Principle Security Incident Response Analyst
OracleAbout the role
We are looking for an experienced Principal Security Incident Response Analyst for a role on the Oracle Cloud Security Incident Response team. Candidates would be part of a dedicated team of security professionals responsible for performing investigations against a variety of cloud environments, services, and products within Oracle’s commercial and regulated markets. Our team is skilled in triaging complex security issues, applying expert use of security tooling, and performing every aspect of the incident response lifecycle.
Candidates will have 10+ years in security specific roles, strong analytic skills and experience using an array of security tooling including SIEM, EDR, AV, Scan tools, forensic collection, processing, and analysis tools. A background of security incident management, and advanced digital forensics is required in addition to experience collaborating with customers, engineering, sales, and other product and security teams within a large organization. A proven subject matter expert capable of discovering new investigation techniques and capabilities related to security investigations. Experience creating standards, playbooks, tabletop exercises, and other training. Capable of mentoring, without ego, junior and senior analysts within the organization.
Career Level - IC4
- Respond to security events and threats that are escalated from external customers, internal security teams, and other developers and engineers.
- Lead complex investigations that will include, triage, containment/mitigation, scoping, hunting, collection, processing, analysis, remediations, and after-action reporting and documentation.
- Work closely with security engineering teams to improve monitoring, detection, and tooling
- Understand the current threat landscape including emerging attacker TTPs and be able to translate them to the gaps and risks in the various environments in scope.
- Operate Security tooling including but not limited to a Security Information Event Management (SIEM) platform, Intrusion Detection Systems (IDS), Firewalls, Anti-Malware solutions, and Endpoint Detection and Response (EDR)
- Collect, process, and analyze an array of additional artifacts unavailable in security tooling. (logs, host/instance-based artifacts)
- Experience working on Windows, Mac, and Linux operating systems
- Provide high quality written and verbal reports as required
- Develop new analysis tactics and capabilities for digital forensics and incident response
- Author SOPs, playbooks and Incident Response plans
- Lead Tabletop exercises
- Mentor and train analyst
- Support on-call rotations
- Effective operator in a remote setting, adept at using technologies and self-imposing good time management practices
Qualifications:
- Bachelor's Degree in Information Security and Assurance, Cyber Security, Computer Science, Software Engineering, Risk Management or maintain multiple security related credentials (Certified Incident Handler (GCIH), EC-Council Certified Incident Handler (ECIH), Certified Information Systems Security Professional (CISSP))
- 10+ years of related cybersecurity architecture, engineering, and/or SOC work experience (monitoring, detection, incident response, forensics, vulnerability management, threat intelligence)
- Ability to script/code using Python, Perl, or an equivalent language
- Excellent written and verbal communications, including presentation skills
- Proven ability to effectively communicate with all levels of the organization, as well as customers and external parties
- Experience with variety of operating systems and threats that target them including Windows, UNIX/LINUX, and MacOS
- Excellent verbal/non-verbal communication skills with the ability to deliver technical information to non-technical staff
- Understanding of common security concerns and associated threat actor tactics
- A broad background in information security with experience in security operations, vulnerabilities and exploitation, network security, and cloud security
Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.
Range and benefit information provided in this posting are specific to the stated locations only
US: Hiring Range: from $109,100 to $223,500 per annum. May be eligible for bonus and equity.
Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
Oracle
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Protection & Controls Technical Training Senior-Principle-Staff
American Electric Power
$169,304/yr
Principle Engineer - Cyber Tools Operations and Strategy
Toyota North America
Adjunct Faculty - MRI4310 Physical Principles
Saint Louis University