Senior Security Engineer
OracleAbout the role
There is a requirement that this person be a US Citizen due to job responsibilities in support of US Federal and DOD agencies.
Responsibilities
- Conduct rigorous security testing focusing on applications using standard static and dynamic security testing tools.
- Security in CICD pipelines enabling effective and efficient security in SDLC emphasizing “shift-left”.
- Threat modeling and risk analysis to help prioritization of threats and vulnerabilities.
- Develop incident response capabilities and participate in red-blue games.
- Security analysis, risk assessment, vulnerability management and mitigation.
- Deploy secure DevSecOps automation, tools and solutions, maintaining best practices and runbooks.
- Evaluate and lead POCs for security tools, and compliance requirements and solutions.
- Participate in development and operations sprints and audits, representing security.
- Security in Containers and Orchestration (e.g., Kubernetes), repository and dependency management.
- Develop deep knowledge on available solutions for IAM, SIEM, DART/CSIRT.
Qualifications
- BS or MS degree; at least 3 years of experience with hands-on security testing and vulnerability management
- Curiosity, love for security, sense of humor and emotional intelligence to work across teams
- Experience with OWASP pen testing methodology and good knowledge of top attack vectors
- Experience with comprehensive security reporting on findings with risk assessment and mitigation plans
- Experience with Mobile Application security testing
- Good knowledge of basic cryptography and standards.
- Good knowledge of security related to network, identity, access, and web application stacks.
- Familiarity with MITRE ATT&CK, CIS, NIST 800. Bonus: certifications such as ECSA, OSCP.
- Experience with security automation related programming with ability to code in python, java, shell, DevOps tools, etc.
- Good communication and presentation skills, self-motivation, and strong work ethic
Career Level - IC3
Responsible for basic planning, design and build of security systems, applications, environments and architectures; oversees the implementation of security systems, applications, environments and architectures and ensures compliance with information security standards and corporate security policies and procedures.
Assist in development of incident response capabilities, training, and tool validation.
May research, evaluate, track, and manage information security threats and vulnerabilities in situations where analysis of well-understood information is required and where computer programming/scripting knowledge is required.
May participate in an incident management team, responding to security events in line with Oracle incident response playbooks. Investigates purported intrusions and breaches, and oversees root cause analysis. Coordinates incidents with other business units and may assist the Incident Commander during serious incidents. Participates in developing new methods, and playbooks, as well as basic scripts, applications, and tools.
Research industry trends and constantly assess current controls and threat posture of new and existing products and services.
Recommend and implement new security controls across Oracle’s line of business (LOB).
Improve current processes and workflows to minimize manual efforts.
Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.
Range and benefit information provided in this posting are specific to the stated locations only
US: Hiring Range: from $87,000 to $178,200 per annum. May be eligible for bonus and equity.
Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s