Jobs and Careers
OR

Security Analyst 3

Oracle
United States, United Statesfull_timeVerifiedPosted 16 Jan 2025
💰 $178,100/yr($87,000/yr$178,100/yr)

About the role

Key Responsibilities

Legacy Hardening

  • Identify security gaps in legacy systems and propose practical hardening measures to reduce risk.
  • Collaborate with cross-functional teams to implement compensating controls where full remediation is not feasible.
  • Document and track hardening initiatives to ensure alignment with compliance and regulatory requirements.

Vulnerability Burndown

  • Prioritize and drive the remediation of critical vulnerabilities across applications, infrastructure, and systems.
  • Collaborate with IT, Operations, and application development teams to resolve vulnerabilities and implement long-term fixes.
  • Utilize ticketing, vulnerability and risk management tools 

Application Security Release Management

  • Work with development to integrate security into the CI/CD pipeline.
  • Perform security reviews of applications, focusing on mitigating OWASP Top 10 risks, addressing 3rd-party dependency issues, and managing SAST/DAST findings.
  • Support secure software development practices by identifying potential risks and recommending mitigations.

Collaboration and Communication

  • Partner with technical and non-technical stakeholders to align security efforts with business goals.
  • Provide clear and actionable updates on progress, challenges, and risks to leadership and relevant teams.
  • Actively contribute to team discussions, offering creative solutions to complex problems.

Continuous Improvement

  • Stay informed about emerging threats, vulnerabilities, and trends in application security and system hardening.
  • Recommend process improvements to enhance the efficiency and effectiveness of vulnerability management and security initiatives.
  • Assist in the development and delivery of training and awareness programs for secure coding and system management.
 

Required Qualifications

  • Education: Degree in Cybersecurity, Computer Science, Information Technology, or a related field. Equivalent work experience will also be considered.
  • Experience:
    • 3-5 years of experience in cybersecurity, with hands-on experience in vulnerability management, application security, or system hardening.
    • Familiarity with vulnerability and risk management principles 
    • Microsoft Windows and Active Directory
    • AWS, Azure or OCI Cloud experience
  • Certifications: Relevant certifications such as CompTIA Security+, CEH, or SANS GIAC certifications (e.g., GSEC, GWAPT) are a plus.
  • Mindset: Can do positive attitude with bias for action
 

Desired Skills

  • Strong understanding of security frameworks and standards (e.g., OWASP Top 10, NIST, CIS).
  • Experience working in environments with legacy systems and modern CI/CD pipelines.Excellent problem-solving and analytical skills with a proactive mindset.
  • Ability to navigate ambiguity and prioritize tasks in a fast-changing environment.
  • Exceptional communication skills, capable of simplifying technical details for various audiences.
  • Experience with scripting or automation (e.g., Python, PowerShell) is a plus.

Career Level - IC3

Key Responsibilities

Legacy Hardening

  • Identify security gaps in legacy systems and propose practical hardening measures to reduce risk.
  • Collaborate with cross-functional teams to implement compensating controls where full remediation is not feasible.
  • Document and track hardening initiatives to ensure alignment with compliance and regulatory requirements.

Vulnerability Burndown

  • Prioritize and drive the remediation of critical vulnerabilities across applications, infrastructure, and systems.
  • Collaborate with IT, Operations, and application development teams to resolve vulnerabilities and implement long-term fixes.
  • Utilize ticketing, vulnerability and risk management tools 

Application Security Release Management

  • Work with development to integrate security into the CI/CD pipeline.
  • Perform security reviews of applications, focusing on mitigating OWASP Top 10 risks, addressing 3rd-party dependency issues, and managing SAST/DAST findings.
  • Support secure software development practices by identifying potential risks and recommending mitigations.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Oracle

View company profile →