OR

Principal Security Analyst

Oracle
Hyderabad4-12 LPA Posted 27 Oct 2025
FULL TIME
Oracle Cloud Infrastructure
Regulatory Compliance
Linux
Risk Management

Job Description

RESPONSIBILITIES:

  • The candidate will support the strengthening of Oracle's security posture, focusing on areas such as regulatory compliance, risk management, incident management and response, and Threat and Vulnerability Management.
  • This role requires an experienced professional with 8+ years in information systems and 3+ years in security operations, capable of operating independently and leading security projects.
  • Key functions include managing compliance programs to industry and government standards, conducting complex information security risk assessments, and overseeing internal audit processes.
  • The position also involves developing, implementing, and maintaining robust security policies and providing guidance on process improvements to remediate control gaps.

Principal Duties and Responsibilities

  • Regulatory Compliance: Manage programs to establish, document, and track compliance to standards and regulations like ISO-27001, PCI-DSS, HIPAA, FedRAMP, CMMC, GDPR, etc. Researches and interprets current and pending governmental laws and regulations.
  • Risk Management: Conduct and document very complex information security risk assessments and lead departmental risk management programs.
  • Audit and Liaison: Oversee and manage internal audit processes, acting as the primary liaison between internal teams to ensure efficient and accurate audit completion. Assess the effectiveness of security controls.
  • Security Posture & Policy: Continuously assess and enhance the organization's security posture. Collaborate with cross-functional teams to establish and maintain robust security policies and procedures.
  • Threat and Vulnerability Management: Research, evaluate, track, and manage information security threats and vulnerabilities.
  • Incident Management and Response: Respond to security events and mitigate vulnerabilities in line with incident response playbooks. Facilitate and drive disaster recovery (DR) planning.
  • Documentation and Reporting: Develop and maintain cybersecurity documentation (e.g., SSP, PIA, CMP, POAM, SOP). Write stakeholder reports, create metrics, and brief executive leadership on compliance matters.
  • Mentorship: Mentors and trains other team members
Join WhatsApp Channel