HM Note: This hybrid contract role is three (3) days in office. Candidates resume must include first and last name.
Description
Role Overview and nbsp;
As the Senior Lead Security Architect for OCI you will spearhead security-by-design consultative engagements and develop reusable repeatable cloud application patterns tailored to Oracle Cloud Infrastructure. Youll lead client-facing assessments drive secure by design architecture reviews and ensure robust security controls across OCI environments. and nbsp;
and nbsp;
Key Responsibilities and nbsp;
- Lead enterprise security-architecture and design reviews for OCI-based solutions (IaaS PaaS SaaS). and nbsp;
- Perform client engagements: threat modeling gap analysis risk assessments and security-control recommendations aligned to internal standards. and nbsp;
- Develop and maintain reusable security reference architectures and deployment patterns for OCI workloads. and nbsp;
- Collaborate with application network and operations teams to translate business requirements into secure solution designs. and nbsp;
- Advise on and validate implementation of OCI security servicesIdentity and Access Management Vault (KMS) Data Safe Cloud Guard Web Application Firewall Logging and amp; Monitoring. and nbsp;
- Integrate OCI environments with enterprise SIEM platforms (Splunk Cloud) and SOAR workflows. and nbsp;
- Facilitate architecture review boards design-approval gates and governance processes. and nbsp;
- Stay current on OCI service enhancements and industry best practices to continuously evolve the security architecture. and nbsp;
and nbsp;
General Skills and nbsp;
- Leadership in developing and implementing technical security architectures and nbsp;
- Experience across multiple cloud platforms (AWS Azure GCP OCI) and enterprise security services and nbsp;
- Strong understanding of application architecture networking and security operations and nbsp;
- Proficiency with structured methodologies for cloud application design and deployment and nbsp;
- Systems analysis and design experience within large secure solution environments and nbsp;
- Familiarity with ITIL processes and the ability to guide teams in its application and nbsp;
- Ability to translate business requirements into technical security solutions and nbsp;
- Expertise preparing conceptual logical and physical process and data models and nbsp;
- Track record of developing recommending and managing technical security architecture and nbsp;
- Awareness of emerging technologies industry trends and best practices and nbsp;
- Excellent analytical problem-solving decision-making and negotiation skills and nbsp;
- Clear verbal and written communication; strong interpersonal and stakeholder-management abilities and nbsp;
- Team player with a proven record of meeting deadlines and collaborating across disciplines and nbsp;
- Solid understanding of information-management security principles concepts policies and practices and nbsp;
Skills
Experience and Skill Set Requirements
OCI Specific Security Experience and Controls (45%) and nbsp;
- Identity and amp; Access Management: OCI IAM policies compartments SSO MFA PKI and nbsp;
- Data Security: Oracle Vault (KMS) Data Safe (encryption activity monitoring) Transparent Data Encryption Tokenization and nbsp;
- Threat Detection and amp; Remediation: Cloud Guard Web Application Firewall Logging and amp; Monitoring and nbsp;
- Network Security: Virtual Cloud Networks Network Security Groups firewalls SASE architectures and nbsp;
- SIEM and amp; CSOC Integration: Splunk Cloud SOAR orchestration alerting and response workflows and nbsp;
Senior Architecture and amp; Design Expertise (35%) and nbsp;
- Threat modeling and secure-by-design reference architectures for OCI workloads (IaaS PaaS SaaS) and nbsp;
- Frameworks: TOGAF NIST CSF CIS Controls SACM and nbsp;
- Infrastructure as code: Terraform OCI CLI/SDK DevSecOps pipelines and nbsp;
- Development of reusable cloud security patterns design-review workshops and governance gates and nbsp;
- Production of conceptual logical and physical architecture diagrams and documentation and nbsp;
Agile Delivery and amp; Collaboration (15%) and nbsp;
- Hands-on experience in Agile teams: backlog grooming user stories Scrum ceremonies sprint delivery and nbsp;
- Stakeholder engagement: business owners DevOps enterprise architects vendor partners and nbsp;
- Clear articulation of complex security concepts to both technical and non-technical audiences and nbsp;
Public Sector and amp; Regulatory (5%) and nbsp;
- Previous public sector work experience is considered a positive and nbsp;
- Prior work in government or regulated industries (e.g. FIPPA SOC 2 PCI DSS) is an asset and nbsp;
and nbsp;
Must-haves:
- Security architecture and design with Oracle Cloud Infrastructure.
- Client Relationship Building skills.