Principal Security Engineer (OCI)
Oracle.com
109k - 223k USD/year
Office
Nashville, TN, United States
Full Time
At Oracle Cloud Infrastructure (OCI), we build the future of the cloud for enterprises. We act with the speed and attitude of a start-up, combined with the scale and customer focus of the leading enterprise software company in the world.
About The Team:
The Enterprise Engineering team is responsible for ensuring the security and compliance of internal systems by performing regular audits, identifying gaps in existing standards, and actively enhancing the organization’s overall security framework using automation. We are an internal security and compliance team tasked with maintaining the security of all systems and ensuring compliance with various security frameworks. Our responsibilities include performing continuous compliance assessments to ensure all systems meet required security standards and are effectively protected.
Ideally, the candidate will possess several of the following skills:
Note: The candidate is required to be in Oracle’s Nashville office – 5 days/week.
This role supports the strengthening of Oracle’s security posture, focusing on one or more of the following areas: regulatory compliance, risk management, Zero Trust Network Access (ZTNA), security policy development and enforcement, and Threat and Vulnerability Management.
- Regulatory Compliance:Brings advanced-level skills to manage programs that establish, document, and track compliance with industry and government standards and regulations (e.g., ISO 27001, PCI-DSS, HIPAA, FedRAMP, CMMC, GDPR, etc.). Researches and interprets current and pending laws, regulations, industry standards, and customer/vendor contracts to communicate compliance requirements to the business. Participates in industry forums to monitor developments in regulatory compliance.
- Risk Management: Brings advanced-level skills to assess information security risks associated with existing and proposed business operations, systems, applications, practices, and procedures in complex, business-critical environments. Conducts and documents in-depth information security risk assessments and assists in the creation and implementation of security solutions and programs.
- Cloud Security: Possesses in-depth knowledge of cloud security principles and best practices, including securing cloud infrastructure, services, and applications across platforms. OCI experience is a plus.
- Network Security: Demonstrates in-depth knowledge of network security principles and best practices, including securing network infrastructure, firewalls, VPNs, intrusion detection/prevention systems (IDS/IPS), and implementing network segmentation strategies. Experience with Zero Trust architecture and secure network design is a plus.
- Threat and Vulnerability Management: Brings advanced-level skills to research, evaluate, track, and manage information security threats and vulnerabilities in situations requiring in-depth analysis of ambiguous information.
- Mentors and trains other team members.
- Compiles and presents security and compliance reports to management.
Career Level - IC4
Responsibilities
- Develop and manage information security governance, including the creation of policies, procedures, standards, baselines, and guidelines to ensure the secure operation of information systems.
- Build application security framework review processes (e.g., OWASP Top 10) to identify vulnerabilities such as SQL injection, XSS, and insecure APIs.
- Design secure system architectures in the cloud, incorporating zero-trust security models, network segmentation, and access control mechanisms.
- Monitor network traffic and security events to detect and respond to potential threats and vulnerabilities.
- Conduct regular vulnerability assessments and penetration tests on network and cloud infrastructure.
- Support the configuration and management of firewalls, VPNs, IDS/IPS, and cloud-native security tools to safeguard network perimeters and segments.
- Perform code reviews and security testing (e.g., SAST, DAST); enforce secure coding practices across the SDLC pipeline using CI/CD tools (e.g., Jenkins, Git, GitHub Actions, Artifactory, SonarQube); manage secrets, software composition analysis (SCA), and open-source tools.
- Build, develop, and monitor configuration management automation and infrastructure-as-code (IaC) strategies to achieve a secure-by-design framework.
- Monitor information systems for security incidents and vulnerabilities; develop visibility capabilities and reporting on incidents, trends, and vulnerabilities for IT and executive management.
- Demonstrate proven leadership in independently leading security projects and initiatives using Agile or Waterfall methodologies.
- Architect, design, implement, maintain, and operate information system security controls and countermeasures; train and supervise personnel in system administration and operations; document usage, operations, and expected outcomes.
- Develop and maintain cybersecurity documentation, including the System Security Plan (SSP), Privacy Impact Assessment (PIA), Configuration Management Plan (CMP), Plan of Action and Milestones (POA&M), and Standard Operating Procedures (SOP), as required.
- Create stakeholder reports summarizing assessment and audit findings with actionable recommendations. Provide metrics to cybersecurity leadership and brief executive teams on compliance matters.
- Participate in internal and external audits, providing executive leadership with clear briefings on compliance issues, audit results, assessment findings, and recommended corrective actions.
This team is targeting candidates in the U.S. who can work ONSITE in Nashville-TN. Relocation Assistance provided. (This is not a remote position)
Visa sponsorship is not available for this position.
Qualifications
- Bachelor’s degree in computer science, Information Security, or related field; Master’s degree preferred.
- 10+ years of experience in cybersecurity, security architecture, or related technical security roles, with a focus on securing cloud environments, automation workflows, incident detection and response, and vulnerability remediation.
- Industry certifications such as CISSP, OSCP, CISM, GIAC, or cloud security specialties (OCI, AWS, Azure) are highly preferred.
- Proven expertise in security architecture, threat modeling, and risk management at an enterprise level.
- Strong knowledge of network security, cloud security (OCI, AWS, Azure, GCP), endpoint security, operating systems (Linux, Windows), middleware, databases, and identity management.
- Experience developing and enforcing security policies, governance frameworks, and compliance controls aligned with standards such as NIST, ISO 27001, SOC 2, GDPR, HIPAA, etc.
- Hands-on experience with firewalls, SIEM tools, IDS/IPS, EDR solutions, and security automation technologies.
- Demonstrated ability to oversee security incident response, forensic analysis, red/blue team operations, and the containment and remediation of cyber threats.
- Strong understanding of cryptography, secure coding practices, zero-trust architecture, and identity and access management (IAM).
- Proficient in scripting languages such as Bash, Python, Perl, or YAML, and experienced with infrastructure-as-code tools like Terraform or CloudFormation.
- Familiarity with container orchestration platforms such as Kubernetes, OpenShift, EKS, AKS, as well as container image scanning and vulnerability management.
- Excellent communication skills, capable of clearly conveying technical concepts to both technical and non-technical audiences, with strong written and verbal proficiency.
Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.
Range and benefit information provided in this posting are specific to the stated locations only
US: Hiring Range in USD from: $109,200 to $223,400 per annum. May be eligible for bonus and equity.
Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto, homeowner and pet insurance
The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.
Career Level - IC4
As a world leader in cloud solutions, Oracle uses tomorrow’s technology to tackle today’s challenges. We’ve partnered with industry-leaders in almost every sector—and continue to thrive after 40+ years of change by operating with integrity.
We know that true innovation starts when everyone is empowered to contribute. That’s why we’re committed to growing an inclusive workforce that promotes opportunities for all.
Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.
We’re committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing accommodation-request_mb@oracle.com or by calling +1 888 404 2494 in the United States.
Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
Principal Security Engineer (OCI)
Office
Nashville, TN, United States
Full Time
109k - 223k USD/year
September 25, 2025