More jobs:
Job Description & How to Apply Below
Senior Principal Offensive Security Engineer
The Oracle Cloud Infrastructure (OCI) Offensive Security team ensures our systems and services meet the security objectives communicated to customers. We conduct security assessments, vulnerability research, static and dynamic analysis, penetration testing, red‑teaming, and develop security tools. The team builds roles around each member’s skills and interests to continuously improve the cloud infrastructure’s security.
Responsibilities- Conduct complex source code audits to reveal subtle security vulnerabilities.
- Write new tools such as fuzzers in C/C++, Python, Ruby, Go, or Java.
- Tear apart undocumented file formats or network protocols.
- Develop novel techniques to solve unique security problems.
- Review new services and their integration points, identifying risk and recommending mitigations.
- Guide security projects beyond assessment work, designing systems that improve offensive security output.
- Disclose vulnerabilities to third‑party vendors.
- Drive organization‑wide improvements in engineering, security architecture, and best practices.
- 6+ years of experience in vulnerability discovery, security engineering, or application security.
- Threat modeling experience of microservice architectures.
- Experience working in a large cloud or software company.
- Extensive research or experience with multiple classes of security bugs.
- Evidence of contribution to the security community (training, talks, publications).
- Expertise in at least one business‑critical area (cryptography, hardware security, OS, authentication, fuzzing, DoS mitigation, networks, distributed systems).
- Collaborative track record working with internal and external teams.
- Excellent verbal and written communication skills.
- Intermediate knowledge of Linux OS internals.
- Advanced knowledge of one programming language and ability to read two high‑level languages such as Java.
- Undergraduate or graduate degree in Electrical Engineering, Computer Science, or related field (or equivalent experience).
- Hands‑on experience developing services on a public cloud platform (AWS, Azure, Oracle).
- Building CI/CD pipelines with robust testing and deployment schedules.
- Experience translating customer requests into prioritized work or features.
- Expertise in risk identification techniques to develop security solutions.
- Knowledge of cryptographic algorithms, standards, and implementation.
- Experience with threat modeling, penetration testing, reverse engineering, and software attacks.
- Experience working with large enterprise customers.
Mid‑Senior level
Employment TypeFull‑time
Job FunctionIT Services and IT Consulting
#J-18808-LjbffrPosition Requirements
10+ Years
work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×