Job Description
Responsible for advanced planning, design and build of security systems, applications, environments and architectures; oversees the implementation of security systems, applications, environments and architectures and ensures compliance with information security standards and corporate security policies and procedures.
Provides technical advice and direction to support the design and development of secure architectures.
May participate in an incident management team, bringing advanced-level skills to respond to security events in line with Oracle incident response playbooks. Investigates purported intrusions and breaches, and oversees root cause analysis. Coordinates incidents with other business units and may act as Incident Commander of serious incidents. Develops new methods, and playbooks, as well as sophisticated scripts, applications, and tools, and trains others in their use.
May participate in an incident management team, responding to security events in line with Oracle incident response playbooks. Investigates purported intrusions and breaches, and oversees root cause analysis. Coordinates incidents with other business units and may act as incident commander of serious incidents. Participates in developing new methods, playbooks throughout Oracle.
Evaluates existing and proposed technical architectures for security risk, provides technical advice to support the design and development of secure architectures and recommends security controls to mitigate those risks. Evaluations of internal security architecture may include design assessment, risk assessment, and threat modeling.
Brings advanced-level skills to research, evaluate, track, and manage information security threats and vulnerabilities in situations where in-depth analysis of ambiguous information is required, and where computer programming/scripting knowledge is required.
Work with Senior management to develop and implement a multi-year security roadmap
Focus on operational and strategic level tasks, and provide counsel and guidance to the junior level security operations engineers in the department.
Minimum of 8 years related experience in an information security role supporting security programs and security engineering/architecture in complex enterprise environments. Hands on experience with enterprise security architecture, engineering and implementation required.
Knowledge of compliance program security controls, like ISO 27001, SOC 2, HITRUST, and FedRAMP, as applied to cloud SaaS, PaaS and IaaS operations.
Familiarity with SDLC principles and scripting & programming languages (such as Terraform, Python, and Ruby).
Strong knowledge of: Cloud architecture and security principles. Risk Management Frameworks. *nix and Windows system administration.
Experience with: Logging and log analysis. Identity management principles and technology.
Preferred but not required qualifications include:
Bachelor-level university degree in a relevant field from an accredited university, or equivalent.
Strong knowledge of web technologies, middleware, database, OS, firewalls, network communication protocols and methods.
Knowledge of database security principles.
Knowledge of encryption technologies and architectures.
Expert level experience in evaluating and assessing security threats across a variety of environments and industries.
Expert level understanding of secure networking principles, routers, switches and load balancers.
If you are a Colorado resident, Please Contact us or Email us at [email protected] to receive compensation and benefits information for this role. Please include this Job ID: 142519 in the subject line of the email.
Responsibilities
The OCI Product Security team is responsible for making sure we deliver the highest level of security for Oracle customers of any cloud environment. Our scope includes the cloud platform itself, as well as the growing list of 175+ services and products within the core OCI catalog. We work in partnership with product service teams to deliver robust, trustworthy cloud services and applications.
This is a role for someone who loves to dive in and rapidly gain a deep understanding of software vulnerabilities and design remediation plans that scale across multiple use cases. This is a role for someone who loves to help others, solve problems, make big security improvements, and loves moving between a diverse set of technical challenges.If you enjoy challenging yourself and want to learn and build the future of cloud – Join us!
Responsibilities
• Assess, prioritize and communicate risks and urgency to leadership and engineering teams
• Ability to perform in-depth vulnerability assessments and variant analysis
• Be the subject matter expert (SME) for Threat and Vulnerability Management, providing deep consulting expertise on complex projects and delivering workable, risk/threat-driven solutions
• Provide solution and guidance to software development teams to remediate security findings and reduce risk
• Perform threat analysis for Cloud services and write remediation plans
• Champion best practice security configuration and hardening
• Stay current with threats and cyber security counter measures, practices, techniques and capabilities in the marketplace
Qualifications
• Bachelor’s or master’s degree in Computer Science or related field, or equivalent experience
• 8+ years of experience in security engineering for a software company
• 5+ years of software/systems engineering/development experience
• Experience with threat analysis and vulnerability management
• Working knowledge of Cloud computing, to include architecture, Identity, Compute, and Networking concepts
• Ability to understand business or regulatory requirements and author technical specifications based on those requirements
• Experience developing cloud services, specifically API’s/Webhooks in Python (or) Java
• Exposure to data warehouse technologies
• Application / product / software security background strongly preferred
• Extensive Linux experience
• Prior DevSecOps or continuous delivery and deployment experience preferred
• Familiar working with industry-standard regulatory requirements (SOC2, HIPPA, FedRamp, etc.) and technical standards (CIS, STIG, etc.)
About Us
More Information
- Salary Offer $113K/yr - $195K/yr
- Address Seattle, WA, USA
- Experience Level Senior
- Total Years Experience 10-20