Jobs and Careers
OR

Principal Security Researcher

Oracle
United Statesfull_timeVerifiedPosted 22 Jan 2024
💰 $223,500/yr($109,100/yr$223,500/yr)

About the role

Onsite presence required in Columbia, MD or Denver, CO (secure, non-government facility)

Do you have a passion for high scale services and working with some of Oracle's most critical customers?  We are seeking experienced, hardworking, and dedicated security researchers who have genuine excitement for and interest in security. You must relish the challenge of assessing large, complex software products. Creativity is highly valued; being able to find novel bugs and stitch them together to create something greater than the sum of their parts is essential in this role.

Who We Are

Oracle’s Software Assurance organization has the mission is to make application security and software assurance, at scale, a reality. We are an inclusive and diverse team of high caliber application security researchers, distributed globally, who thrive on new challenges. We are seeking experienced, hardworking, and dedicated security researchers who have genuine excitement for and interest in security to work on a critical greenfield software assurance project collaboratively with our cloud and mobile engineering teams. You must relish the challenge of assessing large, complex software products. Creativity is highly valued; being able to find novel bugs and stitch them together to create something greater than the sum of their parts is essential in this role.

 

Do you have a passion for high scale services and working with some of Oracle's most critical customers?  We are seeking experienced, passionate, and dedicated security researchers who have genuine excitement for and interest in security. You must relish the challenge of assessing large, complex software products. Creativity is highly valued; being able to find novel bugs and stitch them together to create something greater than the sum of their parts is critical in this role.

Job Description

Oracle’s Software Assurance organization has the mission is to make application security and software assurance, at scale, a reality. We are an inclusive team with varied strengths of high caliber application security researchers, distributed globally, who thrive on new challenges. We are seeking experienced, passionate, and talented security researchers who have genuine excitement for and interest in security to work on a critical greenfield software assurance project collaboratively with our cloud and mobile engineering teams. You must relish the challenge of assessing large, complex software products. Creativity is highly valued; being able to find novel bugs and stitch them together to create something greater than the sum of their parts is essential in this role.

Work You’ll Do

As a member of our team, you will be responsible for planning and delivering in depth security assessments across a variety of products and services. Your next project could be anything from source code review of backend services, to static and dynamic analysis of a mobile application, to review or creation of technical security designs. Responsibilities include:

  • Scope and implement security assessments across a broad range of on-premise software, mobile applications, cloud services and infrastructure
  • Perform in-depth security assessments using your code review skills, demonstrating results from other assessments such as static and dynamic analysis
  • Create testing tools to help engineering teams identify security-related weaknesses
  • Collaborate with engineering teams to help them triage and fix security issues
  • Keep yourself abreast of new TTPs (Tactics, Techniques & Procedures) of the attackers, mimic them in your security assessments and/or quickly react to new threat scenarios to provide continuous security assurance

What You’ll Bring

  • Interest in self-study, setting and achieving long term goals (for example, learning an unfamiliar programming language)
  • Excellent presentation, verbal, and written communication skills
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
  • This role does not require access to a cleared work environment. Security clearances are not required, and active clearances cannot be sponsored.

Nice to Have

  • Experience working in a large cloud or Internet software company
  • Proficiency with one or more programming languages, preferably Go, Java, Python or C/C++
  • Ability to perform manual source code reviews in one of the aforementioned languages, or assisted review with code analysis tools such as CodeQL
  • Experience navigating and working with very large codebases is also highly desirable
  • Experience using common security assessment tools and techniques in one or more the following categor

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Oracle

View company profile →