Job Title: Oracle Security Analyst
Duration: Long Term
Location: Remote
Job Description:
We are seeking an Oracle Security Analyst to design, build, and operate the IT general controls (ITGCs) that govern its Oracle Cloud environment. The role is delivered in two phases: first, standing up and, where needed, fully rebuilding a defined set of security, change-management, and operations controls to meet SOX / ICFR requirements; second, operating those controls on an ongoing basis. The environment is primarily Oracle Fusion Cloud ERP, with additional scope across EPM, Oracle Integration Cloud (OIC), and Oracle Cloud Infrastructure (OCI). This is a largely autonomous role suited to someone equally comfortable architecting a control framework and running it day to day.
Required Qualifications
6+ years in IT security, IT audit, or IT controls.
Hands-on SOX / IT general controls experience designing and operating controls. (Required.)
3+ years hands-on Oracle Fusion Cloud application security: Security Console, role design, data and function security, and role-to-privilege mapping.
Demonstrated ability to perform manual segregation-of-duties analysis ruleset development, conflict identification, and mitigating controls without reliance on an automated GRC platform such as Oracle RMC.
Proven experience both designing/building and operating ITGCs in a production ERP environment.
Strong documentation and Excel-based analysis skills.
Excellent written and verbal communication and stakeholder management; able to work independently in a fully remote setting.
Authorized to work in the United States.
Preferred Qualifications (Nice to Have)
Hands-on security experience with Oracle EPM, Oracle Integration Cloud (OIC), and/or Oracle Cloud Infrastructure (OCI).
Familiarity with Oracle Risk Management Cloud concepts (Advanced Access Controls, Advanced Financial Controls), even if not used in this environment.
Experience with Freshservice or a comparable ITSM ticketing platform.
Bachelor's degree in Information Systems, Accounting, Cybersecurity, or a related field equivalent experience accepted in lieu of a degree.
Certifications (Preferred)
CISA Certified Information Systems Auditor.
CRISC Certified in Risk and Information Systems Control.
OCI Security Oracle Cloud Infrastructure IAM / Security Professional.
CISSP broader information-security credential; a plus.