Cybersecurity Specialist
Summary
A Cybersecurity Specialist protects Deep Knowledge Group's digital infrastructure — cloud platforms (Microsoft Azure, Google Workspace, Microsoft 365), websites, email, databases, and AI/automation tools. Day-to-day work covers risk assessments, access control and MFA, threat monitoring, incident response, security documentation, and compliance support (GDPR, ISO 27001).
About the Role
We are looking for a skilled and practical Cybersecurity Specialist to protect our company's digital infrastructure, internal systems, data assets, cloud tools, websites, email accounts, and operational workflows.
The ideal candidate should be able to assess risks, identify vulnerabilities, secure accounts and systems, improve access controls, monitor threats, support compliance, and create clear cybersecurity processes for a growing analytics and technology-driven organization.
Key Responsibilities
Assess the company's cybersecurity risks across internal systems, websites, cloud platforms, email, file storage, databases, and third-party tools.
Implement and manage security best practices for Google Workspace, Microsoft 365, cloud services, websites, CRM systems, databases, automation tools, and internal dashboards.
Set up and maintain strong access control, role-based permissions, password policies, MFA, account recovery procedures, and offboarding processes.
Conduct vulnerability assessments, security audits, and risk reviews.
Monitor potential threats, suspicious activity, unauthorized access attempts, phishing risks, malware, and data exposure.
Support website, application, and infrastructure security, including SSL, DNS security, firewall settings, backups, and server hardening.
Review and improve security for AI tools, automation workflows, API connections, shared documents, and data pipelines.
Create cybersecurity policies, incident response procedures, security checklists, and internal documentation.
Train team members on cybersecurity basics, phishing prevention, password security, data handling, and secure use of AI tools.
Investigate security incidents and prepare remediation plans.
Coordinate with IT, development, operations, legal, compliance, and management teams.
Support compliance with relevant standards such as GDPR, ISO 27001, SOC 2, NIST, CIS Controls, or other applicable frameworks.
Required Skills & Experience
Experience in cybersecurity, information security, IT security, cloud security, security operations, or similar role.
Experience with Microsoft Azure cloud security is required (e.g., Azure AD/Entra ID, Azure Security Center, role-based access control, network security groups, Azure compliance tools).
Strong understanding of cybersecurity fundamentals, including access control, MFA, phishing prevention, endpoint security, network security, vulnerability management, and incident response.
Experience securing business systems such as Google Workspace, Microsoft 365, Slack, Notion, Airtable, CRM platforms, cloud storage, and collaboration tools.
Knowledge of website and application security, including OWASP risks, SSL/TLS, DNS, firewalls, backups, and secure configuration.
Experience with vulnerability scanning, risk assessment, security audits, and remediation planning.
Ability to review user permissions, shared drives, admin access, API keys, integrations, and third-party apps.
Understanding of data protection, privacy, and secure handling of confidential business information.
Ability to write clear security documentation, policies, checklists, and incident reports.
Strong attention to detail and ability to work independently.
Nice to Have
Experience with ISO 27001, SOC 2, GDPR, NIST, CIS Controls, or other security/compliance frameworks.
Experience with endpoint detection and response tools, SIEM platforms, VPNs, firewalls, password managers, MDM tools, and cloud security platforms.
Experience with AWS, Google Cloud, Cloudflare, GitHub, Docker, databases, APIs, and automation platforms.
Experience with penetration testing, red-team/blue-team exercises, phishing simulations, or social engineering defense.
Experience securing AI workflows, LLM tools, automation systems, data pipelines, and research platforms.
Relevant certifications such as Security+, CySA+, CISSP, CISM, CEH, OSCP, ISO 27001 Lead Implementer, Azure Security Engineer Associate (AZ-500), or similar.
Experience with remote teams and international organizations.
Ideal Candidate Profile
The ideal candidate is practical, proactive, and security-minded without being overly bureaucratic. They can quickly identify the biggest risks, prioritize fixes, and implement realistic cybersecurity improvements.
They should be able to protect sensitive data, secure internal operations, educate the team, and build a strong cybersecurity foundation for a company working with analytics, research, AI tools, financial information, and strategic business intelligence.
