MSR Technology Group has been recognized as an Inc. 500/5000 company for the past seven consecutive years. We currently have an urgent opening for an Oracle Security Analyst, Fully Remote.
Position Details:
Title: Oracle Security Analyst
Location: Fully Remote
Duration: Long Term Contract
Pay Rate: $Negotiable
Job Description.
About the Role
This position owns the lifecycle of the company's Oracle ITGCs end to end. Initially, the analyst will assess the current control environment, then design or rebuild controls covering user access, segregation of duties, privileged access, change management, and IT operations. Once controls are established, the analyst transitions into operating them at their required cadence (per-request, continuous, monthly, quarterly, semi-annual, and annual), maintaining audit-ready evidence throughout. Because the organization does not run Oracle Risk Management Cloud, the analyst must be effective performing segregation-of-duties and access analysis with manual, Excel-based tooling.
Key Responsibilities
Phase 1 Control Design & Build
- Assess the current state of IT general controls across the Oracle Cloud environment (ERP, EPM, OIC, OCI) and identify gaps against SOX / ICFR requirements.
- Design or rebuild controls and document procedures, including control objectives, ownership, frequency, and evidence requirements.
- Develop role-based access models, role-to-privilege mappings, and a segregation-of-duties ruleset using manual tooling.
- Partner with IT, Internal Audit, and Finance to validate control design and establish sustainable operating procedures.
Phase 2 Control Operation
- Ensure user access additions and modifications are authorized by management and accurately implemented; ensure access for terminated and transferred users is removed or modified in a timely manner.
- Perform periodic user access reviews, privileged access reviews, and role-to-permission mapping reviews to identify and remediate inappropriate access.
- Test and approve Oracle role changes prior to implementation.
- Conduct segregation-of-duties reviews, identify conflicts, and remediate or map to mitigating controls.
- Review key changes configurations, reports, integrations, and roles and ensure production change access is appropriately restricted and segregated from development.
- Restrict access to job schedulers; monitor critical jobs, interfaces, and integrations, ensuring processing errors are corrected for successful completion.
- Support evaluation of outside service providers, including review of SOC reports and complementary user entity controls (CUECs).
- Maintain audit-ready documentation and serve as a key liaison for internal and external auditors during SOX testing.
- Manage access and control workflows through Freshservice.
Required Qualifications
- 6+ years in IT security, IT audit, or IT controls.
- Hands-on SOX / IT general controls experience designing and operating controls. (Required.)
- 3+ years hands-on Oracle Fusion Cloud application security: Security Console, role design, data and function security, and role-to-privilege mapping.
- Demonstrated ability to perform manual segregation-of-duties analysis ruleset development, conflict identification, and mitigating controls without reliance on an automated GRC platform such as Oracle RMC.
- Proven experience both designing/building and operating ITGCs in a production ERP environment.
- Strong documentation and Excel-based analysis skills.
- Excellent written and verbal communication and stakeholder management; able to work independently in a fully remote setting.
- Authorized to work in the United States.
Preferred Qualifications (Nice to Have)
- Hands-on security experience with Oracle EPM, Oracle Integration Cloud (OIC), and/or Oracle Cloud Infrastructure (OCI).
- Familiarity with Oracle Risk Management Cloud concepts (Advanced Access Controls, Advanced Financial Controls), even if not used in this environment.
- Experience with Freshservice or a comparable ITSM ticketing platform.
- Bachelor's degree in Information Systems, Accounting, Cybersecurity, or a related field equivalent experience accepted in lieu of a degree.
Certifications (Preferred)
- CISA Certified Information Systems Auditor.
- CRISC Certified in Risk and Information Systems Control.
- OCI Security Oracle Cloud Infrastructure IAM / Security Professional.
- CISSP broader information-security credential; a plus.
If your background and experience align with this opportunity, please share your resume in confidence with the contact below:
Recruiter Name: Sravan
Email:
Equal Opportunity Employer (EOE)