RESPONSIBILITIES :
- The candidate will support the strengthening of Oracle's security posture, focusing on areas such as regulatory compliance, risk management, incident management and response, and Threat and Vulnerability Management.
- This role requires an experienced professional with 8+ years in information systems and 3+ years in security operations, capable of operating independently and leading security projects.
- Key functions include managing compliance programs to industry and government standards, conducting complex information security risk assessments, and overseeing internal audit processes.
- The position also involves developing, implementing, and maintaining robust security policies and providing guidance on process improvements to remediate control gaps.
Principal Duties and Responsibilities
Regulatory Compliance : Manage programs to establish, document, and track compliance to standards and regulations like ISO-27001, PCI-DSS, HIPAA, FedRAMP, CMMC, GDPR, etc. Researches and interprets current and pending governmental laws and regulations.Risk Management : Conduct and document very complex information security risk assessments and lead departmental risk management programs.Audit and Liaison : Oversee and manage internal audit processes, acting as the primary liaison between internal teams to ensure efficient and accurate audit completion. Assess the effectiveness of security controls.Security Posture & Policy : Continuously assess and enhance the organization's security posture. Collaborate with cross-functional teams to establish and maintain robust security policies and procedures.Threat and Vulnerability Management : Research, evaluate, track, and manage information security threats and vulnerabilities.Incident Management and Response : Respond to security events and mitigate vulnerabilities in line with incident response playbooks. Facilitate and drive disaster recovery (DR) planning.Documentation and Reporting : Develop and maintain cybersecurity documentation (e.g., SSP, PIA, CMP, POAM, SOP). Write stakeholder reports, create metrics, and brief executive leadership on compliance matters.Mentorship : Mentors and trains other team membersSkills Required
Regulatory Compliance, Risk Management, Linux, Oracle Cloud Infrastructure