Data Security Engineer
atosPhoenix (AZ)
About the role
Security assessment of GCP-based conversational AI, telephony, API, and backend integration architecture.
Responsibilities:
Assess the end-to-end architecture from a data security and privacy standpoint. Review security controls for GCP Shared VPC, interconnects, service accounts, IAM, and network segmentation. Implement Sentinel policies for enforcing encryption standards and data access standards. Implement database activity monitoring and blocking rules in GCP.Assess AI-specific risks, including prompt/context leakage, model input/output handling, and knowledge store access. Produce findings report with risk ratings, gaps, and remediation recommendations. Review data flows across: GCP service projects Virtual agents / conversational AITelephony platformsAPI proxies Datastore, Big Query, Cloud Storage On-prem / Amex systems of record Identify risks related and implement controls related to: Blocking Customer data exposurePII handling Encryption in transit and at rest Secrets and key management, Users and NHI authentication. Database activity Logging, monitoring, and auditability Data retention and deletion
Required Skills:
Strong experience in cloud security architecture, preferably Google Cloud Platform. Hands-on knowledge of: GCP IAMVPC / Shared VPCCloud Run / GKEBig Query Cloud Storage Datastore / Firestore Cloud KMS / Secret Manager Experience assessing data protection controls for PII, PCI, or regulated customer data. Knowledge of API security, including OAuth, mTLS, token handling, gateways, and service-to-service authentication. Familiarity with network security, private connectivity, firewalls, segmentation, and hybrid cloud interconnects. Understanding of logging, SIEM integration, audit trails, and security monitoring. Experience with threat modeling and architecture risk reviews.
Preferred Skills:
Experience with conversational AI / virtual agent platforms. Knowledge of telephony/SIP integrations and contact center platforms. Experience with PCI DSS, NIST, ISO 27001, SOC 2, or financial services security standards. Familiarity with AI data governance, model safety, and GenAI security risks.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
