Data Security Assessor
Job Title: Data Security AssessorLocation: Phoenix, AZ Onsite Duration: Fulltime/PermanentWe are seeking a highly skilled Security Assessment Consultant with strong expertise in Google Cloud Platform (GCP) Data Security to conduct security assessments for enterprise applications supporting Finance, Supply Chain, and HCM business functions. The ideal candidate will have hands-on experience implementing and assessing encryption, Data Loss Prevention (DLP), Database Activity Monitoring (DAM), IAM controls, and cloud security architectures. Experience with Oracle Cloud security assessments is preferred but not mandatory.Must Have Technical/Functional SkillsStrong hands-on experience with GCP Data SecurityExperience implementing and assessing:Encryption controls (data at rest and in transit)Data Loss Prevention (DLP)Database Activity Monitoring (DAM)Data classification and protection controlsExperience performing Application Security Reviews and Security Architecture AssessmentsStrong understanding of Identity & Access Management (IAM), RBAC, privileged access management, and authentication/authorizationExperience with cloud security frameworks and risk assessment methodologiesHands-on scripting/automation experience using Python or JavaExperience reviewing APIs, integrations, and enterprise application data flowsStrong documentation, analytical, stakeholder management, and communication skillsPreferred SkillsExperience conducting security assessments of Oracle Cloud applications, especially Oracle Fusion ERP, SCM, Finance, and HCMKnowledge of Oracle security models, roles, and Segregation of Duties (SoD)Experience with Oracle HSM integrations and key management solutionsExposure to AWS and Azure security controlsExperience supporting compliance, audit, and governance initiativesRoles & ResponsibilitiesConduct security assessments of cloud-hosted Finance, Supply Chain, ERP, and HCM applications.Perform detailed reviews of application architecture, APIs, integrations, and data flows to identify security risks.Evaluate implementation of:Encryption controlsDLP solutionsDAM controlsIAM and privileged access controlsAssess handling of sensitive data including PII, financial, payroll, supplier, and employee information.Review cloud-native security controls within GCP environments.Evaluate role-based access controls, Segregation of Duties (SoD), and user provisioning processes.Conduct risk assessments and provide remediation recommendations.Partner with Cybersecurity, Enterprise Architecture, Infrastructure, and Application teams throughout project lifecycles.Assess third-party vendors and SaaS platforms against security and compliance standards.Track remediation efforts and validate security control implementation.Prepare security assessment reports, risk registers, executive summaries, and audit documentation.Support internal and external audits and regulatory reviews.Generic Managerial Skills, If anyThe Cyber Threat Remediation Analyst serves as the operational coordinator for enterprise threat remediation activities. This role focuses on managing remediation processes, tracking cyber threat findings, facilitating stakeholder engagement, supporting threat applicability assessments, and improving remediation workflows.Unlike traditional Vulnerability Management roles focused primarily on patching activities, this position supports a broader Threat Remediation Program that incorporates insights from Cyber Threat Intelligence, Incident Response, Red Team assessments, penetration testing, security assessments, and other cybersecurity initiatives.This role is ideal for someone who enjoys combining cybersecurity knowledge, stakeholder engagement, process improvement, and program execution to help drive meaningful risk reduction across the enterprise. It goes beyond program tracking by helping evaluate threat applicability, assess organizational exposure, and influence remediation decisions in partnership with cybersecurity subject matter experts.