Über
Authoritative design: Publish security/compliance reference architectures, control baselines, evidence standards, and implementation patterns; lead cross-org reviews that raise the bar on auditability and continuous assurance.
Build compliance into the cloud: Partner with core service teams (compute, networking, storage, virtualization, container/orchestration, service mesh) to drive secure-by-default and compliant-by-default designs, with controls that are measurable and operationally sustainable.
Frameworks ? controls: Translate regulatory and customer requirements into engineering-ready controls, acceptance criteria, and implementation guidance across regimes including (but not limited to) NIST-800, SOC 2, ISO 27001, ISO 42001, PCI, FedRAMP, GDPR, and regional frameworks-ensuring mappings are rationalized and scalable across multiple regimes.OSCAL ownership: Directly write, curate, and own OSCAL artifacts (e.g., catalogs/profiles/component definitions and related content as applicable), and establish scalable operating models (templates, review workflows, QA checks) so teams can contribute and maintain artifacts over time.
Compliance-as-code: Drive adoption of policy-as-code and compliance-as-code approaches (automated control validation, CI/CD gates, drift detection, and standardized attestations) to reduce manual audit effort and improve consistency.
Evidence engineering: Design and standardize evidence collection pipelines with lineage, traceability, retention, and quality controls; ensure evidence is high-signal, reproducible, and mapped to controls and system boundaries-prioritizing automation, normalization, and audit-ready reporting.
Continuous monitoring & remediation: Design scalable mechanisms to continuously detect control drift and drive remediation (automated and/or workflow-driven), with clear metrics and accountability for sustained compliance outcomes.
Risk, compliance, and safety: Partner with privacy, legal, and security stakeholders to incorporate privacy-by-design and AI governance needs (e.g., ISO 42001) into engineering controls and evidence strategies-especially for AI-enabled applications and services.
Incident leadership (compliance perspective): Ensure compliance controls remain resilient through incidents and major changes; drive post-incident reviews and systemic improvements to guardrails and evidence quality.
Influence at scale: Produce clear design docs and executive narratives; mentor engineers and program leaders; build communities of practice and reusable assets for continuous compliance.
Responsibilities ??????
What you'll bring 12+ years in security architecture/engineering, compliance engineering, or GRC technical leadership for large-scale distributed systems; significant experience "building clouds" (IaaS/PaaS) or platform engineering
Deep expertise in security/compliance frameworks and audit expectations, including several of: NIST-800 series (e.g., NIST 800-53), SOC 2, ISO 27001, ISO 42001, PCI, FedRAMP, GDPR, and international/regional frameworks (ability to map and rationalize across regimes)
Demonstrated ability to translate requirements into engineering-ready controls, define control intent and testability, and drive implementation across multiple teams with measurable outcomes
Demonstrated experience building continuous compliance automation programs/platforms (e.g., control-to-requirement mappings, automated evidence collection, continuous monitoring) that materially reduce audit prep effort and builder toil
Hands-on OSCAL proficiency: capable of authoring and owning OSCAL artifacts directly, and creating scalable contribution models (templates, review workflows, QA checks, governance).
Strong experience with compliance-as-code / policy-as-code, automated control validation, CI/CD integration, configuration baselines, and continuous monitoring
Hands-on depth with one or more: OCI, AWS, Azure, GCP; Kubernetes; Terraform/Policy-as-Code; CI/CD; Linux hardening; observability stacks (enough to design/validate controls and evidence feasibility)
Demonstrated ability to lead cross-org initiatives, influence without authority, and deliver compliant-by-default solutions at scale-including leading through engineering managers/TPMs and partnering effectively with audit/assessors when needed
Strong written and verbal communication; ability to produce clear design docs, control narratives, evidence strategies, and executive-level updates
Commitment to inclusive collaboration and mentoring
Preferred Qualifications: Experience designing and operating evidence pipelines and assurance platforms (control testing automation, evidence normalization, lineage, retention, dashboards, and audit-ready reporting)
Experience building or operating large-scale detection and remediation pipelines that continuously reduce misconfigurations/control drift across large environments
Experience partnering with assessors/auditors and driving remediation programs across large engineering organizations
Familiarity with secure SDLC controls and software supply chain assurance (SBOMs, signing, provenance, deployment gates), especially where they support compliance outcomesExperience defining security/compliance specifications for AI-enabled applications and embedding them into SDLC workflows (aligned to AI governance expectations such as ISO 42001)
Advanced degree in Computer Science, Engineering, or related field (or equivalent experience)
Leadership competencies Performance, drive, and execution
You'll deliver value and shape a performance-driven culture while ensuring accountability and communicating expectationsCollaboration
You understand and promote the value of collaboration and inclusivity and can align strategic aims with organizational goalsCommunicating for impact
You inspire confidence by championing a clear understanding and support of organizational strategy and objectivesInspirational leadership
You build a reputation for strategy by inspiring and empowering others while showing leadership internally and externallyCompetitive edge
You anticipate changes in customer needs and seize opportunities to build value, encourage innovation, and meet objectives
Disclaimer: Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates. Range and benefit information provided in this posting are specific to the stated locations only US: Hiring Range in USD from: $136,600 to $338,500 per annum. May be eligible for bonus, equity, and compensation deferral. Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. Oracle US offers a comprehensive benefits package which includes the following: Medical, dental, and vision insurance, including expert medical opinion
Short term disability and long term disability
Life insurance and AD&D
Supplemental life insurance (Employee/Spouse/Child)
Health care and dependent care Flexible Spending Accounts
Pre-tax commuter and parking benefits
401(k) Savings and Investment Plan with company match
Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
11 paid holidays
Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
Paid parental leave
Adoption assistance
Employee Stock Purchase Plan
Financial planning and group legal
Voluntary benefits including auto, homeowner and pet insurance
The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted. Career Level - IC6 About Us Only Oracle brings together the data, infrastructure, applications, and expertise to power everything from industry innovations to life-saving care. And with AI embedded across our products and services, we help customers turn that promise into a better future for all. Discover your potential at a company leading the way in AI and cloud solutions that impact billions of lives. True innovation starts when everyone is empowered to contribute. That's why we're committed to growing a workforce that promotes opportunities for all with competitive benefits that support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs. We're committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing accommodation-request_mb@ or by calling 1-888-404-2494 in the United States. Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans' status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
Sprachkenntnisse
- English
Hinweis für Nutzer
Dieses Stellenangebot stammt von einer Partnerplattform von TieTalent. Klick auf „Jetzt Bewerben”, um deine Bewerbung direkt auf deren Website einzureichen.