OCI Security Expert
Montréal, CANADA IT development
Job description
Position Description:
Summary:
The Oracle OCI Operations Security Leads are responsible for the security and operational management of Oracle Cloud Infrastructure (OCI) and Oracle ERP systems. This involves ensuring the security, availability, and integrity of the OCI environment and the Oracle ERP applications hosted within it. The successful candidate will implement, monitor, and improve security controls, manage security incidents, and ensure compliance with industry standards and organizational policies
Key Knowledge & Responsibilities:
-Knowledge of Oracle Cloud Infrastructure (OCI) services, including IAM, VCN, WAF, and encryption mechanisms.
-Ensure the secure running of Oracle ERP applications in OCI, including databases, middleware, and integrations.
-Monitoring event queues & use of security management tools
-Knowledge of OCI Security Services
-Identify, categorise, prioritize, and investigate correlated events.
-Communicate and coordinate with multiple teams on security and operational incidents within a globally distributed team.
Access Control:
-Manage and monitor identity and access management (IAM) policies in OCI, ensuring least privilege access and proper role-based access controls (RBAC).
-Implement and enforce multi-factor authentication (MFA) and secure access methods for OCI resources.
-Experience in Oracle Access and Segregation of Duties
-Experience with Oracle Identity and Access Management, Roles and Permissions, and Privileged Access
Security Monitoring and Incident Response:
Security Monitoring:
-Implement and manage security monitoring tools such as Oracle Cloud Guard, Oracle Security Zones, and Oracle CASB (Cloud Access Security Broker).
- Monitor logs and alerts for OCI services, detect and respond to potential security threats.
Incident Response:
- Develop and maintain an incident response capabilities in OCI and Oracle ERP environments.
- Lead the response to security incidents, including investigation, mitigation, and post-incident analysis.
- Perform investigation and triage of events and incidents and escalate according to SOPs.
- Develop reports, dashboards, real-time rules, and filters on large scale systems
- Develop/iterate on event/incident procedures, long-term analysis, investigation processes and reporting.
- Document investigation results and provide relevant details for final analysis
- Identify improvements in event generation and monitoring platforms and work with engineering teams to have these implemented.
- Pursue events and incidents investigation and response automation opportunities.
Threat Intelligence:
- Stay updated on the latest security threats, vulnerabilities, and industry trends relevant to OCI and Oracle ERP systems.
- Use threat intelligence to proactively secure the OCI environment and Oracle applications.
Compliance and Governance:
Compliance Management:
- Ensure compliance with industry standards including ITGC controls, SOX, SOC reporting, security policies.
- Familiarity with Information Security and regulatory frameworks and standards (i.e. CIS, NIST, MITRE, ITIL, Cloud Security Alliance)
- Familiarity with Vulnerability Management reporting and remediation
Policies:
- Monitor and enforce security policies, procedures, and standards for OCI operations and Oracle ERP systems.
- Provide guidance and training to internal teams on OCI security best practices.
Automation and Optimization:
Automation:
- Automate security processes and incident response workflows using OCI native tools and third-party security solutions.
- Optimize the security configuration and posture of the OCI environment through continuous monitoring and improvement.
-Knowledge of Oracle Database security and database security tools
Skills:
· Incident Management
· Threat Risk Assessment
What you can expect from us:
Together, as owners, let’s turn meaningful insights into action.
Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you’ll reach your full potential because…
You are invited to be an owner from day 1 as we work together to bring our Dream to life. That’s why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company’s strategy and direction.
Your work creates value. You’ll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise.
You’ll shape your career by joining a company built to grow and last. You’ll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons.
At CGI, we recognize the richness that diversity brings. We strive to create a work culture where all belong and collaborate with clients in building more inclusive communities. As an equal-opportunity employer, we want to empower all our members to succeed and grow. If you require an accommodation at any point during the recruitment process, please let us know. We will be happy to assist.
Come join our team—one of the largest IT and business consulting services firms in the world.