OROracle
Principal Security Analyst
Hyderabad ₹4-12 LPA Posted 27 Oct 2025
FULL TIME
Oracle Cloud Infrastructure
Regulatory Compliance
Linux
Risk Management
Job Description
RESPONSIBILITIES:
- The candidate will support the strengthening of Oracle's security posture, focusing on areas such as regulatory compliance, risk management, incident management and response, and Threat and Vulnerability Management.
- This role requires an experienced professional with 8+ years in information systems and 3+ years in security operations, capable of operating independently and leading security projects.
- Key functions include managing compliance programs to industry and government standards, conducting complex information security risk assessments, and overseeing internal audit processes.
- The position also involves developing, implementing, and maintaining robust security policies and providing guidance on process improvements to remediate control gaps.
Principal Duties and Responsibilities
- Regulatory Compliance: Manage programs to establish, document, and track compliance to standards and regulations like ISO-27001, PCI-DSS, HIPAA, FedRAMP, CMMC, GDPR, etc. Researches and interprets current and pending governmental laws and regulations.
- Risk Management: Conduct and document very complex information security risk assessments and lead departmental risk management programs.
- Audit and Liaison: Oversee and manage internal audit processes, acting as the primary liaison between internal teams to ensure efficient and accurate audit completion. Assess the effectiveness of security controls.
- Security Posture & Policy: Continuously assess and enhance the organization's security posture. Collaborate with cross-functional teams to establish and maintain robust security policies and procedures.
- Threat and Vulnerability Management: Research, evaluate, track, and manage information security threats and vulnerabilities.
- Incident Management and Response: Respond to security events and mitigate vulnerabilities in line with incident response playbooks. Facilitate and drive disaster recovery (DR) planning.
- Documentation and Reporting: Develop and maintain cybersecurity documentation (e.g., SSP, PIA, CMP, POAM, SOP). Write stakeholder reports, create metrics, and brief executive leadership on compliance matters.
- Mentorship: Mentors and trains other team members
