Senior Principal Application Security Engineer, Oracle Payments
OracleAbout the role
Senior Principal Application Security Engineer, Oracle Payments
Location: United States
Travel: 25%
No visa sponsorship is available for this position.
You have a passion for payments and are driven to apply your creative problem-solving skills to complex challenges. You are a highly motivated self-starter that communicates efficiently across geographic and cultural boundaries and influence at all levels within a company. As a results and goal-oriented professional, you work independently in a sophisticated and dynamic environment.
Sound familiar? Here’s your chance to be part of a tight-knit global team at one of the world’s leading tech companies.
The Role
As part of the Oracle Payments Team, the Security Lead is responsible for reducing security assurance risk. You will lead the security practice to drive the culture in the organization and ensure that all activities are effective at avoiding, mitigating, finding and fixing vulnerabilities.
The SPOC is considered the security expert for the component team and as such, is the central security resource to the team. The SPOC is a key player and has significant responsibilities during each product release cycle. These security compliance activities are not a one-time occurrence but are ongoing and carry through every product release.
Career Level - IC5
Essential Functions
As a member of the software engineering team, you will take an active role in the definition and evolution of standard practices and procedures. You will be responsible for defining and developing software for tasks associated with the developing, designing and debugging of software applications or operating systems.
- Monitor, develop, and maintain enterprise security tooling program including Security Information and Event Management (SIEM), Endpoint Protection, and Web Application Firewalls in both an engineering and analyst capacity.
- Participate in security project tasks on an as needed basis and interact directly with security organizations and multiple Lines of Business globally.
- Work directly with system owners to implement security controls and configure security tools to meet a variety of requirements.
- Build relationships with other compliance and regulatory teams to assess and incorporate security and compliance requirements into our development processes.
- Lead the internal security review processes and provide guidance during design, development and release phases on security standards
- Reduce risk by enhancing existing security tools and processes within the organization
- Support for Reported Product Security Vulnerabilities - Have the skills to review code fixes of security bugs in their areas of responsibility
- Technical Guidance for Ongoing Product Development - During the design phase, the Security Lead must ensure that product functional and design specifications include security considerations for every release
- Security Community Activity Leadership - The Security Lead must coordinate the various security activities for the respective product family
- Product Security Compliance - A major component of the Security Lead function is to identify and quantify security risks for management, especially product risks for customers and the consequential risks to the Oracle brand.
- Participate in a Rotational On-Call schedule for Critical issues (we strive to make sure this is truly as rare as it can be)
- Analyzes the impact that proposed features will have on the security of other components as well as the product overall.
- Participates in design reviews of other components of the product to spot potential threats and risks to his/her component and the product overall.
- Checks that core security modules are used (crypto, SSO, etc.); raises exceptions to GPS with explanation and justification if needed.
- Uses threat analysis techniques to review and minimization of the threat landscape and attack surface for the component, ensuring entry points/APIs are properly secured.
- Conducts periodic code reviews to ensure the component’s security status is consistent with the design and with the Secure Coding Standards.
- Monitor internal SecAlert announcements and external security web sites/mailing lists for new developments and emerging threats that may impact the component.
- Tracks and reviews third party code that is used by the component and ensures that it is approved for use and the current version updated with available security patches.
- Ensures adequate code analysis and security testing of the component is completed.
- Read security alerts from partner vendors and act as necessary for the component.
- Apply latest Critical Patch Updates and s
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s