CT Automotive
Website:
ct-automotive.net
Job details:
Job Specification — Cloud Data Security Engineer
Department: MetisEI — Platform
Reports to: Lead Developer, MetisEI
Location: Pune
Type: Full time, permanent
Purpose of the Role:
MetisEI runs CT Automotive's factories: production monitoring, scheduling, quality audit systems, HR attendance including biometric identification, supply chain agents, IoT device fleets on the shop floor, WhatsApp-based communications, and a PLM system holding customer CAD and engineering data. The platform spans Azure cloud services, ERP integration (Microsoft Business Central), edge hardware, and mobile interfaces used by hundreds of factory employees across Mexico, China, Turkey, India and the UK.
The Cloud Data Security Engineer owns the security of this estate end to end: cloud infrastructure, data protection, device fleet security, API and integration security, and regulatory compliance for the data classes we hold — including biometric data (sensitive personal data under Mexican LFPDPPP), employee personal data, customer intellectual property (CAD, engineering documents), and commercially sensitive production data for an AIM-listed company. MetisEI is also being prepared for external commercialisation, so the security posture must stand up to enterprise customer due diligence.
Key Responsibilities:
• Own security architecture across the Azure estate: identity and access management, network segmentation, key and secret management, encryption at rest and in transit, logging and monitoring.
• Design and enforce role-based access control across MetisEI applications: shop-floor mobile interfaces, dashboards, PLM document access, HR data — least privilege by default, with individual-level data (pay, attendance, biometrics) restricted per defined policy.
• Secure the IoT/edge fleet (vision camera units, cycle count relay devices): device identity and authentication, no inbound connections, signed OTA updates, fleet monitoring, secure provisioning and decommissioning.
• Secure integrations: Business Central APIs, WhatsApp/Meta Business Platform, HeyGen, carrier/tracking APIs, supplier email automation — credential management, scoping, and third-party risk assessment.
• Own data protection compliance: biometric and employee data under Mexican LFPDPPP and applicable law in other operating countries; retention and deletion policies (e.g. gate photographs, facial recognition templates); documented consent and access records.
• Protect customer IP within the PLM: customer CAD and engineering data segregation, access logging, and defensible evidence of control for customer security audits.
• Build the security development lifecycle with the engineering team: secure coding standards, dependency and vulnerability management, security review gates for new modules, penetration testing programme.
• Incident response: detection, playbooks, and readiness appropriate to a listed company's disclosure obligations.
• Prepare and maintain the security posture for external commercialisation: security documentation, customer due-diligence responses, and progress toward recognised certification (e.g. ISO 27001 / SOC 2) as the commercial plan requires.
Essential Skills & Experience
• Proven experience securing production cloud environments, Azure strongly preferred: Entra ID, network security, Key Vault, Defender/Sentinel or equivalents.
• Data protection engineering experience: encryption, tokenisation, retention/deletion automation, handling of sensitive personal data classes.
• API and integration security: OAuth2/OIDC, secret rotation, third-party service assessment.
• Practical IoT or embedded/edge device security experience, or demonstrable ability to own it.
• Working knowledge of at least one major data protection regime and the ability to operationalise regulatory requirements into engineering controls.
• Scripting/automation competence (Python or PowerShell) — security as code, not policy documents alone.
Desirable:
• ISO 27001 or SOC 2 implementation experience.
• Manufacturing/OT environment exposure and shop-floor network realities.
• Experience supporting enterprise customer security due diligence for a SaaS or platform product.
• Familiarity with Mexican LFPDPPP or Latin American data protection practice.
• Relevant certification (e.g. CISSP, CCSP, Azure Security Engineer) valued but evidence of real systems secured is valued more.
Personal Attributes:
• Enabling mindset: finds the secure way to ship, rather than the reasons not to.
• Rigorous on the things that cannot fail (biometrics, customer IP, credentials); proportionate everywhere else.
• Communicates risk clearly to non-technical leadership and can defend decisions to auditors and customers.
- Comfortable owning security alone initially, building process and tooling from the ground up.
Click on Apply to know more.