Nashville, TN, USA
21 days ago
Information Security Snr Manager

At Oracle Cloud Infrastructure (OCI) we build the future of the cloud for Enterprises. We act with the speed and attitude of a start-up along with the scale and customer focus of the leading enterprise software company in the world.

About the team:

The Enterprise Engineering SRE team is tasked with ensuring the security and compliance of internal systems by conducting regular audits, identifying potential gaps in existing standards and proactively improving the organization's overall security posture. The team plays a critical role in safeguarding the integrity, confidentiality and availability of all systems while driving risk management initiatives across departments including disaster recovery planning and execution.

Ideally, the candidate will possess several of the following skills:

Regulatory Compliance: Brings advanced level skills to manage programs to establish, document and track compliance to industry and government standards and regulations, e.g. ISO-27001, PCI-DSS, HIPAA, FedRAMP, CMMC, GDPR, etc.  Researches and interprets current and pending governmental laws and regulations, industry standards and customer and vendor contracts to communicate compliance requirements to the business. Participates in industry forums monitoring developments in regulatory compliance Risk Management: Brings advanced level skills to assess the information security risk associated with existing and proposed business operational programs, systems, applications, practices and procedures in very complex, business-critical environments. Conduct and document very complex information security risk assessments and assist in the creation and implementation of security solutions and programs Cloud Security: In-depth knowledge of cloud security principles and best practices, including securing cloud infrastructure, services, and applications in platforms, OCI experience is a plus Threat and Vulnerability Management:  Brings advanced level skills to research, evaluate, track, and manage information security threats and vulnerabilities in situations where in-depth analysis of ambiguous information is required Incident Management and response:  Brings advanced level skills to respond to security events and responding in line with Oracle incident response playbooks to mitigate vulnerabilities Mentors and trains other team members Compiles information and reports for senior leadership and executive teams

 

Qualifications:

Bachelor's Degree: Computer Science, Information Technology, Cybersecurity, or a related field is typically required Master's Degree (optional but preferred): Information Security, Cybersecurity, Business Administration (with a focus on IT), or a similar field can be an added advantage 5+ years of experience managing a team focused on enterprise information security. 10+ years of experience in information systems, business operations, security operations, with a focus on incident detection, response, and vulnerability remediation Industry certifications such as CISSP, CISM, CRISC, GIAC, or OCI\AWS\GCP\Azure Security Specialty are highly preferred. Hands-on experience with security operations, incident response, cloud security (OCI, AWS, Azure, GCP), identity & access management (IAM), and data protection. Extensive experience with security frameworks, risk management, and regulatory compliance (ISO 27001, NIST, CIS Controls, GDPR, HIPAA, PCI-DSS). Solid understanding of networking protocols, operating systems (Linux, Windows), MiddleTier, Database, cloud computing and end point computing management Proven ability to collaborate across departments and influence stakeholders at all levels, including executive leadership. 

Soft Skills:

Critical Thinking & Problem Solving: Security issues often require quick, rational decision-making, especially during crises. Collaboration: You'll be working with different teams across the organization to ensure that security is integrated into every part of the business. Adaptability: Cybersecurity is a constantly evolving field, so staying adaptable to new technologies and threats is essential. Attention to Detail: Even small vulnerabilities can lead to significant issues, so attention to detail is crucial. Communication:  Excellent verbal and writing skills to communicate to wide range of audiences - technical, non-technical, executives.

Career Level - M3

Confirm your E-mail: Send Email