Skip to content
← Back to job listings

Senior Security Engineer

Eeho · Nashville, TN, United States

CybersecurityImported listingfull-time2 days ago

About The Role

Creates testing tools to help engineering teams identify security-related weaknesses.

Recognizes and escalates complex security violations to senior team members.

Contributes to compliance assessments to identify gaps and ensure compliance with internal and external obligations.

Provides security best judgment and recommends best practices of data security using various tools and techniques such as encryption, hashing, masking, and access management to ensure the confidentiality and integrity of sensitive information.

We are vigorously investing in Oracle Cloud to provide the broadest, most secure cloud in the industry. Oracle offers a suite of integrated services, including applications as a service, platform as a service, and infrastructure as a service, that eliminates the data and business process fragmentation which comes with cloud silos. This is your opportunity to be part of the exciting Cloud Security team that is responsible for protecting Oracle’s infrastructure and keeping customer workloads safe.

Oracle’s mission is to provide customers with best-in-class compute, storage, networking, database, security, and an ever-expanding set of foundational cloud-based security services. We are rapidly expanding the size and scale of our business and are looking for highly talented individuals to join our team.

cloud.oracle.com/cloud-infrastructure

cloud.oracle.com/security

As a vital member of Oracle Cloud Infrastructure’s (OCI) Security Operations Organization, you will be at the forefront of protecting Oracle’s cloud and enterprise environments from both external adversaries and insider threats. As our team continues to expand and tackle ambitious initiatives, we are seeking experienced security professionals with a proven track record in safeguarding critical infrastructure and data.

Our rapidly growing team specializes in threat hunting, analyzing indicators of compromise (IOCs), investigating security incidents, managing incident responses, and conducting digital forensics across IaaS, PaaS, and SaaS platforms. In this role, you will be part of a dedicated security operations team, leveraging data loss prevention, case management tools, and developing automation to detect and respond to security threats in real time. Additionally, you will play a critical role in designing and implementing data loss prevention strategies to proactively mitigate potential data security risks. As the last line of defense when security controls are breached, your expertise will be instrumental in securing Oracle’s data and infrastructure.

The ideal candidate is a proactive self-starter with a strong sense of ownership, accountability, and capable of delivering effective results under pressure. By bringing deep expertise in security engineering, you will help drive the strategic development of our enterprise security threat program.

The Role

We are seeking a seasoned security engineering professional that will build and operate advanced security tools, processes, and automation to identify and mitigate data security risks related to proprietary data across OCI and Oracle’s broader enterprise. You will lead sensitive DLP investigations, conduct thorough root cause analyses, and work collaboratively with partner teams - including SOC, digital forensics, incident response, physical security, engineering teams as well as legal and HR - to respond effectively to diverse and sophisticated threats.

Key Responsibilities

  • Monitor and Analyze User Activity: Continuously monitor, analyze, and investigate anomalous user behaviors and activities across networks, applications, and endpoints to detect suspicious patterns or potential insider threats.
  • Build and Maintain Detection and Response Systems: Develop, implement, and manage tools, analytics, and automated detection systems specifically designed to identify potentially malicious activity.
  • Data Loss Prevention (DLP): As a member of the DLP operations team, enhance data loss prevention strategies, including deploying and tuning DLP technologies to prevent unauthorized access or transmission of sensitive proprietary data.
  • AI-Enabled Security Operations: build, deploy, and operate AI-enabled capabilities that accelerate DLP investigations, enhance analyst decision-making, and improve detection, triage, and response workflows. Drive the adoption of AI-powered tooling and automation while ensuring solutions are secure, effective, and aligned with operational and governance requirements.
  • Incident Investigations: Conduct thorough investigations of security incidents related to potential or confirmed threats, collaborating closely with legal, HR, and compliance teams as needed.
  • Case Management: Document and manage cases from detection through to resolution, ensuring proper documentation and reporting processes are followed.
  • Security Awareness and Training: Support the development and delivery of targeted security awareness training at all levels of the company. Training to be focused on reducing data security risk and how to recognize and report suspicious behaviors.
  • Collaboration and Coordination: Work with cross-functional teams such as HR, legal, compliance, physical security and other engineering organizations to coordinate incident response and security policy and standards of enforcement.
  • Threat Hunting: Proactively hunt for evidence of threats by analyzing system logs, access records, and behavioral analytics.
  • Tool and Process Enhancement: Evaluate and recommend improvements to detection tools, response processes, and operational playbooks.
  • Reporting and Analytics: Prepare reports and metrics on insider threat trends, investigation outcomes, and security posture for management and leadership.

Preferred Qualifications

  • For IC3 – 3-6yrs of experience in Insider Threat, DLP (client/server/cloud), incident response and/or security operations center activities at a cloud service provider
  • Exceptional written and oral communications skills with the ability to deliver technical information to non-technical staff
  • Comfortable working in an ambiguous, fast-paced, unpredictable environment
  • Experience working in a highly collaborative, team centric, event driven operations team
  • Experience with variety of technologies and how they are used to exfiltrate data
  • Experience with a variety of DLP tools (data at rest, data in motion, data in use)
  • Experience with a wide variety of logs and telemetry including AV, web server, SIEM, etc.
  • Experience with sophisticated threat actors and complex security incidents
  • Understanding of insider threat actor tactics, techniques, and procedures (TTPs) and threat analysis models like MITRE ATT&CK Framework
  • Experience developing and hunting using DLP-related indicators of compromise (IOC’s)
  • Experience performing open-source research on a variety of topics

Minimum Job Qualifications

Education and/or Experience

8 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, a related field

OR

Bachelor's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 4 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field

OR

Master's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field. AND 2 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field.

Job Skills

Same skills as proir level plus;

Incident Management and Response Demonstrated ability in or knowledge of incident management and response, including timely handling and escalation of incidents to minimize business impact.

Security Operations Services Demonstrated experience providing security monitoring, incident detection, and response services.

Scripting Languages Demonstrated ability in or knowledge of scripting languages, including writing and maintaining scripts to improve system efficiency.

Security Architecture Principles Demonstrated ability to apply security architecture principles to build and manage secure environments.

Cloud Security Demonstrated ability in or knowledge of cloud security, including protecting cloud infrastructure and data using risk management frameworks.

Cryptography Demonstrated ability in or knowledge of cryptography, including applying encryption techniques and ensuring secure communications.

Machine Identity Security Demonstrated skill in deploying and managing machine identity security and PKI solutions.

Security Investigation Demonstrated ability in or knowledge of security investigation, including assessing threats and vulnerabilities and enhancing security practices.

Security Assessment Demonstrated ability in or knowledge of security assessment, including conducting and interpreting vulnerability and risk analyses.

Cybersecurity and Privacy Principles Demonstrated ability in or knowledge of cybersecurity and privacy principles, including applying best practices and regulations for data protection.

Preferred Job Qualifications

Education and/or Experience

8 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field

OR

Bachelor's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 4 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field

OR

Master's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 2 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field.

Cloud or Internet Software Security Experience

2 years of experience working on projects related to cloud or internet software security.

Programming/Scripting Experience

2 years of experience working with one or more of the following programming or scripting languages (e.g., Go, Java, Python, or C/C++).

This is an external listing. JobSpring does not represent or verify the employer. Report this listing