Jobs and Careers
OR

Senior Security Analyst (Governance, Risk, and Compliance)

Oracle
United States, United Statesfull_timeVerifiedPosted 5 Apr 2024
💰 $178,200/yr($86,200/yr$178,200/yr)

About the role

Do you have a passion for high scale services and working with some of Oracle's most critical customers?  We are seeking experienced, passionate, and talented security analysts who have genuine excitement for and interest in security. If you thrive on the challenge of navigating the complexities of large, intricate software systems to enhance security and compliance frameworks, we want you. Creativity and a keen eye for detail are critical in this role; your ability to device comprehensive security protocols and innovative compliance strategies can lead to transformative outcomes. Join us in shaping the future of Oracle’s security posture, where your efforts ensure the integrity and resilience of our services on a global scale. 

Who We Are

We are a world-class team of high calibre application security researchers and analysts who thrive on new challenges.  We are an inclusive and diverse team with a full spectrum of experience distributed globally.  We have the resources of a large enterprise and the energy of a start-up, working on a critical Greenfield software assurance project collaboratively with our cloud and mobile engineering teams.  The Software Assurance organization has the mission is to make application security and software assurance, at scale, a reality.  We are a dedicated team, leveraging each other’s insights and abilities to produce cutting edge solutions to difficult problems through automation and CI/CD.  Join us to grow your career and create the future of software assurance at scale together. 

Career Level - IC3

Work You’ll Do

As a member of our team, your days will be dynamic and filled with impactful work. You’ll immerse yourself in the development and refinement of Governance, Risk, and Compliance (GRC) protocols, crafting policy frameworks that not only meet but exceed industry standards. Each project presents a new set of challenges, whether it’s tailoring security solutions for Oracle’s critical customers, or navigating the complexities of global compliance requirements. Additional responsibilities include:

  • Developing and refining information security protocols and policies, ensuring alignment with current industry standards and regulatory requirements.
  • Crafting comprehensive policy framework that guide the organization in maintaining robust security and privacy measures.
  • Working closely with clients to develop security and privacy program requirements, ensuring their unique needs are met while maintaining compliance with established security standards.
  • Overseeing the implementation of internal information security training programs, enhancing the security awareness and expertise of colleagues.
  • Managing compliance tracking mechanisms to monitor and report on adherence to established security practices and taking action on deviations.
  • Collaboration with cross functional teams to maintain an improved GRC processes, ensuring the seamless integration of security practices across Oracle infrastructure and operations.

What You’ll Bring

  • At least five years of experience in information security, specifically with GRC.
  • Demonstrating proficiency in developing information security protocols and crafting policy frameworks based on industry standards such as those from the National Institute of Standards and Technology (NIST).
  • Excellent communication skills with the ability to effectively engage with both technical teams, and not technical stakeholders, including government representatives.
  • Experience with compliance, auditing, security policy development, and risk assessment methodologies.
  • Aptitude for self-study, setting and achieving long term goals (for example, learning an unfamiliar programming language).
  • Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staff.
  • Excellent organizational, presentation, verbal, and written communication skills.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
  • United States Citizenship Required

Nice to Have

  • Professional certifications, such as CISSP, CISM, CISA, or equivalent.
  • Familiarity with Center for Internet Security (CIS) benchmarks and best practices.
  • Experience working with cloud technologies, and familiarity with the unique security challenges and solutions in cloud environments.
  • Proficiency in audit preparation, tracking, and management, ensuring readiness for external security and compliance audits.
     

What We’ll Give You

  • A team of very skilled and diverse personnel across the globe.
  • Ability to work in a flexible wor

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Oracle

View company profile →