Job Description

Oracle Advanced Customer Services Risk Management is looking for a security professional with a passion and knack in Federal security and compliance under the NIST framework. As a member of this team, you will work closely with your peers and counterparts in operations and security engineering to support the ongoing accreditation and compliance for Federal cloud infrastructure, engage in Federal risk assessments and audits, and execute, analyze, and deliver vulnerability scans for the cloud infrastructure customers.

This role relies upon familiarity with the NIST/FedRAMP risk management framework and the assessment/audit of those security controls. You should be knowledgeable of IT Security components associated to hosted and cloud services such as: network devices, virtual or physical servers, operating systems, databases, web servers, and virtual hosts. You'll also need working knowledge in understanding threat and vulnerabilities for most of the components listed above. The candidate will be comfortable communicating and presenting status information in verbal, written, and graphic presentations.
What You'll Do:
  • Create and maintain the documentation required for federal compliance for information systems as required by NIST/FedRAMP such as: (System Security Plans (SSP) and Plan of Action and Milestones (POAMs), policy and procedure documents, etc.)
  • Identify gaps or issues with existing security control implementations and work with the team to drive remediation efforts
  • Participate in Federal information system audits in preparation, execution, and remediation
  • Collect and analyze security data and communicate for meaningful consumption
  • Track, report and drive remediation of identified vulnerabilities
  • Communicate security status and information and respond to requests inquiries of Federal customers
  • Define, document, maintain, and communicate new security requirements as the Federal compliance landscape evolves
  • Understand and report security risks and vulnerabilities being detected
  • Apply Federal DevSecOps/cybersecurity guidance as applicable to both cloud infrastructure and customer environments
  • Other ad-hoc projects
What We Like to See:
  • Possess an understanding of Information Technology security standards and Information Technology risk management frameworks such as NIST 800 special publications, FedRAMP, ISO 27001, HIPAA, ITAR, etc.
  • Possess technical foresight and the ability to understand and interpret vulnerability data and its applicability for various technologies
  • Have experience in documenting and communicating new requirements, standard operating procedures, etc. Produce risk assessment artifacts describing initial risks during system development and residual risks identified during IV&V
  • Able to analyze, interpret, and apply Federal cybersecurity guidance to customer needs
What We Love to See:
  • Experience with System Security Plans (SSP), Plan of Action and Milestones (POA&Ms), Security Assessment Report (SARs), Security Assessment Plan (SAPs)
  • Communicate the security posture of systems through designated reporting mechanism
  • Be able to adapt to changing priorities in a dynamic environment
  • Be able to multi-task, and be pro-active in addressing issues and requests quickly
  • Professional certification(s) related to information security desired
About Oracle
Big things are happening here at Oracle. As the Cloud leader, we offer the broadest suite of Cloud solutions - and we're introducing new services every month for 400,000 customers worldwide. Innovation at this level starts with our employees: we look for creative people with an entrepreneurial spirit ... those who see new possibilities and welcome new challenges.

Oracle employees enjoy industry-leading compensation and benefits, a flexible work environment, educational opportunities, and work/life tools to balance professional and personal goals.

If you're looking to elevate your career - and have fun doing it - you've come to the right place.
Life at Oracle:
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform crucial job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veteran's status or any other characteristic protected by law.

At Oracle, we don't just value differences-we celebrate them! We're committed to creating a workplace where all kinds of people work together. We believe innovation starts with diversity and inclusion.


Develops and executes programs and processes to reduce information security risk and strengthen Oracle's security posture.

