Oracle Cloud Security Incident Response (JoinOCI-SecurityOps) in Colorado Springs, Colorado
Design, develop, troubleshoot and debug software programs for databases, applications, tools, networks etc.
As a member of the software engineering division, you will take an active role in the definition and evolution of standard practices and procedures. You will be responsible for defining and developing software for tasks associated with the developing, designing and debugging of software applications or operating systems.
Work is non-routine and very complex, involving the application of advanced technical/business skills in area of specialization. Leading contributor individually and as a team member, providing direction and mentoring to others. BS or MS degree or equivalent experience relevant to functional area. 7 years of software engineering or related experience.
Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans status or any other characteristic protected by law.
Are you interested in building large-scaledistributed infrastructure for the cloud? Oracle s Cloud Infrastructure team isbuilding its next generation Cloud IaaS/PaaS/SaaS technologies that operate athigh scale in a broadly distributed multi-tenant environment. Our customers runtheir businesses on our cloud, and our mission is to provide them with best inclass, foundational cloud networking services.
Our team designs, engineers and operates thesecurity for our premier cloud services. We are re-imagining the traditional enterprise thinking of security andcreating an environment suitable for the most demanding and security consciencecustomers with our new large scale distributed services. This team is here to protect the customers,protect our cloud and make sure it best of breed.
We are looking for people with experience inthreat hunting, determining indicators of compromise (IOCs), incidentmanagement and red team/blue team activities for our IaaS, PaaS and SaaSenvironments. You will be part of aCSIRT team responsible for the investigation and reporting of product securityincidents for all of our cloud. Thisincludes using tools to analyze and respond to threats, creating tools/scriptsto aid in quick analysis and response, and responding to security events. The position operates and tunessecurity-supporting tools, provides requirements for new security tools andcreates use cases for additional monitoring situations.
If this excites you, come help us deliver thenext level of secure cloud computing. These are exciting times in our space - we are growing fast, still at anearly stage and working on ambitious new initiatives. An engineer at any level can have significanttechnical and business impact.
We are looking for a Cloud Security Engineerto help us push the boundaries of what can be accomplished in both current andthe next generation of Oracle cloud services using automation and activeintelligence gathering systems. Theideal candidate will have proven experience in Security Incident Response(CSIRT, SIRT), Blue Team, Security Monitoring, or Threat Hunting.
This role will be part of the Oracle s CloudSecurity Threat Management team. Multiple levels of experienced roles are available for this posting.
Coordinatethe CSIRT efforts across multiple business units during response
Performhunting exercises using threat intelligence, analysis of anomalous log data andresults of historical events and data to detect and response to threats
Developanomaly detection dashboards and reports to identify potential threats,suspicious activity, and intrusions
Monitorfor security indicators by correlating and analyzing a variety of application, networkand host-based security logs and determining the correct remediation actionsand escalation paths for each incident
Assistwith the development of processes and procedures to improve security operationsfunctions, incident response times, analysis of incidents, and overall SOCfunctions
Createrepeatable processes for continuous testing and monitoring of IOCs following aproven methodology you help define
Developscripts, processes and content to improve detective capabilities
Knowledgeof the chain of custody process and properly securing evidence
Researchindustry trends, identify ongoing security threats, analyze new securitytesting tools, and provide recommendations on the need and usefulness ofservices and/or products
Evaluateand recommend new and emerging security solutions and technologies to issues
Effectivelycommunicate security concepts with both technical and non-technical individuals
Provideinformation regarding intrusion events, security incidents, and other threatindications and warning information to teams and leadership as part of incidentresponse
Deliverself-service security metric data of discovery, triage and trending analysis ofteam findings
Authorpost mortem reports to be provided to senior leadership following an intrusionor red team engagement
Participatein Red/Blue/Purple team activities
Bachelor sDegree in Information Assurance, Security, Management Information Systems, RiskManagement or equivalent work experience acceptable
2-3 years of related cybersecurity architecture, engineering, or SOC workexperience (monitoring, detection, incident response, forensics)
Abilityto write scripts/code using Python, Perl, Powershell, or an equivalent language
Excellentwritten and verbal communications, including presentation skills, are importantto be successful in this role
Provenability to effectively communicate with all levels of the organization, as wellas with external parties
Experiencewith forensics tools such as X-Ways, F-Response, Volatility and Rekall
Red/Blueteam experience turning findings into actionable detections and mitigations
Preferredknowledge of current advanced adversary TTP s and experience responding to ATPattacks
Understandingof privilege escalation, persistence, and lateral movement techniques
Understandingof host and network Incident Response processes, tasks, and tools
Excellentcustomer service skills required
Knowledgeof operational security tools and practices (e.g. IDS, firewalls, &3rd-party security products)
Abilityto both work independently with minimal direction and to collaborateeffectively with local and remote teams with a strong customer focus
Experienceworking in a large cloud or Internet software company preferred.
Beavailable on an on-call basis to respond to pending issues or problems arisingduring non-business hours and provide support and response
Job: *Product Development
Title: Cloud Security Incident Response (JoinOCI-SecurityOps)
Requisition ID: 180002IU
Other Locations: United States