Jobs
>
Redwood City

    IT Security Analyst 3 - Redwood City, United States - Oracle

    Default job background
    Regular Employee
    Description

    At Oracle Cloud Infrastructure (OCI), we build the future of the cloud for Enterprises. We act with the speed and attitude of a start-up along with the scale and customer focus of the leading enterprise software company in the world.

    About the team:

    EES Security and Compliance team defines and measures baseline standards using existing internal policies and industry standards such as CIS and SANS. The team creates tools to proactively detect gaps with baseline compliance that improve security operations (scan failure, asset management gaps, configuration drift, and drive resolution. Technical liaisons for EES teams to analyze and prioritize vulnerabilities, compliance gaps, and security programs. Provides solution guidance to optimize remediation efforts, assist with exception requests, and resolve any process inefficiencies.

    Ideally, the candidate will possess several of the following skills:

  • Security Compliance and Auditing: Knowledge of regulatory compliance requirements (., GDPR, HIPAA, PCI, DSS, NIST) and experience with security auditing frameworks and processes
  • Cloud Security: Familiarity with cloud security principles and best practices, including securing cloud infrastructure, services, and applications in platforms, OCI is a plus
  • Security Standards: Improve security posture by defining, enhancing, and maintaining security standards based on industry leading security framework.
  • Security Architecture: Ability to assess, design, and implement security architectures, including network segmentation, secure access controls, and defense-in-depth strategies
  • Forensics and Incident Response: Experience in conducting digital forensics investigations and leading incident response activities, including evidence collection, analysis, and containment
  • Communication and Leadership: Strong leadership, interpersonal, and communication skills, with the ability to effectively communicate security-related concepts and findings to stakeholders at all levels of the organization
  • Continuous Learning and Improvement: Commitment to continuous learning and professional development in the field of cybersecurity, staying updated with the latest threats, trends, and technologies
  • Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field. Master's degree preferred
  • 8+ years of experience in information systems, business operations, or related fields,
  • 3+ years of experience in security operations, with a focus on incident detection, response, and vulnerability remediation
  • Experience with at least 1 automation language or framework (Python, PowerShell, Terraform, or vulnerability scanning tool (Qualys, Nessus,
  • Strong understanding of networking protocols, operating systems (Linux, Windows), MiddleTier, Database, and cloud computing environments
  • Experience with security tools such as SIEM platforms, intrusion detection/prevention systems, and endpoint security solutions
  • Relevant certifications such as CISSP, CISM, CISA, or GIAC certifications are preferred
  • Excellent communication skills with the ability to effectively communicate technical concepts to both technical and non-technical stakeholders
  • Proven leadership abilities with experience leading security projects and initiatives
  • Ability to work independently and collaboratively in a fast-paced environment
  • Strong analytical and problem-solving skills with a keen attention to detail
  • Career Level -

    Responsibilities:

  • Manage and address security audits as directed and liaison with internal teams for evidence as a security and compliance SME.
  • Make recommendations and provide guidance/consultation regarding process improvements necessary for remediating internal control gaps. Engage with various teams, both internal and external, around data compliance efforts.
  • Drive security risk management program with forensics investigations, and evidence collection, as a security exemption approver
  • Responsible for service impact analysis (SIA) and maintaining service resilience compliance in partnership with business owner
  • Build and publish security standards for commonly audited areas (Endpoint, Application, Network) to address gap areas and drive better compliance. Work with system administrators, engineers, and the Information System Security Manager (ISSM) to create or update system/site policies, procedures, and process guides.
  • Build automation to detect configuration gaps that impact security operations. Collaborate with cross-functional teams to design and implement security controls and countermeasures
  • Develop and maintain cybersecurity documentation such as the System Security Plan (SSP), Privacy Impact Assessment (PIA), Configuration Management Plan (CMP), Plan of Action and Milestones (POA&M), and Standard Operating Procedures (SOP) as necessary.
  • Define roles and responsibilities, process ownership, and operating model for all teams involved in security operations
  • Develop, implement, and maintain industry best practices and regulatory security policies, procedures, and system standards (servers, database, endpoint, application design)
  • Engagement in cloud security technologies and protocols, including cloud security architecture, identity and access management, and data protection
  • Write stakeholder reports using accessible language to explain the assessment and audit results and recommendations. Create and provide metrics for cybersecurity leadership. Brief executive leadership on compliance matters.
  • Disclaimer:

    Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.

    Range and benefit information provided in this posting are specific to the stated locations only

    US: Hiring Range: from $ to $ per hour; from $86,200 to $178,200 per annum. May be eligible for equity.

    Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business.
    Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

    Oracle US offers a comprehensive benefits package which includes the following:
    1. Medical, dental, and vision insurance, including expert medical opinion
    2. Short term disability and long term disability
    3. Life insurance and AD&D
    4. Supplemental life insurance (Employee/Spouse/Child)
    5. Health care and dependent care Flexible Spending Accounts
    6. Pre-tax commuter and parking benefits
    k) Savings and Investment Plan with company match
    8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
    9. 11 paid holidays
    10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
    11. Paid parental leave
    12. Adoption assistance
    13. Employee Stock Purchase Plan
    14. Financial planning and group legal
    15. Voluntary benefits including auto, homeowner and pet insurance

  • Synack

    Security Analyst

    3 days ago


    Synack San Mateo, United States Part time

    At Synack, we create technology that unleashes the best cybersecurity talent to secure our digital world. · We protect leading global organizations by reducing companies' security risk and increasing their resistance to cyber attack. How do we do this? By utilizing the world's be ...

