Information Security Snr Manager

Nashville, TN, United States

Oracle

Oracle offers a comprehensive and fully integrated stack of cloud applications and cloud platform services.

View all jobs at Oracle

Apply now Apply later

At Oracle Cloud Infrastructure (OCI) we build the future of the cloud for Enterprises. We act with the speed and attitude of a start-up along with the scale and customer focus of the leading enterprise software company in the world.

About the team:

The Enterprise Engineering SRE team is tasked with ensuring the security and compliance of internal systems by conducting regular audits, identifying potential gaps in existing standards and proactively improving the organization's overall security posture. The team plays a critical role in safeguarding the integrity, confidentiality and availability of all systems while driving risk management initiatives across departments including disaster recovery planning and execution.

Ideally, the candidate will possess several of the following skills:

  • Regulatory Compliance: Brings advanced level skills to manage programs to establish, document and track compliance to industry and government standards and regulations, e.g. ISO-27001, PCI-DSS, HIPAA, FedRAMP, CMMC, GDPR, etc.  Researches and interprets current and pending governmental laws and regulations, industry standards and customer and vendor contracts to communicate compliance requirements to the business. Participates in industry forums monitoring developments in regulatory compliance
  • Risk Management: Brings advanced level skills to assess the information security risk associated with existing and proposed business operational programs, systems, applications, practices and procedures in very complex, business-critical environments. Conduct and document very complex information security risk assessments and assist in the creation and implementation of security solutions and programs
  • Cloud Security: In-depth knowledge of cloud security principles and best practices, including securing cloud infrastructure, services, and applications in platforms, OCI experience is a plus
  • Threat and Vulnerability Management:  Brings advanced level skills to research, evaluate, track, and manage information security threats and vulnerabilities in situations where in-depth analysis of ambiguous information is required
  • Incident Management and response:  Brings advanced level skills to respond to security events and responding in line with Oracle incident response playbooks to mitigate vulnerabilities
  • Mentors and trains other team members
  • Compiles information and reports for senior leadership and executive teams

 

Qualifications:

  • Bachelor's Degree: Computer Science, Information Technology, Cybersecurity, or a related field is typically required
  • Master's Degree (optional but preferred): Information Security, Cybersecurity, Business Administration (with a focus on IT), or a similar field can be an added advantage
  • 5+ years of experience managing a team focused on enterprise information security.
  • 10+ years of experience in information systems, business operations, security operations, with a focus on incident detection, response, and vulnerability remediation
  • Industry certifications such as CISSP, CISM, CRISC, GIAC, or OCI\AWS\GCP\Azure Security Specialty are highly preferred.
  • Hands-on experience with security operations, incident response, cloud security (OCI, AWS, Azure, GCP), identity & access management (IAM), and data protection.
  • Extensive experience with security frameworks, risk management, and regulatory compliance (ISO 27001, NIST, CIS Controls, GDPR, HIPAA, PCI-DSS).
  • Solid understanding of networking protocols, operating systems (Linux, Windows), MiddleTier, Database, cloud computing and end point computing management
  • Proven ability to collaborate across departments and influence stakeholders at all levels, including executive leadership. 

Soft Skills:

  1. Critical Thinking & Problem Solving: Security issues often require quick, rational decision-making, especially during crises.
  2. Collaboration: You'll be working with different teams across the organization to ensure that security is integrated into every part of the business.
  3. Adaptability: Cybersecurity is a constantly evolving field, so staying adaptable to new technologies and threats is essential.
  4. Attention to Detail: Even small vulnerabilities can lead to significant issues, so attention to detail is crucial.
  5. Communication:  Excellent verbal and writing skills to communicate to wide range of audiences - technical, non-technical, executives.

