Jobs and Careers
OR
Security Analyst 3
OracleUnited States, United Statesfull_timeVerifiedPosted 16 Jan 2025
💰 $178,100/yr($87,000/yr – $178,100/yr)
About the role
Key Responsibilities
Legacy Hardening
- Identify security gaps in legacy systems and propose practical hardening measures to reduce risk.
- Collaborate with cross-functional teams to implement compensating controls where full remediation is not feasible.
- Document and track hardening initiatives to ensure alignment with compliance and regulatory requirements.
Vulnerability Burndown
- Prioritize and drive the remediation of critical vulnerabilities across applications, infrastructure, and systems.
- Collaborate with IT, Operations, and application development teams to resolve vulnerabilities and implement long-term fixes.
- Utilize ticketing, vulnerability and risk management tools
Application Security Release Management
- Work with development to integrate security into the CI/CD pipeline.
- Perform security reviews of applications, focusing on mitigating OWASP Top 10 risks, addressing 3rd-party dependency issues, and managing SAST/DAST findings.
- Support secure software development practices by identifying potential risks and recommending mitigations.
Collaboration and Communication
- Partner with technical and non-technical stakeholders to align security efforts with business goals.
- Provide clear and actionable updates on progress, challenges, and risks to leadership and relevant teams.
- Actively contribute to team discussions, offering creative solutions to complex problems.
Continuous Improvement
- Stay informed about emerging threats, vulnerabilities, and trends in application security and system hardening.
- Recommend process improvements to enhance the efficiency and effectiveness of vulnerability management and security initiatives.
- Assist in the development and delivery of training and awareness programs for secure coding and system management.
Required Qualifications
- Education: Degree in Cybersecurity, Computer Science, Information Technology, or a related field. Equivalent work experience will also be considered.
- Experience:
- 3-5 years of experience in cybersecurity, with hands-on experience in vulnerability management, application security, or system hardening.
- Familiarity with vulnerability and risk management principles
- Microsoft Windows and Active Directory
- AWS, Azure or OCI Cloud experience
- Certifications: Relevant certifications such as CompTIA Security+, CEH, or SANS GIAC certifications (e.g., GSEC, GWAPT) are a plus.
- Mindset: Can do positive attitude with bias for action
Desired Skills
- Strong understanding of security frameworks and standards (e.g., OWASP Top 10, NIST, CIS).
- Experience working in environments with legacy systems and modern CI/CD pipelines.Excellent problem-solving and analytical skills with a proactive mindset.
- Ability to navigate ambiguity and prioritize tasks in a fast-changing environment.
- Exceptional communication skills, capable of simplifying technical details for various audiences.
- Experience with scripting or automation (e.g., Python, PowerShell) is a plus.
Career Level - IC3
Key Responsibilities
Legacy Hardening
- Identify security gaps in legacy systems and propose practical hardening measures to reduce risk.
- Collaborate with cross-functional teams to implement compensating controls where full remediation is not feasible.
- Document and track hardening initiatives to ensure alignment with compliance and regulatory requirements.
Vulnerability Burndown
- Prioritize and drive the remediation of critical vulnerabilities across applications, infrastructure, and systems.
- Collaborate with IT, Operations, and application development teams to resolve vulnerabilities and implement long-term fixes.
- Utilize ticketing, vulnerability and risk management tools
Application Security Release Management
- Work with development to integrate security into the CI/CD pipeline.
- Perform security reviews of applications, focusing on mitigating OWASP Top 10 risks, addressing 3rd-party dependency issues, and managing SAST/DAST findings.
- Support secure software development practices by identifying potential risks and recommending mitigations.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s