rules in GCP.
· Assess AI-specific risks, including prompt/context leakage, model input/output handling, and knowledge store access.
· Produce findings report with risk ratings, gaps, and remediation recommendations.
· Review data flows across:
· GCP service projects
· Virtual agents / conversational AI
· Telephony platforms
· API proxies
· Datastore, BigQuery, Cloud Storage
· On-prem / Amex systems of record
· Identify risks related and implement controls related to:
· Blocking Customer data exposure
· PII handling
· Encryption in transit and at rest
· Secrets and key management, Users and NHI authentication.
· Database activity Logging, monitoring, and auditability
· Data retention and deletion
Required Skills
· Strong experience in cloud security architecture, preferably Google Cloud Platform.
· Hands-on knowledge of:
· GCP IAM
· VPC / Shared VPC
· Cloud Run / GKE
· BigQuery
· Cloud Storage
· Datastore / Firestore
· Cloud KMS / Secret Manager
· Experience assessing data protection controls for PII, PCI, or regulated customer data.
· Knowledge of API security, including OAuth, mTLS, token handling, gateways, and service-to-service authentication.
· Familiarity with network security, private connectivity, firewalls, segmentation, and hybrid cloud interconnects.
· Understanding of logging, SIEM integration, audit trails, and security monitoring.
· Experience with threat modeling and architecture risk reviews.
Preferred Skills
· Experience with conversational AI / virtual agent platforms.
· Knowledge of telephony/SIP integrations and contact center platforms.
· Experience with PCI DSS, NIST, ISO 27001, SOC 2, or financial services security standards.
· Familiarity with AI data governance, model safety, and GenAI security risks.