Senior Security Systems Developer - Santa Ana, Costa Rica - Oracle

    Oracle
    Oracle Santa Ana, Costa Rica

    hace 2 semanas

    Default job background
    Regular Employee
    Descripción

    Responsibilities

  • Responsible for advanced planning, design and build of security systems, applications, environments and architectures; oversees the implementation of security systems, applications, environments and architectures and ensures compliance with information security standards and corporate security policies and procedures.
  • May participate in an incident management team, bringing advanced-level skills to respond to security events in line with Oracle incident response playbooks.
  • Investigates purported intrusions and security events, and oversees root cause analysis.
  • Coordinates incidents with other business units and may act as Incident Commander of serious incidents.
  • Develops new methods, and playbooks, as well as sophisticated scripts, applications, and tools, and trains others in their use.
  • Evaluates existing and proposed technical architectures for security risk, provides technical advice to support the design and development of secure architectures and recommends security controls to mitigate those risks.
  • Evaluations of internal security architecture may include design assessment, risk assessment, and threat modeling.
  • Work with Senior leadership to develop and implement a multi-year security roadmap
  • Focus on operational and strategic level tasks, and provide counsel and guidance to the junior level security operations engineers in the department.
  • Qualifications

  • Minimum of 8 years related experience in an information security role supporting security programs and security engineering/architecture in complex enterprise environments.
  • Hands on experience with enterprise security architecture, engineering and implementation required.
  • Knowledge of compliance program security controls, like ISO 27001, SOC 2, HITRUST, PCI-DSS and FedRAMP, as applied to cloud SaaS, PaaS and IaaS operations.
  • Familiarity with SDLC principles and scripting & programming languages (such as Terraform, Python, and Ruby).
  • Strong knowledge of: Cloud architecture and security principles. Risk Management Frameworks. *nix and Windows system administration.
  • Experience with: Microsegmentation methods and technologies. Containers and orchestration platforms. Logging and log analysis. Identity management principles and technology. Database security and technologies. CI/ CD and DevOps methodologies.
  • Preferred but not required qualifications include: Bachelor-level university degree in a relevant field from an accredited university, or equivalent. Strong knowledge of web technologies, middleware, database, OS, firewalls, network communication protocols and methods. Knowledge of database security principles. Knowledge of encryption technologies and architectures. Expert level experience in evaluating and assessing security threats across a variety of environments and industries. Expert level understanding of secure networking principles, routers, switches and load balancers.
  • Career Level - IC3

    Responsible for basic planning, design and build of security systems, applications, environments and architectures; oversees the implementation of security systems, applications, environments and architectures and ensures compliance with information security standards and corporate security policies and procedures.
    Assist in development of incident response capabilities, training, and tool validation.
    May research, evaluate, track, and manage information security threats and vulnerabilities in situations where analysis of well-understood information is required and where computer programming/scripting knowledge is required.
    May participate in an incident management team, responding to security events in line with Oracle incident response playbooks. Investigates purported intrusions and breaches, and oversees root cause analysis. Coordinates incidents with other business units and may assist the Incident Commander during serious incidents. Participates in developing new methods, and playbooks, as well as basic scripts, applications, and tools.
    Research industry trends and constantly assess current controls and threat posture of new and existing products and services.
    Recommend and implement new security controls across Oracle's line of business (LOB).
    Improve current processes and workflows to minimize manual efforts.

    Disclaimer:

    Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.

    Range and benefit information provided in this posting are specific to the stated locations only

    US: Hiring Range: from $87,000 to $178,200 per annum. May be eligible for bonus and equity.

    Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business.
    Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

    Oracle US offers a comprehensive benefits package which includes the following:
    1. Medical, dental, and vision insurance, including expert medical opinion
    2. Short term disability and long term disability
    3. Life insurance and AD&D
    4. Supplemental life insurance (Employee/Spouse/Child)
    5. Health care and dependent care Flexible Spending Accounts
    6. Pre-tax commuter and parking benefits
    k) Savings and Investment Plan with company match
    8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
    9. 11 paid holidays
    10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
    11. Paid parental leave
    12. Adoption assistance
    13. Employee Stock Purchase Plan
    14. Financial planning and group legal
    15. Voluntary benefits including auto, homeowner and pet insurance