**Job Description**
This Technical Program Manager role will be well-versed in security architecture and compliance. You will review enterprise software-both third-party and internally developed to ensure alignment with Oracle's corporate security policies, standards, and regulatory obligations. You will perform security and privacy risk assessments, evaluate architectures and configurations (identity/access, data protection, logging/monitoring, secure deployment), validate control mappings, and document findings with clear remediation plans. Working with product owners, engineering, operations, Vendor Risk, Legal/Privacy, and Compliance, you will drive remediation to closure, contribute to standards and secure SDLC guardrails, support audits and exceptions, and provide clear guidance to stakeholders on risks, tradeoffs, and compliance requirements.
**Responsibilities**
**About the team**
Oracle's Global Physical Security (GPS) team protects our people, facilities, data centers, and our customer operations worldwide. We design and operate resilient, scalable, and privacy-aware physical security solutions in close partnership with Real Estate & Facilities, Oracle Cloud Infrastructure, Data Center Engineering, Legal/Privacy, Procurement, and Regional Security Operations.
**Key responsibilities**
+ Daily Responsibilities
+ Lead security architecture and design reviews for new deployments and changes to GPS technologies and networks.
+ Triage and resolve escalated security engineering issues; perform root-cause analysis and corrective actions.
+ Review exceptions, changes, and deviations against GPS standards and control frameworks.
+ Maintain documentation: reference architectures, diagrams, runbooks, and data flow mappings.
+ Monitor security posture via dashboards and reports; follow up on anomalies, alarms, and audit findings.
+ Provide SME support to Regional Security Operations, Data Center Engineering, OCI, and systems integrators.
+ Project Participation
+ Serve as security architect to review new site builds, data center expansions, and retrofits.
+ Develop technical requirements, bill-of-materials, and secure configurations for access control, VMS, intrusion, identity/visitor systems, and SOC platforms.
+ Drive design reviews and acceptance criteria; ensure resiliency and scalability.
+ Manage pilots/POCs and partner with Procurement on RFPs, vendor assessments, and contract security requirements.
+ Governance, risk, and compliance
+ Author and maintain GPS policies, standards, and control baselines aligned to ISO 27001/22301, NIST 800-53, SOC 2, and applicable privacy regulations (e.g., GDPR/CPRA).
+ Conduct risk assessments, control testing, and internal audits; track remediation and exceptions.
+ Define and enforce data handling/retention standards for video, access logs, and visitor data; ensure privacy-by-design.
+ Support third-party risk evaluations, supplier audits, and evidence gathering for external attestations.
+ Contribute to business continuity and incident response planning for physical security systems.
+ Operations enablement
+ Build and maintain operational runbooks, SOPs, playbooks, and training for SOC and field teams.
+ Define KPIs/SLAs/SLOs; implement observability and capacity planning for critical security services.
+ Champion automation and least-privilege operations.
+ Mentor engineers with "security first" principles; uplift regional teams on architecture and compliance practices.
+ Technology evaluation
+ Evaluate and recommend enterprise-class security technologies and integrations (ACS, VMS, credentialing, identity/visitor platforms, PSIM/C2, analytics).
+ Assess interoperability, API/security controls, encryption, identity federation/SSO, and network segmentation.
+ Drive secure configurations and zero-trust-aligned designs for security device networks and cloud-connected services.
+ Develop reference architectures, patterns, and hardening guides; measure total cost of ownership and risk reduction.
+ Stakeholder engagement
+ Partner with RE&F, Data Center Engineering, OCI, Legal/Privacy, Procurement, Regional Security Operations, HR, Internal Audit, and Compliance.
+ Communicate risk, trade-offs, and recommendations to technical and executive audiences.
+ Coordinate with external vendors and integrators.
**Minimum Qualifications**
+ 5+ years in security engineering/architecture for physical security or converged security environments at cloud scale.
+ One certification in security required, such as Security+, GSEC, SSCP, CCSK/CCSP
+ Strong knowledge of governance, risk, and compliance frameworks (e.g., ISO 27001, NIST 800-53, SOC 2) and privacy concepts (data minimization, retention, DPIAs).
+ Proficiency in network/security fundamentals: segmentation, VPNs, TLS, PKI, identity and access management, logging/monitoring.
+ Experience producing architecture diagrams, data flow maps, standards, and procedural documentation.
+ Bachelor's degree in a relevant field (Security, Engineering, Computer Science, or equivalent experience).
**Preferred Qualifications**
+ Progress toward CISSP or GIAC is a plus.
+ Hands-on with leading platforms (e.g., Genetec, Lenel/S2, Avigilon/Motorola, HID, Milestone) and integrations via APIs/Webhooks.
+ Proven experience designing and operating enterprise access control, VMS, and SOC technologies in multi-site/global settings.
+ Experience with privacy and regional regulatory requirements (GDPR, CPRA) and evidence collection for audits/attestations.
+ Familiarity with secure SDLC, zero trust for OT/IoT, and converged cyber-physical risk management.
+ Exposure to GRC and ITSM tools (e.g., Archer, ServiceNow GRC/ITSM) and analytics/SIEM dashboards.
+ Experience with Atlassian products.
**Key Competencies**
+ Security architecture and systems thinking; ability to balance risk, usability, and cost.
+ Risk assessment, threat modeling, and control mapping.
+ Clear written and verbal communication; executive-ready reporting.
+ Program and project management; vendor and integrator oversight.
+ Incident response, problem solving, and root-cause analysis.
+ Collaboration, influence without authority, and stakeholder management.
+ High integrity, discretion, and commitment to privacy-by-design.
**Work Model and Travel**
+ Strong ability to work independently and with teams across global time zones
**Notes**
+ This role combines some cross-team hands-on design and delivery with standards development and cross-functional leadership. It is well-suited for candidates earlier in their architecture career who have strong engineering depth and are ready to operate at enterprise scale.
+ Candidates must demonstrate commitment to Oracle's security, privacy, and compliance standards and be able to work across time zones.
+ When evaluating or proposing third-party tools or cloud services, ensure alignment with Oracle's internal security, privacy, and procurement guidelines.
Disclaimer:
**Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.**
**Range and benefit information provided in this posting are specific to the stated locations only**
US: Hiring Range in USD from: $106,300 to $223,400 per annum. May be eligible for bonus and equity.
Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto, homeowner and pet insurance
The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.
Career Level - IC4
**About Us**
As a world leader in cloud solutions, Oracle uses tomorrow's technology to tackle today's challenges. We've partnered with industry-leaders in almost every sector-and continue to thrive after 40+ years of change by operating with integrity.
We know that true innovation starts when everyone is empowered to contribute. That's why we're committed to growing an inclusive workforce that promotes opportunities for all.
Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.
We're committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing
[email protected] or by calling +1 888 404 2494 in the United States.
Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans' status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.