Senior Security Engineer
Oracle Nashville, Tennessee, United States · $82K–$187K/yr
IT Services and IT Consulting · 10,001+ employees
About the role
The role involves building and operating advanced security tools and automation to identify and mitigate data security risks across Oracle's cloud infrastructure. You will lead data loss prevention investigations and collaborate with cross-functional teams to respond to sophisticated security threats.
What they look for
Requirements
Candidates should have 3-6 years of experience in insider threat, data loss prevention, and incident response within a cloud service provider environment. Strong communication skills and the ability to work in a fast-paced, ambiguous environment are essential.
Benefits
Full description
Creates testing tools to help engineering teams identify security-related weaknesses. Recognizes and escalates complex security violations to senior team members. Contributes to compliance assessments to identify gaps and ensure compliance with internal and external obligations. Provides security best judgment and recommends best practices of data security using various tools and techniques such as encryption, hashing, masking, and access management to ensure the confidentiality and integrity of sensitive information.
Responsibilities
We are vigorously investing in Oracle Cloud to provide the broadest, most secure cloud in the industry. Oracle offers a suite of integrated services, including applications as a service, platform as a service, and infrastructure as a service, that eliminates the data and business process fragmentation which comes with cloud silos. This is your opportunity to be part of the exciting Cloud Security team that is responsible for protecting Oracle’s infrastructure and keeping customer workloads safe.
Oracle’s mission is to provide customers with best-in-class compute, storage, networking, database, security, and an ever-expanding set of foundational cloud-based security services. We are rapidly expanding the size and scale of our business and are looking for highly talented individuals to join our team.
cloud.oracle.com/cloud-infrastructure
cloud.oracle.com/security
As a vital member of Oracle Cloud Infrastructure’s (OCI) Security Operations Organization, you will be at the forefront of protecting Oracle’s cloud and enterprise environments from both external adversaries and insider threats. As our team continues to expand and tackle ambitious initiatives, we are seeking experienced security professionals with a proven track record in safeguarding critical infrastructure and data.
Our rapidly growing team specializes in threat hunting, analyzing indicators of compromise (IOCs), investigating security incidents, managing incident responses, and conducting digital forensics across IaaS, PaaS, and SaaS platforms. In this role, you will be part of a dedicated security operations team, leveraging data loss prevention, case management tools, and developing automation to detect and respond to security threats in real time. Additionally, you will play a critical role in designing and implementing data loss prevention strategies to proactively mitigate potential data security risks. As the last line of defense when security controls are breached, your expertise will be instrumental in securing Oracle’s data and infrastructure.
The ideal candidate is a proactive self-starter with a strong sense of ownership, accountability, and capable of delivering effective results under pressure. By bringing deep expertise in security engineering, you will help drive the strategic development of our enterprise security threat program.
The Role We are seeking a seasoned security engineering professional that will build and operate advanced security tools, processes, and automation to identify and mitigate data security risks related to proprietary data across OCI and Oracle’s broader enterprise. You will lead sensitive DLP investigations, conduct thorough root cause analyses, and work collaboratively with partner teams - including SOC, digital forensics, incident response, physical security, engineering teams as well as legal and HR - to respond effectively to diverse and sophisticated threats.
Key Responsibilities
- Monitor and Analyze User Activity: Continuously monitor, analyze, and investigate anomalous user behaviors and activities across networks, applications, and endpoints to detect suspicious patterns or potential insider threats.
- Build and Maintain Detection and Response Systems: Develop, implement, and manage tools, analytics, and automated detection systems specifically designed to identify potentially malicious activity.
- Data Loss Prevention (DLP): As a member of the DLP operations team, enhance data loss prevention strategies, including deploying and tuning DLP technologies to prevent unauthorized access or transmission of sensitive proprietary data.
- AI-Enabled Security Operations: build, deploy, and operate AI-enabled capabilities that accelerate DLP investigations, enhance analyst decision-making, and improve detection, triage, and response workflows. Drive the adoption of AI-powered tooling and automation while ensuring solutions are secure, effective, and aligned with operational and governance requirements.
- Incident Investigations: Conduct thorough investigations of security incidents related to potential or confirmed threats, collaborating closely with legal, HR, and compliance teams as needed.
