Senior Manager, Network Audit and Compliance

Overview

On Site
USD 105,000.00 - 223,400.00 per year
Full Time

Skills

Risk Analysis
Database
Financial Services
Life Sciences
Hospitality
Retail
Service Delivery
Network Engineering
Artificial Intelligence
Data Centers
Hosting
Routing
Switches
Lifecycle Management
Computer Hardware
Migration
Cerner
Oracle Cloud
ISO/IEC 27001:2005
SOP
Communication
Workflow Management
OCI
Documentation
Risk Assessment
Risk Management
Reporting
Standard Operating Procedure
Continuous Monitoring
Firewall
Security Controls
Access Control
Network Design
Design Review
Disaster Recovery
Policies and Procedures
Collaboration
Product Development
Problem Management
Vendor Management
LCM
Leadership
Team Leadership
Mentorship
People Management
Training
Conflict Resolution
Roadmaps
Change Management
Continuous Improvement
Screening
PASS
Salesforce.com
Computer Science
Network Operations
Program Management
Management
ITGC
PCI DSS
HIPAA
Sarbanes-Oxley
System On A Chip
Technical Drafting
Regulatory Compliance
Auditing
ISS
Thread
Network Security
Agile
Scrum
Project Management
Network
Analytics
Grafana
SNMP
Oracle Application Express
Apex
Microsoft Power BI
Computer Networking
Incident Management
Vulnerability Management
Customer Facing
Recruiting
Health Care
Taxes
Financial Planning
Legal
Insurance
Cloud Computing
Value Engineering
Innovation
Life Insurance
Accessibility
Oracle
Law

Job Details

Job Description

The Ideal Candidate

Do you enjoy complex puzzles and challenging problems? Do you believe comprehensive risk analysis should guide design decisions? Do you value structured processes and continuous improvement? Do you believe that security and reliability are achieved through comprehensive risk assessment, problem avoidance, detailed planning, and precise execution? Do you believe variability and complexity are the anthesis of stability and reliability? If you answer yes to each, then Oracle's IES Networking Organization is looking for YOU!

Who we are

Oracle Cloud continues innovative breakthroughs providing Autonomous Database and cloud services to an ever-increasing customer base. Oracle's Infrastructure Engineering Services (IES) Cloud Services group is an industry leader focused on innovation, service delivery, and migration of traditional, on-premises workloads to Oracle Cloud Infrastructure. Our customer base includes fortune 500 and industry leaders across a variety of sectors including Health, AI, Federal/Government, Communications, Financial Services, Life Sciences, Hospitality, Retail, Utilities, Construction and Engineering. Together, we are purposeful, industry leading experts in cloud service delivery providing the next generation of Cloud services hosted in the Oracle Cloud.

What we do

Within IES, the Cloud & Data Center Network Engineering group plays a critical and central role in Oracle Health & AI (OHAI), providing a secure, highly available, and reliable network infrastructure spanning multiple US and International hosting environments. The expansive world-wide network includes physical data centers, OCI and hybrid cloud environments, all of which provide hosting to Oracle Health customers and numerous Global Industry Units (GIUs). The group's responsibilities include traditional routing and switching, advanced fabric technologies, application delivery, network automation, virtual cloud networking, transit services, network security, and full lifecycle management of hardware and software components. The migration of Cerner and OHAI tenants to Oracle Cloud Infrastructure (OCI) is a core priority of the group.

What you will do

As the Network Audit and Compliance Manager you will lead a team of highly skilled network engineers, program managers, and security champions maintaining standard operating procedures and demonstrating network controls. The audit and compliance manager ensures the group adheres to established policies & regulations ensuring readiness for multiple industry standard audits and compliance evaluations. In a structured approach, your team will continuously assess and evaluate network systems and process readiness for HIPAA, NIST, PCI DSS, GDPR, SOC 1 & 2, ISO 27001, SOX, as well as other internal & external audits.

The Networking Audit and Compliance Manager serves as the organizational leader & senior security champion ensuring preparedness for organizational audits, compliance reviews, vulnerability management, security controls and standard operating procedure (SOP) alignment. You will be responsible for the development, establishment, and communication of security policies, standards, guidelines, and the education and awarness of these requirements across our network organization. You will prepare for and perform internal audits, develop procedures, and assess potential risks to the network environments. Additionally, you will drive vulnerability remediation for network assets including triage and workflow management across the networking organization. The role advises Senior Leadership, LOB & OCI's Security teams.

Responsibilities

Duties and Core Responsibilities
  • Manage the compliance program: Implement and oversee the networking compliance program that promotes awareness and enforces adherence to all prescribed compliance requirements. Stay informed about changes in national and international laws, industry standards, and government directives that could impact the organization.
  • Establish and maintain networking policies: Develop, implement, review, and maintain network security policies, standards, and procedures based on Oracle Security and regulatory requirements (e.g., HIPAA, PCI DSS, NIST, SOC1 /3, etc.).
  • Liaison with External Bodies: Interact with external auditors and regulatory bodies to defend the company's compliance systems and ensure proper documentation and adherence to requirements.
  • Create a compliance framework: Build and maintain a networking controls matrix aligned with multiple compliance frameworks to ensure continuous adherence across the organization.
  • Advise leadership: Report to and advise senior leadership of existing risks, vulnerabilities, issues, and the overall compliance posture of the production network environment. Identify and recommend necessary risk mitigation actions.

