You will design security and compliance reference architectures, standards, and controls for Oracle Cloud services and platforms, with a focus on continuous compliance and audit-ready engineering. This role is a hybrid of compliance engineering (building automation, evidence pipelines, compliance-as-code) and security GRC architecture (control design, framework mapping, risk decisions, and governance at scale). You will lead high-impact design reviews, control and evidence strategy, and requirements-to-implementation translation across cloud primitives (compute, network, storage), identity and access, container/Kubernetes platforms, AI/ML systems, and developer platforms. You will collaborate with senior leaders and product teams, mentor engineers, and influence roadmaps through clear writing, principled prioritization, and metrics—while directly authoring and owning OSCAL artifacts and scaling through others. Ideal candidates bring deep experience “building clouds” or securing large-scale distributed systems; strong fluency in global compliance regimes (including but not limited to NIST-800 series, SOC 2, ISO 27001, ISO 42001, PCI, FedRAMP, GDPR, and other international/regional frameworks); and a track record of delivering automation-first compliance outcomes (e.g., continuous control validation, evidence automation, and measurable reduction in audit preparation effort). You are hands-on, inclusive, and customer-obsessed, balancing rigor with velocity. Oracle’s Governance, Risk & Compliance (GRC) organization enables secure, compliant cloud delivery by partnering deeply with engineering and operations. We standardize control outcomes, strengthen evidence quality, and operationalize compliance through scalable patterns, automation, and measurable risk reduction—helping Oracle meet customer, regulatory, and industry expectations.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed