- Company Name
- AKKODIS
- Job Title
- Data Security & Privacy Consultant
- Job Description
-
Job title: Data Security & Privacy Consultant
Role Summary: 3–6 month contract to embed privacy and security into product development. Acts as platform administrator, integrates data‑security tools into source code, CI/CD, and engineering workflows, drives data classification, lineage, and retention governance, and champions a shift‑left “privacy by design” model.
Expactations: Deliver actionable security outcomes, reduce non‑production sensitive data exposure, maintain compliance evidence, and provide clear reporting on classification and remediation progress.
Key Responsibilities
- Administer and configure the data security/privacy platform.
- Integrate the platform into source code repositories, CI/CD pipelines, and engineering systems; analyze scan results and triage anomalies with developers.
- Map customer, employee, PII, and sensitive data flows; build and validate classification models; package deliverables for design reviews.
- Champion privacy and security by design; embed checks early in the SDLC; define and enforce guardrails for handling sensitive data.
- Develop and enforce data lifecycle policies: retention, archival, secure deletion, encryption, and access controls across environments.
- Monitor data movement, reduce storage of sensitive data in dev/test logs and backups.
- Collaborate with AppSec, Cloud/Infra Security, and compliance teams; provide reporting on coverage, remediation, and risk trends; support ISO 27001, SOC 2, and NIST Privacy Framework evidence.
Required Skills
- 5+ years in data‑security, privacy engineering, or product‑security roles.
- Hands‑on experience administering data‑classification/privacy platforms and integrating them into engineering workflows.
- Strong technical background with source‑code repos, CI/CD, and scanning tools.
- Deep knowledge of classification, encryption, access control, minimization, retention, and deletion practices.
- Proven ability to embed privacy/security in the SDLC (shift‑left).
- Familiarity with ISO 27001, SOC 2, NIST Privacy Framework.
- Excellent communication and stakeholder alignment skills.
Required Education & Certifications
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Relevant certifications (e.g., CISSP, CISM, ISO 27001 Lead Implementer, or similar) preferred.