Third-Party Security Advisor

Oracle


Job Location:

Nashville, IN - USA

Yearly Salary: $ 104200 - 234600
Posted on: 9 days ago
Vacancies: 1 Vacancy

Job Summary

Description

Oracle Security is seeking an experienced individual contributor to support and mature the intake function within the Third-Party Risk Management program.

This role will serve as a key front-door control point for third-party risk demand helping ensure supplier product service SaaS tooling and integration requests are identified early triaged consistently and routed to the appropriate TPRM path. The role will work across onboarding procurement security architecture legal privacy business stakeholders and other security teams to determine whether a supplier requires standard assessment support deeper risk review reuse of an existing assessment or supplier incident / breach follow-up.

The successful candidate will help shift TPRM earlier into the supplier lifecycle improve visibility of third-party technology and service risk reduce ad hoc intake and support scalable decision-making across Oracles broad supplier ecosystem.



Responsibilities

Intake and Triage

  • Manage incoming third-party risk requests from onboarding procurement security architecture business stakeholders security teams and related intake channels.
  • Review supplier product service and engagement details to determine whether TPRM involvement is required.
  • Validate whether incoming requests contain sufficient information to support triage routing and assessment scoping.
  • Identify whether the request relates to a new supplier existing supplier changed scope new integration sensitive data customer-impacting service or elevated-risk activity.
  • Route requests into the appropriate TPRM path: no action / reuse standard assessment deep dive or breach / incident support.
  • Help reduce fragmented informal or late-stage demand by establishing a more consistent front-door process.

Assessment Reuse and Routing

  • Check whether an existing TPRM assessment supplier profile tiering decision or risk output can be reused.
  • Determine whether the suppliers current use case materially changes the previous risk position.
  • Reduce duplicate assessments by ensuring existing risk decisions are leveraged where current and applicable.
  • Escalate higher-risk unclear or materially changed requests for deep-dive consideration.
  • Ensure downstream teams receive concise actionable TPRM outputs that allow work to continue without unnecessary rework.

Supplier Entry-Point Integration

  • Support integration of TPRM into supplier approval workflows.
  • Help identify third-party IT tools SaaS integrations and services that should trigger TPRM review.
  • Partner with Security Architecture Procurement Legal Privacy and LoB stakeholders to improve early supplier risk detection.
  • Capture and categorize intake demand signals to support future automation reporting and control improvement.
  • Help move TPRM from reactive assessment support toward earlier supplier lifecycle control.

Operational Governance and Data Quality

  • Maintain accurate intake records supplier routing decisions assessment status and key risk indicators in approved tracking systems.
  • Support the development of intake rules triage criteria minimum data requirements decision trees and process documentation.
  • Identify recurring intake gaps unclear ownership points and opportunities to simplify or automate routing.
  • Help maintain linkage between intake supplier tiering assessment activity findings continual monitoring services and future capabilities.
  • Support clean handoffs between intake standard assessment activity deep-dive work and breach / incident follow-up.

Breach and Incident Signal Support

  • Support initial supplier-risk triage for supplier breach ransomware malware certificate compromise data exposure and other third-party incident signals.
  • Help determine whether Oracle may be impacted by a supplier event.
  • Gather key information such as affected services data exposure compromise window containment evidence Oracle dependencies and recommended actions.
  • Route supplier incident matters to the appropriate internal teams where deeper security legal privacy customer product or infrastructure review is required.
  • Ensure supplier incident signals feed back into reassessment findings management continual monitoring and supplier risk records.

Minimum Qualifications

  • Bachelors degree in Information Security Cybersecurity Computer Science Information Technology Risk Management Business Supply Chain Procurement or a related field or equivalent practical experience.
  • 5 years of experience in third-party risk management supplier risk cybersecurity risk technology risk vendor management procurement risk security governance compliance or related security operations.
  • Experience triaging supplier SaaS product service tooling integration or data-use requests and routing them to the appropriate risk security legal privacy procurement or business review path.
  • Experience supporting third-party risk assessments supplier due diligence risk tiering assessment reuse or supplier control review activities.
  • Experience working with cross-functional stakeholders and producing clear written risk routing or assessment outputs.

Preferred Qualifications

  • Experience in a large complex multinational technology cloud or regulated enterprise environment.
  • Experience supporting supplier onboarding procurement security architecture privacy legal or incident-response workflows.
  • Familiarity with supplier incident triage including ransomware malware data exposure certificate compromise service compromise or other third-party breach signals.
  • Familiarity with supplier assurance evidence including SOC 2 ISO 27001 SIG CAIQpenetration test summaries security questionnaires or equivalent materials.
  • Experience with Jira GRC tooling procurement platforms supplier management systems or continuous monitoring platforms.
  • Relevant professional certification such as CISSP CISM CISA CRISC ISO 27001 or equivalent.


Qualifications
Disclaimer:

Certain U.S. based or U.S. customer or client-facing roles may be required to comply with applicable requirements such as immunization/occupational health mandates and/or drug testing requirements.

Range and benefit information provided in this posting are specific to the stated locations only

US: Hiring Range in USD from: $104200 to $234600 per annum. May be eligible for bonus equity and compensation deferral.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge skills experience market conditions and locations as well as reflect Oracles differing products industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following:
1. Medical dental and vision insurance including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto homeowner and pet insurance

The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.

Career Level - IC4





Required Experience:

Unclear Seniority

DescriptionOracle Security is seeking an experienced individual contributor to support and mature the intake function within the Third-Party Risk Management program.This role will serve as a key front-door control point for third-party risk demand helping ensure supplier product service SaaS tooling...

About Company

Company Logo

As a world leader in cloud solutions, Oracle uses tomorrow’s technology to tackle today’s challenges. We’ve partnered with industry-leaders in almost every sector—and continue to thrive after 40+ years of change by operating with integrity. We know that true innovation starts when eve ... View more

View Profile View Profile