DescriptionOur rapidly growing team specializes in threat hunting analyzing indicators of compromise (IOCs) investigating security incidents managing incident responses and conducting digital forensics across IaaS PaaS and SaaS this role you will be part of a dedicated security operations team leveraging data loss prevention case management tools and developing automation to detect and respond to security threats in real time. Additionally you will play a critical role in designing and implementing data loss prevention strategies to proactively mitigate potential data security risks. As the last line of defense when security controls are breached your expertise will be instrumental in securing Oracles data and infrastructure.
The ideal candidate is a proactive self-starter with a strong sense of ownership accountability and capable of delivering effective results under pressure. By bringing deep expertise in security engineering you will help drive the strategic development of our enterprise security threat program. An acute attention to detail and a tenacious investigative and analytical approach will be key to success.
The Role
We are seeking a seasoned security engineering professional to join our T1/2 DLP operations team to investigate alerts through tooling and perform triage and response to DLP related events. Support build-out of advanced security tools processes and automation to identify and mitigate risks related to proprietary data across OCI and Oracles broader enterprise. You will drive sensitive investigations conduct thorough root cause analyses and work collaboratively with partner teamsincluding SOC digital forensics incident response physical security and engineeringto respond effectively to diverse and sophisticated threats.
ResponsibilitiesKey Responsibilities
- Incident Investigation and Response: Analyze DLP security alerts through DLP intake systems and escalated through DLP tools and case management triage investigate and respond to potential security incidents and coordinate appropriate incident response actions.
- Advanced Threat Analysis:Assess and triage complex DLP events (alerts) across OCI and the Oracle enterprise CSP environments using security monitoring tools logs and threat intelligence to identify indicators of compromise and recommend remediation steps.
- Monitor and Analyze User Activity: Continuously monitor analyze and investigate user behaviors and activities across networks applications and endpoints to detect suspicious patterns or potential insider threats.
- Build and Maintain Detection and Response Systems: Develop implement and manage tools analytics and automated detection systems specifically designed to identify potentially malicious activity.
- Data Loss Prevention (DLP): Participate with the DLP team to enhance data loss prevention strategies including deploying and tuning DLP technologies to prevent unauthorized access or transmission of sensitive proprietary data.
- Incident Investigations: Conduct thorough investigations of security incidents related to potential or confirmed threats collaborating closely with legal HR and compliance teams as needed.
- Case Management: Document and manage cases from detection through to resolution ensuring proper documentation and reporting processes are followed.
- Security Awareness and Training: Support the development and delivery of targeted security awareness training at all levels of the company. Training to be focused on reducing data security risk and how to recognize and report suspicious behaviors.
- Collaboration and Coordination: Work with cross-functional teams such as HR legal compliance physical security and other engineering organizations to coordinate incident response and security policy and standards of enforcement.
- Threat Hunting: Proactively hunt for evidence of threats by analyzing system logs access records and behavioral analytics.
- Tool and Process Enhancement: Evaluate and recommend improvements to detection tools response processes and operational playbooks.
- Reporting and Analytics: Prepare reports and metrics on insider threat trends investigation outcomes and security posture for management and leadership.
Preferred Qualifications
- Five years of experience in DLP (client/server/cloud) incident response and/or security operations center activities at a cloud service provider
- Effective written and oral communications skills with the ability to deliver technical information to non-technical staff
- Comfortable working in an ambiguous fast-paced unpredictable environment
- Experience working in a highly collaborative team centric event driven operations team
- Experience with variety of technologies and how they are used to exfiltrate data
- Experience with a variety of DLP tools (data at rest data in motion data in use)
- Experience with a wide variety of logs and telemetry including AV web server SIEM etc.
- Experience with sophisticated threat actors and complex security incidents
- Understanding of insider threat actor tactics techniques and procedures (TTPs) and threat analysis models like MITRE ATT&CK Framework
- Experience developing and hunting using DLP-related indicators of compromise (IOCs)
- Experience performing open-source research on a variety of topics
QualificationsDisclaimer:
Certain US customer or client-facing roles may be required to comply with applicable requirements such as immunization and occupational health mandates.Range and benefit information provided in this posting are specific to the stated locations onlyUS: Hiring Range in USD from: $82200 to $178100 per annum. May be eligible for bonus and equity.
Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge skills experience market conditions and locations as well as reflect Oracles differing products industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
Oracle US offers a comprehensive benefits package which includes the following:
1. Medical dental and vision insurance including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto homeowner and pet insurance
The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.
Career Level - IC3