Senior Security Engineer

Oracle
NC, United States
$87K-$178.2K a year
Full-time

Do you want to advance your career with the world’s first cloud company? Since 1998, Oracle NetSuite has been on a mission to deliver an agile, unified application suite that gives leaders a complete view into their business.

Our team is growing, and we’re looking for people like you to help us make a global impact.

As the leading cloud business system, NetSuite includes financials, inventory management, HR, professional services automation, commerce, and more.

Tens of thousands of customers all over the world trust NetSuite to give their businesses the visibility, agility, and control needed to make data-informed decisions quickly.

NetSuite is a place where you can build your career and have fun while doing so! We’re invested in our people, our customers, and the community.

As part of Oracle, our benefits are second to none. Joining our passionate team means that you’re ready to take your career to the next level.

With priceless learning opportunities, strong support, incredible innovation, and volunteer opportunities, NetSuite is committed to creating a workplace where everyone feels empowered and set up for success.

Responsibilities

Responsible for advanced planning, design and build of security systems, applications, environments and architectures;

oversees the implementation of security systems, applications, environments and architectures and ensures compliance with information security standards and corporate security policies and procedures.

  • May participate in an incident management team, bringing advanced-level skills to respond to security events in line with Oracle incident response playbooks.
  • Investigates purported intrusions and security events, and oversees root cause analysis.
  • Coordinates incidents with other business units and may act as Incident Commander of serious incidents.
  • Develops new methods, and playbooks, as well as sophisticated scripts, applications, and tools, and trains others in their use.
  • Evaluates existing and proposed technical architectures for security risk, provides technical advice to support the design and development of secure architectures and recommends security controls to mitigate those risks.
  • Evaluations of internal security architecture may include design assessment, risk assessment, and threat modeling.
  • Work with Senior leadership to develop and implement a multi-year security roadmap
  • Focus on operational and strategic level tasks, and provide counsel and guidance to the junior level security operations engineers in the department.

Qualifications

  • Minimum of 8 years related experience in an information security role supporting security programs and security engineering / architecture in complex enterprise environments.
  • Hands on experience with enterprise security architecture, engineering and implementation required.
  • Knowledge of compliance program security controls, like ISO 27001, SOC 2, HITRUST, PCI-DSS and FedRAMP, as applied to cloud SaaS, PaaS and IaaS operations.
  • Familiarity with SDLC principles and scripting & programming languages (such as Terraform, Python, and Ruby).
  • Strong knowledge of : Cloud architecture and security principles. Risk Management Frameworks. *nix and Windows system administration.
  • Experience with : Microsegmentation methods and technologies. Containers and orchestration platforms. Logging and log analysis.

Identity management principles and technology. Database security and technologies. CI / CD and DevOps methodologies.

Preferred but not required qualifications include : Bachelor-level university degree in a relevant field from an accredited university, or equivalent.

Strong knowledge of web technologies, middleware, database, OS, firewalls, network communication protocols and methods. Knowledge of database security principles.

Knowledge of encryption technologies and architectures. Expert level experience in evaluating and assessing security threats across a variety of environments and industries.

Expert level understanding of secure networking principles, routers, switches and load balancers.

Career Level - IC3

Responsible for basic planning, design and build of security systems, applications, environments and architectures; oversees the implementation of security systems, applications, environments and architectures and ensures compliance with information security standards and corporate security policies and procedures.

Assist in development of incident response capabilities, training, and tool validation.

May research, evaluate, track, and manage information security threats and vulnerabilities in situations where analysis of well-understood information is required and where computer programming / scripting knowledge is required.

May participate in an incident management team, responding to security events in line with Oracle incident response playbooks.

Investigates purported intrusions and breaches, and oversees root cause analysis. Coordinates incidents with other business units and may assist the Incident Commander during serious incidents.

Participates in developing new methods, and playbooks, as well as basic scripts, applications, and tools.

Research industry trends and constantly assess current controls and threat posture of new and existing products and services.

Recommend and implement new security controls across Oracle’s line of business (LOB).

Improve current processes and workflows to minimize manual efforts.

Disclaimer :

Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.

Range and benefit information provided in this posting are specific to the stated locations only

US : Hiring Range : from $87,000 to $178,200 per annum. May be eligible for bonus and equity.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.

Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following :

1. Medical, dental, and vision insurance, including expert medical opinion

2. Short term disability and long term disability

3. Life insurance and AD&D

4. Supplemental life insurance (Employee / Spouse / Child)

5. Health care and dependent care Flexible Spending Accounts

6. Pre-tax commuter and parking benefits

7. 401(k) Savings and Investment Plan with company match

8. Paid time off : Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position.

Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment.

Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.

9. 11 paid holidays

10. Paid sick leave : 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.

11. Paid parental leave

12. Adoption assistance

13. Employee Stock Purchase Plan

14. Financial planning and group legal

15. Voluntary benefits including auto, homeowner and pet insurance

The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.

30+ days ago
Related jobs
Promoted
VirtualVocations
Charlotte, North Carolina

A company is looking for a Senior/Lead Security Engineer - IAM/IGA - Identity Governance and Administration. ...

Promoted
GXO Logistics
High Point, North Carolina
Remote

As the Senior Engineer, Information Security (DFIR), you'll be responsible for performing, facilitating, and documenting the complex analysis, development and testing of security methodologies and technologies. Knowledge of the corporate cybersecurity threat landscape, cyber threats and vulnerabilit...

Promoted
VirtualVocations
Charlotte, North Carolina

A company is looking for a Senior Engineer, IT Systems. ...

GXO Logistics
Charlotte, North Carolina
Remote

As the Senior Engineer, Information Security (DFIR), you'll be responsible for performing, facilitating, and documenting the complex analysis, development, and testing of security methodologies and technologies. Senior Engineer, Information Security (DFIR) - Remote. Knowledge of the corporate cybers...

Promoted
VirtualVocations
Durham, North Carolina

A company is looking for a Senior Cloud Security Engineer to enhance its cloud security capabilities. ...

WELLS FARGO BANK
Charlotte, North Carolina

Provide security consulting on medium projects for internal clients to ensure conformity with corporate information, security policy, and standards. Design, document, test, maintain, and provide issue resolution recommendations for moderately complex security solutions related to networking, cryptog...

GXO
NC, United States
Remote

As the Senior Engineer, Information Security (DFIR), you’ll be responsible for performing, facilitating, and documenting the complex analysis, development and testing of security methodologies and technologies. Knowledge of the corporate cybersecurity threat landscape, cyber threats and vulnerabilit...

Surescripts
Raleigh, North Carolina

The Senior Cloud Security Engineer - GCP helps architect, deploy, and operate the security cloud infrastructure that aligns with business needs. Along with security leadership, the Senior Cloud Security Engineer - GCP will consistently assess the threat landscape and adapt quickly to protect the bus...

Truist
Charlotte, North Carolina

Develop and maintain technical IT/cyber capabilities including all phases of the software development lifecycle and software stack which includes threat modeling of application designs, static application security testing (SAST), software composition analysis (SCA), dynamic application security test...

Celonis
Raleigh, North Carolina

Celonis is looking for talented senior security engineers to join our Security Engineering Org. Collaborate with Security and Engineering teams to incorporate strong security controls, apply security best practices in our development life cycle, and mitigate risks and security vulnerabilities. The s...