- Case Management: Document and manage cases from detection through to resolution, ensuring proper documentation and reporting processes are followed.
- Security Awareness and Training: Support the development and delivery of targeted security awareness training at all levels of the company. Training to be focused on reducing data security risk and how to recognize and report suspicious behaviors.
- Collaboration and Coordination: Work with cross-functional teams such as HR, legal, compliance, physical security and other engineering organizations to coordinate incident response and security policy and standards of enforcement.
- Threat Hunting: Proactively hunt for evidence of threats by analyzing system logs, access records, and behavioral analytics.
- Tool and Process Enhancement: Evaluate and recommend improvements to detection tools, response processes, and operational playbooks.
- Reporting and Analytics: Prepare reports and metrics on insider threat trends, investigation outcomes, and security posture for management and leadership.
Preferred Qualifications
- For IC3 – 3-6yrs of experience in Insider Threat, DLP (client/server/cloud), incident response and/or security operations center activities at a cloud service provider
- Exceptional written and oral communications skills with the ability to deliver technical information to non-technical staff
- Comfortable working in an ambiguous, fast-paced, unpredictable environment
- Experience working in a highly collaborative, team centric, event driven operations team
- Experience with variety of technologies and how they are used to exfiltrate data
- Experience with a variety of DLP tools (data at rest, data in motion, data in use)
- Experience with a wide variety of logs and telemetry including AV, web server, SIEM, etc.
- Experience with sophisticated threat actors and complex security incidents
- Understanding of insider threat actor tactics, techniques, and procedures (TTPs) and threat analysis models like MITRE ATT&CK Framework
- Experience developing and hunting using DLP-related indicators of compromise (IOC’s)
- Experience performing open-source research on a variety of topics
Qualifications
Disclaimer:
Certain U.S. based or U.S. customer or client-facing roles may be required to comply with applicable requirements, such as immunization/occupational health mandates, and/or drug testing requirements.
Range and benefit information provided in this posting are specific to the stated locations only
US: Hiring Range in USD from: $82,200 to $187,000 per annum. May be eligible for bonus and equity.
Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
Oracle US offers a comprehensive benefits package which includes the following: 1. Medical, dental, and vision insurance, including expert medical opinion 2. Short term disability and long term disability 3. Life insurance and AD&D 4. Supplemental life insurance (Employee/Spouse/Child) 5. Health care and dependent care Flexible Spending Accounts 6. Pre-tax commuter and parking benefits 7. 401(k) Savings and Investment Plan with company match 8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation. 9. 11 paid holidays 10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours. 11. Paid parental leave 12. Adoption assistance 13. Employee Stock Purchase Plan 14. Financial planning and group legal 15. Voluntary benefits including auto, homeowner and pet insurance
The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted. As part of Oracle's onboarding process and consistent with applicable law, US-based employees are required to complete identity verification, which involves the collection and processing of their biometric information. Accommodations to this requirement may be granted following an individualized assessment.
Only Oracle brings together the data, infrastructure, applications, and expertise to power everything from industry innovations to life-saving care. And with AI embedded across our products and services, we help customers turn that promise into a better future for all. Discover your potential at a company leading the way in AI and cloud solutions that impact billions of lives.
True innovation starts when everyone is empowered to contribute. That’s why we’re committed to growing a workforce that promotes opportunities for all with competitive benefits that support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.
We’re committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing accommodation-request_mb@oracle.com or by calling 1-888-404-2494 in the United States.
Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
Similar roles
-
Campus - Internship Programme - Undergraduate Information Security Engineer - 2027 (UK - Burgess Hill)
American Express Mid Sussex, England, United Kingdom
-
IT Security Engineer (m/w/d)
VusionGroup SA Fernitz-Mellach, Styria, Austria · €47K/yr
-
Security Engineer
Penneo Copenhagen, Capital Region of Denmark, Denmark
-
IT Infrastructure Security Engineer
Nexthink Madrid, Community of Madrid, Spain · €36K–€54K/yr
-
Campus - Full Time - Information Security Engineer - 2027 (UK - Burgess Hill)
American Express Mid Sussex, England, United Kingdom
-
Sales Specialist Cybersecurity
Inetum Saint-Ouen-sur-Seine, Ile-de-France, France