Principal TPM Cloud Compliance
Listed on 2026-01-02
-
IT/Tech
Cybersecurity, Systems Engineer -
Engineering
Cybersecurity, Systems Engineer
Oracle Cloud Infrastructure (OCI) is building the next generation cloud to support demanding hyperscale and AI/ML workloads. The Cloud Compliance & Assurance org are the keepers of customer trust ensure that Oracle Cloud IaaS, PaaS, and SaaS services meet the high compliance standards that our customers expect.
We are looking for a driven, curious, and collaborative technical professional with a track record of raising the bar on the security and compliance of complex cloud and AI/ML services.
You will work with subject matter experts across Oracle to help define the security, compliance, and operational standards we should follow. You will work with engineering teams and ensure that our infrastructure and IaaS, PaaS, and SaaS services meet these standards. You will be expected to have deep expertise in cloud services, AI/ML compliance, cloud compliance, and/or security. By leveraging this unique cross‑section of skills, you will guide engineering teams to build the right controls in their services.
You will assess the infrastructure and services to make sure that our standards have been met and can be proved in external attestation.
Within the Cloud Compliance & Assurance org, you will be part of the team that’s responsible for Compliance Architecture, Standards, and Continuous Compliance. We partner with SMEs across Oracle to develop and maintain standards that engineering teams must meet and the architecture guidance they can follow to meet these standards. We provide guidance to the engineering teams and assess their products and services.
You will contribute across all these work streams and devise ways for us to accomplish our mission at cloud scale. Our org is critical to OCI’s success and, as a member of the team, you will play a key role in enabling Oracle open new multibillion dollar markets.
- Bachelor’s degree or equivalent, ideally in a technical field.
- 10 years related technical experience.
- 5 years program management experience.
- Ability to prioritize, manage, and deliver on multiple projects simultaneously.
- Highly motivated and able to work against aggressive schedules and shifting business priorities.
- Strong bias for action and iterative delivery style.
- Superior communication skills (interpersonal, verbal, written, presentation).
- Positive attitude, team player, self‑starter.
- Knowledge of cloud architecture and services.
- Cloud delivery models – IaaS, PaaS and SaaS; hybrid and multi‑cloud.
- Shared responsibility models and architectures for various cloud delivery models.
- Typical cloud service building blocks and best practices in building complex systems with them.
- Knowledge of cloud compliance.
- Familiarity with standards and regulatory requirements such as ISO 42001, PCI‑DSS, FedRAMP, HIPAA, GDPR and or others.
- Building Continuous Compliance in the cloud through verifiable controls and automation.
- Security best practices.
- Dev Sec Ops , Secure SDLC, AI/ML security, cloud controls and common cloud vulnerabilities.
- Building a culture of security and shifting security left.
- Important security concepts — cryptography, identity, AuthZ, AuthN, logging and alerting, data protection, etc.
- Develop, update, and enforce security and compliance policies, procedures, and standards to align with evolving regulatory landscapes and industry best practices.
- Partner closely with engineering, product, security, release management, and compliance teams to ensure that security and compliance are integrated into the product development lifecycle.
- Develop and provide guidance on controls for AI/ML systems and ensure compliance with AI-specific frameworks like ISO 42001 or others.
- Create and present reports on compliance status, risk posture, and remediation efforts to senior leadership and stakeholders.
- Collaborate with audit management teams to ensure smooth and successful service audits.
- Develop and maintain clear documentation and guidance resources that helps Engineering teams.
- Devise processes and automation to deliver continuous compliance at cloud scale.
Certain US customer or client‑facing roles may be required to comply with applicable requirements,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).