FirstBank Jobs

Job Information

Oracle Principle Security Incident Response Analyst in Denver, Colorado

Job Description

We are looking for an experienced Principal Security Incident Response Analyst for a role on the Oracle Cloud Security Incident Response team. Candidates would be part of a dedicated team of security professionals responsible for performing investigations against a variety of cloud environments, services, and products within Oracle’s commercial and regulated markets. Our team is skilled in triaging complex security issues, applying expert use of security tooling, and performing every aspect of the incident response lifecycle.

Candidates will have 10+ years in security specific roles, strong analytic skills and experience using an array of security tooling including SIEM, EDR, AV, Scan tools, forensic collection, processing, and analysis tools. A background of security incident management, and advanced digital forensics is required in addition to experience collaborating with customers, engineering, sales, and other product and security teams within a large organization. A proven subject matter expert capable of discovering new investigation techniques and capabilities related to security investigations. Experience creating standards, playbooks, tabletop exercises, and other training. Capable of mentoring, without ego, junior and senior analysts within the organization.

Career Level - IC4

Responsibilities

  • Respond to security events and threats that are escalated from external customers, internal security teams, and other developers and engineers.

  • Lead complex investigations that will include, triage, containment/mitigation, scoping, hunting, collection, processing, analysis, remediations, and after-action reporting and documentation.

  • Work closely with security engineering teams to improve monitoring, detection, and tooling

  • Understand the current threat landscape including emerging attacker TTPs and be able to translate them to the gaps and risks in the various environments in scope.

  • Operate Security tooling including but not limited to a Security Information Event Management (SIEM) platform, Intrusion Detection Systems (IDS), Firewalls, Anti-Malware solutions, and Endpoint Detection and Response (EDR)

  • Collect, process, and analyze an array of additional artifacts unavailable in security tooling. (logs, host/instance-based artifacts)

  • Experience working on Windows, Mac, and Linux operating systems

  • Provide high quality written and verbal reports as required

  • Develop new analysis tactics and capabilities for digital forensics and incident response

  • Author SOPs, playbooks and Incident Response plans

  • Lead Tabletop exercises

  • Mentor and train analyst

  • Support on-call rotations

  • Effective operator in a remote setting, adept at using technologies and self-imposing good time management practices

Qualifications:

  • Bachelor's Degree in Information Security and Assurance, Cyber Security, Computer Science, Software Engineering, Risk Management or maintain multiple security related credentials (Certified Incident Handler (GCIH), EC-Council Certified Incident Handler (ECIH), Certified Information Systems Security Professional (CISSP))

  • 10+ years of related cybersecurity architecture, engineering, and/or SOC work experience (monitoring, detection, incident response, forensics, vulnerability management, threat intelligence)

  • Ability to script/code using Python, Perl, or an equivalent language

  • Excellent written and verbal communications, including presentation skills

  • Proven ability to effectively communicate with all levels of the organization, as well as customers and external parties

  • Experience with variety of operating systems and threats that target them including Windows, UNIX/LINUX, and MacOS

  • Excellent verbal/non-verbal communication skills with the ability to deliver technical information to non-technical staff

  • Understanding of common security concerns and associated threat actor tactics

  • A broad background in information security with experience in security operations, vulnerabilities and exploitation, network security, and cloud security

Disclaimer:

Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.

Range and benefit information provided in this posting are specific to the stated locations only

US: Hiring Range: from $109,100 to $223,500 per annum. May be eligible for bonus and equity.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.

Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following:

  1. Medical, dental, and vision insurance, including expert medical opinion

  2. Short term disability and long term disability

  3. Life insurance and AD&D

  4. Supplemental life insurance (Employee/Spouse/Child)

  5. Health care and dependent care Flexible Spending Accounts

  6. Pre-tax commuter and parking benefits

  7. 401(k) Savings and Investment Plan with company match

  8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.

  9. 11 paid holidays

  10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.

  11. Paid parental leave

  12. Adoption assistance

  13. Employee Stock Purchase Plan

  14. Financial planning and group legal

  15. Voluntary benefits including auto, homeowner and pet insurance

The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.

About Us

As a world leader in cloud solutions, Oracle uses tomorrow’s technology to tackle today’s problems. True innovation starts with diverse perspectives and various abilities and backgrounds.

When everyone’s voice is heard, we’re inspired to go beyond what’s been done before. It’s why we’re committed to expanding our inclusive workforce that promotes diverse insights and perspectives.

We’ve partnered with industry-leaders in almost every sector—and continue to thrive after 40+ years of change by operating with integrity.

Oracle careers open the door to global opportunities where work-life balance flourishes. We offer a highly competitive suite of employee benefits designed on the principles of parity and consistency. We put our people first with flexible medical, life insurance and retirement options. We also encourage employees to give back to their communities through our volunteer programs.

We’re committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by calling +1 888 404 2494, option one.

Disclaimer:

Oracle is an Equal Employment Opportunity Employer*. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

* Which includes being a United States Affirmative Action Employer

DirectEmployers