  • Informatica

    Security Analyst

    2 weeks ago


    Informatica Redwood City, United States

    · Job Number: · 37136 · Position Title: · Intern · Build Your Career at Informatica · We're looking for a diverse group of collaborators who believe data has the power to improve society. Adventurous, work-from-anywhere minds who value solving some of the world's most challe ...

  • Allied Universal®

    SOC Security Analyst

    2 weeks ago


    Allied Universal® San Francisco, United States

    SOC Security Analyst · **Overview**: · Allied Universal, North America's leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels ...


  • Pinnacle Group Santa Clara, United States

    **Position: Cyber Security Analyst** · **Location: Santa Clara, CA (Hybrid schedule)** · **Contract Duration: 7+ Months contract-to-hire** · Qualifications: · - Bachelor degree or higher in CS, CIS, MIS or equivalent experience · - 2-5 years hands-on IT and security administratio ...


  • Ramsoftsystems inc Santa Clara, United States

    **Job Title: Information Security Manager** · **Location (Onsite, Remote, or Hybrid?): Santa Clara, CA (3 days Onsite in Mandatory (Hybrid))** · **Contract Duration: contract until 12/1/2024** · **Working Hours: 8-5 M-F PST** · **Position Overview**: · - Work with one of Company' ...


  • Lambda San Francisco Bay Area, United States

    Lambda's GPU cloud is used by deep learning engineers at Stanford, Berkeley, and Carnegie Mellon. Lambda's on-prem systems power research and engineering at Intel, Microsoft, Kaiser Permanente, major universities, and the Department of Defense. · If you'd like to build the world' ...

  • Notable Health

    Security Analyst

    1 week ago


    Notable Health San Mateo, United States

    Overview · Notable is the leading intelligent automation company for healthcare. Customers use Notable to drive patient acquisition, retention, and reimbursement, scaling growth without hiring more staff. We don't just make software. We are on a mission to fix the broken U.S. hea ...

  • Notable

    Security Analyst

    1 week ago


    Notable San Mateo, United States

    Overview · Notable is the leading intelligent automation company for healthcare. Customers use Notable to drive patient acquisition, retention, and reimbursement, scaling growth without hiring more staff. We don't just make software. We are on a mission to fix the broken U.S. he ...


  • RingCentral Belmont, United States

    Say hello to possibilities. · Internship opportunities are important. You want to make sure you land a great one where you will learn A LOT. We're RingCentral and we're happy you are considering an internship with us - we promise to make it worth your while. · First, a little a ...


  • RingCentral Belmont, United States

    Say hello to possibilities. · Internship opportunities are important. You want to make sure you land a great one where you will learn A LOT. We're RingCentral and we're happy you are considering an internship with us - we promise to make it worth your while. · First, a little a ...


  • RingCentral Belmont, United States

    Say hello to possibilities. · Internship opportunities are important. You want to make sure you land a great one where you will learn A LOT. We're RingCentral and were happy you are considering an internship with us - we promise to make it worth your while. · First, a little ab ...


  • RingCentral Belmont, United States

    Say hello to possibilities. · Internship opportunities are important. You want to make sure you land a great one where you will learn A LOT. We're RingCentral and were happy you are considering an internship with us - we promise to make it worth your while. · First, a little abou ...


  • hims & hers Palo Alto, United States

    Hims & Hers · Hims is a one-stop telehealth service for men's wellness and care, providing treatment options for hair loss, ED & more. · View company page · Hims & Hers Health, Inc. (better known as Hims & Hers) is the leading health and wellness platform, on a mission to help ...

  • Zobility

    IT Security Analyst

    3 weeks ago


    Zobility Newark, United States

    We are currently seeking an IT Security Analyst who will be monitoring computer networks for security issues. This person will also investigate cyber security incidents as well as security breaches. Our ideal candidate exhibits a can-do attitude and approaches his or her work wit ...

  • PRI Global

    IT Security Analyst

    1 week ago


    PRI Global Newark, United States

    Vertical Description: · We are currently seeking an IT Security Analyst who will be monitoring computer networks for security issues. This person will also investigate cyber security incidents as well as security breaches. Our ideal candidate exhibits a can-do attitude and approa ...


  • Special Ed Therapy Redwood City, United States

    **About Us** · **Position Description** · Epic Special Education Staffing is partnering with an exceptional school district who is looking for a contract Board Certified Behavior Analyst (BCBA) for the school year. · - Location: Redwood City, CA · - Duration: August 16, June 6, 2 ...

  • Insight Global

    Security Analyst

    3 weeks ago


    Insight Global Berkeley, United States

    Job Description · Insight Global is looking for a security analyst to join one of our largest education client's IT Division · We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are a ...

  • Harness

    Security Analyst

    5 days ago


    Harness San Francisco, United States

    Harness is a high-growth company that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably, efficiently, securely and quickly, increasing customers' pace of innovation while im ...

  • The Fountain Group

    Security Analyst

    1 week ago


    The Fountain Group Santa Clara, United States

    Title: Security Analyst · Location(s): Remote · Bid rate: $37 hourly. · Fast hire - 2-3 month assignment · W2 only, no C2C opportunities for this position. · JOB DESCRIPTION · Test application (ex, facebook, gmail, zoom,...) using browsers and/or mobile devices. · Capture the ...

  • University of California

    Security Analyst

    3 weeks ago


    University of California San Francisco, United States

    · Security Analyst · PPH-Domestic-Core-IZ · Full Time · 77068BR · Job Summary · This position supports the California Immunization System and involves work implementing and maintaining measures to safeguard the system from unauthorized access, data breaches, and cyber threat ...