Oracle User Security Lead

Information TechnologyHybrid Remote, Santa Clara, CA


Description

Shockwave Medical, Inc. is a pioneer in the development and commercialization of Intravascular Lithotripsy (IVL) to treat complex calcified cardiovascular disease. Shockwave Medical aims to establish a new standard of care for medical device treatment of atherosclerotic cardiovascular disease through its differentiated and proprietary local delivery of sonic pressure waves for the treatment of calcified plaque.

 

Position Overview

The Oracle User Security Lead is a senior-level role responsible for managing, enhancing, and ensuring the security and compliance of user access within Oracle Cloud applications, with a focus on Segregation of Duties (SOD) controls, within a medical device company. This position plays a pivotal role in safeguarding sensitive data, managing access controls, and ensuring regulatory compliance.

 

Essential Job Functions 

  • User Access Governance: Develop, implement, and lead user access governance processes, policies, and procedures for Oracle Cloud applications to ensure secure, compliant, and efficient user access management.
  • Access Control Management: Administer user accounts, roles, and permissions within Oracle Cloud applications, with a focus on SOD controls, ensuring that access is appropriate based on job roles, responsibilities, and regulatory requirements (e.g., FDA regulations).
  • SOD Controls: Design, implement, and enforce robust Segregation of Duties (SOD) controls within Oracle Cloud, identifying and mitigating conflicts that could lead to security risks and compliance violations.
  • Security Policies: Define, enforce, and regularly update security policies, access controls, and security standards for Oracle Cloud, aligning them with industry best practices and regulatory mandates.
  • Role and Privilege Management: Define, maintain, and optimize role-based access controls (RBAC), privileges, and access matrices within Oracle Cloud applications, adhering to the principle of least privilege (PoLP).
  • Access Reviews and Audits: Plan, conduct, and lead regular access reviews, audits, and assessments to validate user access, detect unauthorized access, and ensure compliance with security policies, SOD controls, and audit and regulatory requirements.
  • Incident Response: Develop, implement, and lead incident response plans for security breaches or unauthorized access incidents within Oracle Cloud applications, ensuring timely resolution and reporting in compliance with regulations.
  • User Training and Awareness: Develop and deliver comprehensive training, guidance, and awareness programs to educate end-users, administrators, and stakeholders on Oracle Cloud security best practices, SOD controls, and data protection.
  • Compliance Monitoring: Establish continuous monitoring mechanisms to assess Oracle Cloud applications for compliance with industry standards, security regulations, SOD controls, and internal security policies.
  • Security Enhancements: Identify opportunities and lead initiatives for enhancing security within Oracle Cloud applications, collaborating closely with IT teams to implement security improvements.
  • Documentation and Reporting: Maintain meticulous documentation of user access configurations, security policies, access control procedures, security incidents, and SOD conflict resolutions. Generate and present regular security reports to management.
  • Vendor Collaboration: Collaborate with Oracle and third-party vendors to stay updated on security patches, updates, best practices, and solutions that enhance security and SOD controls within Oracle Cloud.

 

Qualifications

  • Bachelor’s degree in computer science preferred.
  • Typically 10+ years of experience in user access and security management roles.
  • Extensive and demonstrated experience in user access and security management within Oracle Cloud applications, with a proven track record of leadership, especially in regulated industries.
  • Strong expertise in designing, implementing, and managing SOD controls within Oracle Cloud.
  • In-depth understanding of Oracle Cloud security features, configurations, best practices, and regulatory requirements.
  • Comprehensive knowledge of regulatory requirements in the medical device industry, including FDA regulations.
  • Exceptional problem-solving, communication, leadership, and project management skills.
  • Meticulous attention to detail and the ability to work effectively both independently and collaboratively.
  • At least 4 Oracle cloud implementations you have managed the user security process end to end and also at least 4 cycles with auditors.
  • Understanding of integration of user orchestration from perpipheral systems like ADP, Workday etc.
  • Experience in user on(off)-boarding on a run time within predefined SLAs.
  • Usage of Risk Compliance or GRC tools desired.
  • Exposure to IAM tools (like Sailpoint etc.) and concomitant user on-boarding and off-boarding orchestration knowledge would be a plus.
  • Exposure to Fastpath, Auditboard or similar tools will be a plus.
  • Exposure to change control procedures and deployment orchestration would be a plus.

 

Market Range: $155,000 - $173,000
Exact compensation may vary based on skills, experience, and location.

Benefits
Shockwave Medical offers a competitive total compensation package as well as the following benefits and perks:

Core Benefits: Medical, Dental, Vision, Pre-tax and Roth 401k options with a fully vested match, Short-Term and Long-Term Disability, and Life Insurance, Employer contribution toward Health Savings Account (HSA), Competitive PTO balance

Perks: ESPP, Calm App, Pet Insurance, Student Loan Refinancing, Spot Bonus awards

EEO Employer