Supports the strengthening of Oracle's security posture, focusing on one or more of the following: risk management; regulatory compliance; threat and vulnerability management; incident management and response; security policy development and enforcement; privacy; information security education, training and awareness (ISETA); digital forensics and similar focus areas.
Risk Management: Brings advanced level skills to assess the information security risk associated with existing and proposed business operational programs, systems, applications, practices and procedures in very complex, business-critical environments. May conduct and document very complex information security risk assessments. May assist in the creation and implementation of security solutions and programs.
Regulatory Compliance: Brings advanced level skills to manage programs to establish, document and track compliance to industry and government standards and regulations, e.g. ISO-27001, PCI-DSS, HIPAA, FedRAMP, GDPR, etc. Researches and interprets current and pending governmental laws and regulations, industry standards and customer and vendor contracts to communicate compliance requirements to the business. Participates in industry forums monitoring developments in regulatory compliance.
Threat and Vulnerability Management: Brings advanced level skills to research, evaluate, track, and manage information security threats and vulnerabilities in situations where in-depth analysis of ambiguous information is required.
Incident Management and response: Brings advanced level skills to respond to security events, identifying possible intrusions and responding in line with Oracle incident response playbooks. May operate as Incident Commander on serious incidents.
Digital Forensics: Brings advanced level skills to conduct data collection, preservation and forensic analysis of digital media independently, where an advanced understanding of forensic techniques is required.
Other areas of focus may include duties providing advanced level skills and knowledge to manage Information Security Education, Training and Awareness programs. In a Corporate Security role, may manage the creation, review and approval of corporate information security policies.
Mentors and trains other team members.
Compiles information and reports for management.

Minimum of 8 years experience in information systems, business operations, or related fields, at least 5 years of which must be from at least one of the following: Information security risk management; information security program management; Industry/Government security compliance program management (ISO-27001, GDPR, HIPAA, FedRamp, etc.); threat and vulnerability management; incident management and response; security policy development and enforcement; privacy, information security education, training and awareness (ISETA), information security solutions development, etc. required.
Strong knowledge of: Cloud architecture and security principles. Risk Management Frameworks. *nix and Windows system administration.
Experience with: Logging and log analysis. Identity management principles and technology.
Preferred but not required qualifications include: Bachelor-level university degree in a relevant field from an accredited university, or equivalent. CISSP, CISM, CISA, CIPP or other equivalent certification. Comprehensive knowledge of security design for networks, databases, infrastructure, and cloud computing. Experience writing security incident and vulnerability reports for leadership and other stakeholders. Ability to effectively communicate and influence secure product and network design in a collaborative environment. Comprehensive knowledge of digital forensics. Strong knowledge of web technologies, middleware, database, OS, firewalls, network communication protocols and methods. Knowledge of encryption technologies and architectures. Expert level experience in evaluating and assessing security threats across a variety of environments and industries. Expert level understanding of secure networking principles, routers, switches and load balancers.

If you are a Colorado resident, Please Contact us or Email us at oracle-salary-inquiries_us@oracle.com to receive compensation and benefits information for this role. Please include this Job ID: 132167 in the subject line of the email.

About Us

Innovation starts with inclusion at Oracle. We are committed to creating a workplace where all kinds of people can be themselves and do their best work. It's when everyone's voice is heard and valued, that we are inspired to go beyond what's been done before. That's why we need people with diverse backgrounds, beliefs, and abilities to help us create the future, and are proud to be an affirmative-action equal opportunity employer.

Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans status, age, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.


For over three decades, Oracle has been the center of innovation for business software—birthplace of the first commercially available relational database, the first suite of internet-based applications, and the next-generation enterprise-computing platform, Oracle Fusion. Today, Oracle provides the world's most complete, open, and integrated business software and hardware systems, with more than 370,000 customers—including 100 of the Fortune 100—representing a variety of sizes and industries in more than 145 countries around the globe. And Oracle's 104,500 global employees—including 30,000 developers working full-time on Oracle products—are critical to that success.

Oracle recruiters are always searching for brilliant employees with an entrepreneurial spirit, looking for a work culture where innovation is the goal, hard work is expected, and creativity is rewarded. Oracle employees enjoy competitive salaries, excellent health benefits, and a network of like-minded co-workers that drive innovation across the entire technology industry.