Oracle
Senior Data Loss Prevention Security Engineer
OracleRomania1 day ago
Full-timeInformation Technology
Job Description

Our rapidly growing team specializes in threat hunting, analyzing indicators of compromise (IOCs), investigating security incidents, managing incident responses, and conducting digital forensics across IaaS, PaaS, and SaaS platforms. In this role, you will be part of a dedicated security operations team, leveraging data loss prevention, case management tools and developing automation to detect and respond to security threats in real time. Additionally, you will play a critical role in designing and implementing data loss prevention strategies to proactively mitigate potential data security risks. As the last line of defense when security controls are breached, your expertise will be instrumental in securing Oracle’s data and infrastructure.

The ideal candidate is a proactive self-starter with a strong sense of ownership and accountability, capable of delivering effective results under pressure. Bringing deep expertise in security engineering, you will help drive the strategic development of our enterprise security threat program.

The Role

We are seeking a seasoned security engineering professional that will build and operate advanced security tools, processes, and automation to identify and mitigate risks related to proprietary data across OCI and Oracle’s broader enterprise. You will lead sensitive investigations, conduct thorough root cause analyses, and work collaboratively with partner teams—including SOC, digital forensics, incident response, physical security, and engineering—to respond effectively to diverse and sophisticated threats.

Responsibilities

  • Monitor and Analyze User Activity: Continuously monitor, analyze, and investigate user behaviors and activities across networks, applications, and endpoints to detect suspicious patterns or potential insider threats.
  • Build and Maintain Detection and Response Systems: Develop, implement, and manage tools, analytics, and automated detection systems specifically designed to identify potentially malicious activity.
  • Data Loss Prevention (DLP): Participate with DLP team to enhance data loss prevention strategies, including deploying and tuning DLP technologies to prevent the unauthorized access or transmission of sensitive proprietary data.
  • Incident Investigations: Conduct thorough investigations of security incidents related to potential or confirmed threats, collaborating closely with legal, HR, and compliance teams as needed.
  • Case Management: Document and manage cases from detection through to resolution, ensuring proper documentation and reporting processes are followed.
  • Security Awareness and Training: Support the development and delivery of targeted security awareness training at all levels of the company. Training to be focused on reducing data security risk and how to recognize and report suspicious behaviors.
  • Collaboration and Coordination: Work with cross-functional teams such as HR, legal, compliance, physical security and other engineering organizations to coordinate incident response and security policy and standards enforcement.
  • Threat Hunting: Proactively hunt for evidence of threats by analyzing system logs, access records, and behavioral analytics.
  • Tool and Process Enhancement: Evaluate and recommend improvements to detection tools, response processes, and operational playbooks.
  • Reporting and Analytics: Prepare reports and metrics (OKR's) on insider threat trends, investigation outcomes, and security posture for management and leadership.


Preferred Qualifications

  • Five years of experience in Insider Threat, DLP (client/server/cloud), incident response and/or security operations center activities at a cloud service provider
  • Effective written and oral communications skills with the ability to deliver technical information to non-technical staff
  • Comfortable working in an ambiguous, fast-paced, unpredictable environment
  • Experience working in a highly collaborative, team centric, event driven operations team
  • Experience with variety of technologies and how they are used to exfiltrate data
  • Experience with a variety of DLP tools (data at rest, data in motion, data in use)
  • Experience with a wide variety of logs and telemetry including AV, web server, SIEM, etc.
  • Experience with sophisticated threat actors and complex security incidents
  • Understanding of insider threat actor tactics, techniques, and procedures (TTPs) and threat analysis models like MITRE ATT&CK Framework
  • Experience developing and hunting using DLP-related indicators of compromise (IOC’s)
  • Experience performing open-source research on a variety of topics


Qualifications

Career Level - IC3

About Us

As a world leader in cloud solutions, Oracle uses tomorrow’s technology to tackle today’s challenges. We’ve partnered with industry-leaders in almost every sector—and continue to thrive after 40+ years of change by operating with integrity.

We know that true innovation starts when everyone is empowered to contribute. That’s why we’re committed to growing an inclusive workforce that promotes opportunities for all.

Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.

We’re committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing [email protected] or by calling +1 888 404 2494 in the United States.

Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

Key Skills

Ranked by relevance