Career Level - M3

  1. Leadership and Management Skills:
    1. As a senior manager, responsible for leading a team of security professionals, managing projects, and making key decisions. You need strong people management skills, the ability to motivate and mentor staff, and a strategic mindset to drive security initiatives.
  2. Risk Management and Governance:
    1. Understanding and implementing risk management practices is a central aspect of the role. Assess threats, prioritize risks, and implement mitigation strategies. Experience with risk management frameworks (like NIST or ISO 27001) is often required.
  3. Incident Response and Crisis Management:
    1. Experience handling cybersecurity incidents, whether that means leading a team through a data breach, addressing system vulnerabilities, or conducting post-incident analysis. An incident response plan and disaster recovery planning knowledge are essential.
  4. Knowledge of Security Frameworks and Regulations:
    1. A solid understanding of various security frameworks (e.g., ISO 27001, NIST, CIS Controls, COBIT) is crucial, as well as compliance regulations (e.g., GDPR, HIPAA, PCI-DSS). Ability to assess the organization’s compliance with these frameworks and manage audits or certifications.
  5. Security Architecture & Design:
    1. Experience with designing and implementing security architectures for networks, applications, and cloud systems. Understanding of secure infrastructure from the ground up, including the use of firewalls, encryption, multi-factor authentication, etc., is vital.
  6. Threat Intelligence and Cyber Threat Landscape:
    1. As a senior managers should be well-versed in the current cyber threat landscape—which includes recognizing and mitigating attacks like phishing, ransomware, social engineering, and advanced persistent threats (APTs). Proficiency in using threat intelligence tools and analyzing security data is critical.
  7. Communication and Stakeholder Management:
    1. A key part of the role is interacting with senior management, IT teams, legal teams, and potentially external auditors or regulators. Communicate complex security risks in an easily understandable way to non-technical stakeholders. This includes writing security reports, making presentations, and influencing decision-making.
  8. Vendor and Third-Party Management:
    1. Many organizations use third-party vendors for various IT services, assess and manage vendor relationships from a security standpoint, ensuring that any external entities comply with security standards.
  9. Security Tools and Technology:
    1. Familiarity with a wide range of security tools and technologies is important. These might include:
      1. Security Information and Event Management (SIEM) systems (like Splunk, IBM QRadar).
      2. Endpoint Detection and Response (EDR) tools (such as CrowdStrike, Carbon Black).
      3. Firewall management tools. Virtural cloud network and security rules.
      4. Identity and Access Management (IAM) solutions.
      5. Data Loss Prevention (DLP) tools.
      6. Encryption technologies.
    2. Staying up-to-date with emerging technologies (e.g., AI/ML in security) is essential as new tools and threats evolve rapidly.
  10. Project Management:
    1. Ability to manage multiple projects, prioritize security tasks, and ensure that deadlines are met. Experience with project management methodologies (such as Agile or Waterfall) is often preferred.
    2. Building OKRs and KPIs to measure effectiveness of security operations including vulnerability management, patch management, compliance, risk management. 
Disclaimer:

Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.

Range and benefit information provided in this posting are specific to the stated locations only

US: Hiring Range in USD from: $120,100 to $251,600 per annum. May be eligible for bonus, equity, and compensation deferral.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto, homeowner and pet insurance

The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.

As a world leader in cloud solutions, Oracle uses tomorrow’s technology to tackle today’s problems. True innovation starts with diverse perspectives and various abilities and backgrounds.

When everyone’s voice is heard, we’re inspired to go beyond what’s been done before. It’s why we’re committed to expanding our inclusive workforce that promotes diverse insights and perspectives.

We’ve partnered with industry-leaders in almost every sector—and continue to thrive after 40+ years of change by operating with integrity.

Oracle careers open the door to global opportunities where work-life balance flourishes. We offer a highly competitive suite of employee benefits designed on the principles of parity and consistency. We put our people first with flexible medical, life insurance and retirement options. We also encourage employees to give back to their communities through our volunteer programs.

We’re committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by calling +1 888 404 2494, option one.

Disclaimer:

Oracle is an Equal Employment Opportunity Employer*. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

* Which includes being a United States Affirmative Action Employer

Apply now Apply later
Job stats:  1  0  0
Category: Leadership Jobs

Tags: Agile Audits AWS Azure Carbon Black CISM CISSP Cloud CMMC COBIT Compliance Computer Science CRISC CrowdStrike EDR Encryption FedRAMP Firewalls GCP GDPR GIAC Governance HIPAA IAM Incident response ISO 27001 KPIs Linux Monitoring NIST OKR Oracle QRadar Risk assessment Risk management SIEM Splunk Threat intelligence Vulnerabilities Vulnerability management Windows

Perks/benefits: 401(k) matching Competitive pay Equity / stock options Flex hours Flexible spending account Flex vacation Health care Insurance Medical leave Parental leave Salary bonus Team events

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.