Oracle

Principal Security Analyst


PayCompetitive
LocationBengaluru/Karnataka
Employment typeOther

This job is now closed

  • Job Description

      Req#: 264401

      Develops and executes programs and processes to reduce information security risk and strengthen Oracle’s security posture.

      Oracle is seeking security analyst to support systems and security operations of Database Engineering Cloud infrastructure. The position requires proven track record in designing, implementing and running Public Cloud infrastructure , security architecture, vulnerability management and internal security auditing and reporting. Security analysts are also responsible for keeping the company's security systems up to date and documenting and planning for all security-related information, including incident response and disaster recovery plans. The position involves close collaboration with other teams to achieve collective security goals. The job involves to run large infrastructure with Sec Ops Automation

      Responsibilities displayed in the job posting

      • Design and develop cloud security architecture and perform architecture design reviews.
      • Implementation of various aspects of security architecture standard processes.
      • Knowledge of application, data classification, security infrastructure and governance, Logging, Supervising aspects and Authorization
      • Ability to analyze customer requirements and convert into secure and scalable cloud solutions.
      • Review application architectures and implementation details for design flaws, incorrect security implementation and missing security controls.
      • Drive and lead security processes, tools, methods, and knowledge and security enhancements
      • Build out new security control catalog, security policies and procedures and assist in implementing them.
      • Use Static and Dynamic Analysis tools to support broad testing and vulnerability discovery in the CI/CD pipeline.
      • Conduct security assessments through vulnerability testing and risk analysis
      • Coordinate with Corporate Security teams and System Owners to ensure Corporate Security standards implementation.
      • Perform security audit, risk assessment, and generate reports of security posture of systems.
      • Build automation using Python/Ruby/Terraform/Ansible /Oracle Apex to handle large Infrastructure.
      • Drive innovation and integration of new technologies into projects and activities
      • Conduct Penetration tests and recommend secure implementation.
      • Provide domain-specific expertise, overall security leadership and perspective to cross- organization projects, programs, and activities.
      • Willing to learn new technologies and products.
      • Knowledge of encryption technologies
      • Create threat models to communicate risks to engineers, project managers and other technical teams.

      Career Level - IC4

      Responsibilities

      Supports the strengthening of Oracle’s security posture, focusing on one or more of the following: risk management; regulatory compliance; threat and vulnerability management; incident management and response; security policy development and enforcement; privacy; information security education, training and awareness (ISETA); digital forensics and similar focus areas.
      Risk Management: Brings advanced level skills to assess the information security risk associated with existing and proposed business operational programs, systems, applications, practices and procedures in very complex, business-critical environments. May conduct and document very complex information security risk assessments. May assist in the creation and implementation of security solutions and programs.
      Regulatory Compliance: Brings advanced level skills to manage programs to establish, document and track compliance to industry and government standards and regulations, e.g. ISO-27001, PCI-DSS, HIPAA, FedRAMP, GDPR, etc. Researches and interprets current and pending governmental laws and regulations, industry standards and customer and vendor contracts to communicate compliance requirements to the business. Participates in industry forums monitoring developments in regulatory compliance.
      Threat and Vulnerability Management: Brings advanced level skills to research, evaluate, track, and manage information security threats and vulnerabilities in situations where in-depth analysis of ambiguous information is required.
      Incident Management and response: Brings advanced level skills to respond to security events, identifying possible intrusions and responding in line with Oracle incident response playbooks. May operate as Incident Commander on serious incidents.
      Digital Forensics: Brings advanced level skills to conduct data collection, preservation and forensic analysis of digital media independently, where an advanced understanding of forensic techniques is required.
      Other areas of focus may include duties providing advanced level skills and knowledge to manage Information Security Education, Training and Awareness programs. In a Corporate Security role, may manage the creation, review and approval of corporate information security policies.
      Mentors and trains other team members.
      Compiles information and reports for management.

  • About the company

      Our mission is to help people see data in new ways, discover insights, unlock endless possibilities. Want to make a difference? You've come to the right place. We're using innovative emerging technologies to tackle real-world problems today.

Notice

Talentify is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Talentify provides reasonable accommodations to qualified applicants with disabilities, including disabled veterans. Request assistance at accessibility@talentify.io or 407-000-0000.

Federal law requires every new hire to complete Form I-9 and present proof of identity and U.S. work eligibility.

An Automated Employment Decision Tool (AEDT) will score your job-related skills and responses. Bias-audit & data-use details: www.talentify.io/bias-audit-report. NYC applicants may request an alternative process or accommodation at aedt@talentify.io or 407-000-0000.