Auditing and Risk Assessment
  • Lead & participate in audits: Independently lead internal audits and assessments to check for adherence to regulations and identify areas for improvement. Coordinate with external and regulatory auditors to demonstrate and/or provide evidence of adherence to established controls.
  • Conduct risk assessments: Perform risk assessments of the network, cloud environment, networking tools, & networking infrastructure hosts to identify vulnerabilities and prioritize risk mitigation/remediation or issues that could lead to non-compliance, system compromises, and reduced security posture.
  • Remediate findings: Develop and implement remediation plans to address issues identified in internal and external audits. Drive the implementation of these corrective actions across the networking organization.
  • Produce compliance reports: Develop and maintain automated reporting and visualizations providing evidence of compliance for auditors.
  • Monitor controls: Ensure that all information system controls and monitoring systems are operating effectively. Ensure Standard Operating Procedures (SOPs) are created and maintained aligning to and supporting existing controls.
  • Violation Investigation: Investigate instances of non-compliance or potential ethical violations and take appropriate action to address them.

Technical and Operational Activities
  • Monitor security reports: Continuous monitoring and review of security logs and reports identifying issues and driving them to resolution across the networking group.
  • Manage firewall configuration: Monitor and review firewall configurations, logging, and change records for compliance to established security controls.
  • Evaluate access controls: Review system user access records to least privileged access is provided across networking systems. Ensure accounts are properly maintained including timely updates and terminations when necessary.
  • Implement security solutions: Participate in network architecture & design reviews, recommending implementation of secure infrastructure standards and configurations.
  • Plan for disaster recovery: Lead networking organizational disaster recovery plans and strategies.

Training and Collaboration
  • Provide security training: Develop and deliver security and compliance awareness training programs to networking teams directly related to security policies and procedures.
  • Collaborate with stakeholders: Work closely with various internal departments (Security, Legal, Product Development, Network Operations, Problem Management) and third-party vendors to resolve compliance issues.
  • Maintain vendor management: Continuously monitor vendor vulnerability announcements, and equipment lifecycle announcements, and assist with the network Life Cycle Management (LCM) program.

People Management & Leadership
  • People management: Lead and manage small, geographically distributed (remote worker) team of Network Engineers, Program Managers, and Security Champions
  • Team leadership and performance: Guide employees, set clear goals and priorities, monitor progress, conduct performance evaluations
  • Employee career development: Mentor, coach, guide, and direct team members providing consistent and constructive feedback. Provide opportunities for training and career development activities.
  • Conflict resolution: Assess problems, gather information, mediate and coach employees to resolve internal conflicts within the team and with peer teams.
  • Operational and Project management: Manage and conduct daily intake and scrum sessions. Prioritize and assign work items, tasks, and deliverables. Establish and manage strategic roadmaps, and critical projects.
  • Change management: Perform planned change reviews, enforce compliance with change management procedures and processes. Drive continuous improvement of network change program.

Required Experience & Qualifications
  • U.S. Citizenship, Government background screening with ability to pass a federal background check (SF-85)
  • Bachelor's degree in Computer Science, Engineering, or related field or equivalent hands-on experience
  • 7+ years of experience in enterprise-scale network operations or network program management
  • 3+ years managing high-performing technical teams
  • Demonstrated success leading network audit and compliance initiatives
  • Expertise with IT General Controls (ITGC), SOX, PCI DSS, HIPAA, NIST, SOX, SOC 1 & 2, and other regulatory compliance frameworks, including drafting policies, implementing systems and processes, ongoing compliance assessment, and executing recurring audits.
  • Experience with a variety of IT and ISS tools and systems, Advanced Thread Protection, Cloud Computing, Cyber Risks, and of course Network Security
  • Familiarity with Agile/Scrum project management practices
  • Experience integrating and operationalizing network analytics tools (Grafana, Elastic, SNMP traps, syslogs, Apex, PowerBi)
  • Knowledge of networking vendor lifecycle programs including vulnerability announcements
  • Demonstrated experience with incident response and vulnerability management
  • Able and willing to operate in a 24x7x365 environment including support and participation in role specific on-call escalation support

Qualifications

Disclaimer:

Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.

Range and benefit information provided in this posting are specific to the stated locations only

US: Hiring Range in USD from: $105,000 to $223,400 per annum. May be eligible for bonus and equity.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto, homeowner and pet insurance

The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.
Career Level - M3

About Us

As a world leader in cloud solutions, Oracle uses tomorrow's technology to tackle today's challenges. We've partnered with industry-leaders in almost every sector-and continue to thrive after 40+ years of change by operating with integrity.

We know that true innovation starts when everyone is empowered to contribute. That's why we're committed to growing an inclusive workforce that promotes opportunities for all.

Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.

We're committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing or by calling +1 in the United States.

Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans' status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.