Job was saved successfully.
Job was removed from Saved Jobs.

Job Details


Oracle

Senior Pen Tester/DevSecOps Security Engineer

Technology

Senior Network Engineer

No

Bloomington, Minnesota, United States

"Responsible for the planning, design and build of security architectures; oversees the implementation of network and computer security and ensures compliance with corporate security policies and procedures.Responsible for advanced planning, design and build of security systems, applications, environments and architectures; oversees the implementation of security systems, applications, environments and architectures and ensures compliance with information security standards and corporate security policies and procedures. Provides technical advice and direction to support the design and development of secure architectures. May participate in an incident management team, bringing advanced-level skills to respond to security events in line with Oracle incident response playbooks. Investigates purported intrusions and breaches, and oversees root cause analysis. Coordinates incidents with other business units and may act as Incident Commander of serious incidents. Develops new methods, and playbooks, as well as sophisticated scripts, applications, and tools, and trains others in their use. May participate in an incident management team, responding to security events in line with Oracle incident response playbooks. Investigates purported intrusions and breaches, and oversees root cause analysis. Coordinates incidents with other business units and may act as incident commander of serious incidents. Participates in developing new methods, playbooks throughout Oracle. Evaluates existing and proposed technical architectures for security risk, provides technical advice to support the design and development of secure architectures and recommends security controls to mitigate those risks. Evaluations of internal security architecture may include design assessment, risk assessment, and threat modeling. Brings advanced-level skills to research, evaluate, track, and manage information security threats and vulnerabilities in situations where in-depth analysis of ambiguous information is required, and where computer programming/scripting knowledge is required. Work with Senior management to develop and implement a multi-year security roadmap Focus on operational and strategic level tasks, and provide counsel and guidance to the junior level security operations engineers in the department.Minimum of 8 years related experience in an information security role supporting security programs and security engineering/architecture in complex enterprise environments. Hands on experience with enterprise security architecture, engineering and implementation required. Knowledge of compliance program security controls, like ISO 27001, SOC 2, HITRUST, and FedRAMP, as applied to cloud SaaS, PaaS and IaaS operations. Familiarity with SDLC principles and scripting & programming languages (such as Terraform, Python, and Ruby). Strong knowledge of: Cloud architecture and security principles. Risk Management Frameworks. **nix and Windows system administration. Experience with: Logging and log analysis. Identity management principles and technology. Preferred but not required qualifications include: Bachelor-level university degree in a relevant field from an accredited university, or equivalent. Strong knowledge of web technologies, middleware, database, OS, firewalls, network communication protocols and methods. Knowledge of database security principles. Knowledge of encryption technologies and architectures. Expert level experience in evaluating and assessing security threats across a variety of environments and industries. Expert level understanding of secure networking principles, routers, switches and load balancers.*This is a remote/office based position which may be performed anywhere in the United States except for within the state of Colorado.**Oracle is an Affirmative Action-Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veterans status, age, or any other characteristic protected by law.**Senior DevSecOps Security Engineer**NOTE: We are unable to provide visa sponsorship for this role at this time. No candidates requiring visa sponsorship will be considered.**Role description:*** *** *** *** *** *** *** ***This is a security focused role that will provide security testing, oversight and assistance for operations and QA engineers responsible for incorporating security testing into the CI/CD pipelines as regular part of SDLC for Oracle Cloud applications in the Federal space. This role will be responsible for conducting regular security and penetration tests on applications at different points during the development lifecycle to validate efficiency of the security testing program, ensure compliance to required federal controls and initiate necessary adjustments. This role will be involved in the NIST 800-53 System and Services Acquisition control area ensuring that security requirements are incorporated into organizational information systems and that developers possess the requisite security expertise and skills. In addition, this role will be involved in the NIST 800-53System and Information Integritycontrol family to ensure that controls regarding flaw remediation are in place in accordance with the requirements. Finally, this role will coordinate with the Federal Security, Risk and Compliance team to ensure that the Security Impact Analysis process is in place and being followed during change and release management.This individual should be collaborative and a team player as the role will work across many teams.*Mandatory qualifications:*** *** *** *** *** *** *** ***U.S. CitizenB.S. Computer ScienceLinux shell scripting experienceExperience automating CI/CD pipeline including SAST/DAST/Fuzzing5 years of experience testing web, mobile, and API interfaces via automation and manual effortAble to work independently in a fast paced DevSecOps environmentWorking knowledge of NIST 800-53 controls that impact the software development lifecycle*Desired qualifications*** *** *** *** *** *** *** ***Experience with Security Impact Analysis (SIA) for application and environment changes as part of change controlKubernetes, Istio, Oracle Database, Cloud (OCI Preferred)**Job:** **Information Security Engineering***Organization:** **Oracle***Title:** *Senior Pen Tester/DevSecOps Security Engineer***Location:** *United States***Requisition ID:** *21000AAI*"