06 Aug
|
Vericence
|
India
About Vericence
Vericence is a digital engineering and technology consulting firm helping enterprises build AI-driven platforms, modernize legacy systems, and scale innovation through cloud, data, and intelligent engineering. We partner with global organizations to deliver high-impact technology solutions and build world-class engineering teams.
Security & IAM Engineer
Lead the design and implementation of secure, governed, least-privilege identity, access, data-protection, and AI security controls for the OCI AIDP Lakehouse platform.
Job Description
We are seeking an experienced Security & IAM Engineer to secure and govern the OCI AIDP Lakehouse platform across identity, access, data protection, cloud security posture, audit readiness, and AI-enabled consumption patterns. This role will implement secure-by-design controls across Oracle Cloud Infrastructure, including IAM policies, compartments, dynamic groups, federation, network security, encryption, secrets management, Cloud Guard, Data Safe, logging, monitoring, and evidence-generation patterns required for regulated healthcare data environments.
This role reports to the Principal Data Engineering Lead and operates within the Data Governance, AI & Analytics organization as part of the Enterprise Data Lakehouse Architecture and Platform team. The ideal candidate brings hands-on experience securing cloud-native data platforms, implementing least-privilege IAM, protecting PHI and sensitive data, supporting compliance programs, and enabling secure GenAI, RAG, vector search, and agentic workflow adoption without weakening governance, privacy, or operational controls.
What You Will Do
OCI Security and Identity Architecture
- Design, implement, and maintain OCI IAM policies, groups, dynamic groups, service principals, federation patterns, compartment structures, tenancy guardrails, and least-privilege access models for human and non-human identities.
- Configure and operationalize OCI security capabilities, including Vault, key management, secrets management, Security Zones, Cloud Guard, Logging, Monitoring, audit trails, network security controls, and security posture management.
- Partner with platform architecture, DevOps, infrastructure, and engineering teams to embed security controls into infrastructure-as-code, CI/CD pipelines, environment promotion gates, and production deployment patterns.
- Troubleshoot complex authentication, authorization, access, and security configuration issues while maintaining clear documentation, stakeholder communication, and operational continuity.
Data Protection, PHI Controls, and Governed Access
- Implement PHI discovery, sensitive-data classification, masking, tokenization, encryption, privileged access monitoring, and secure consumption patterns using OCI Data Safe and enterprise-approved security tooling.
- Define and support row-level, column-level, attribute-based, and role-based access controls for governed data products, semantic layers, analytics consumers, AI workloads, and operational support teams.
- Ensure source-data permissions, classifications, lineage, metadata, and quality signals are inherited by downstream lakehouse, semantic, vector, RAG, and GenAI consumption patterns.
- Develop reusable security patterns for enterprise domains such as Provider, Product, Claims, Member, Finance, and future acquisition data sources.
Compliance, Audit Readiness, and Security Operations
- Support HIPAA-oriented, privacy-sensitive, and regulated-data control requirements through audit logging, traceability, evidence capture, access reviews, control testing, remediation tracking, and operational reporting.
- Configure logging, monitoring, alerting, SIEM integrations, vulnerability-management workflows, and investigation patterns to improve detection, response, and forensic readiness across OCI workloads.
- Partner with governance, risk, legal, privacy, compliance, platform, and engineering stakeholders to validate control effectiveness and maintain audit-ready security documentation.
- Contribute to incident response, threat modeling, architecture reviews, control exception analysis, and continuous improvement of cloud security operations.
AI Security and Responsible AI Guardrails
- Establish security guardrails for GenAI, RAG, embeddings, vector indexes, semantic models, agent identities, scoped permissions, prompt handling, context retention, logging, evaluation, and human approval workflows.
- Ensure AI-enabled data products and agentic workflows remain secure, auditable, explainable, privacy-aware, and aligned to approved governance and responsible AI standards.
- Partner with AI-native delivery, data engineering, security, and governance teams to validate AI workload release gates, access boundaries, monitoring expectations, and operational support models.
- Document AI security patterns, acceptable-use boundaries, monitoring procedures, and evidence requirements for production AI adoption in regulated data environments.
What You Will Deliver
- OCI IAM and security-control design covering compartments, tenancy guardrails, federation, dynamic groups, service principals, policies, least-privilege access, and environment-level security patterns.
- Data-protection implementation pattern for PHI discovery, classification, masking, encryption, tokenization, privileged access monitoring, audit logging, and governed data consumption.
- Access-control model for governed data products, semantic layers, analytics users, support personas, AI workloads, and non-human identities across development, test, and production environments.
- Security gates, audit-readiness checklist, control evidence templates,
logging and monitoring requirements, incident-response inputs, and vulnerability remediation tracking patterns.
- AI workload security guardrails for GenAI, RAG, embeddings, vector search, agentic workflows, prompt/context handling, scoped access, retention, monitoring, and human approval workflows.
- Reusable security runbooks, operating procedures, control documentation, architecture review materials, and executive-ready summaries that support pilot delivery and enterprise scale-out.
Required Qualifications, Capabilities, and Skills
- 8+ years of experience in cloud security, identity and access management, cybersecurity engineering, data protection, infrastructure security, or related technology roles.
- Hands-on experience designing and implementing OCI security services, IAM policies, compartments, federation, Vault, key management, secrets management, logging, monitoring, Cloud Guard, and secure networking patterns.
- Strong understanding of least privilege, RBAC, ABAC, identity lifecycle management, privileged access, service identities, non-human identities, CI/CD access controls, and secure-by-design cloud operations.
- Experience securing data platforms, lakehouse environments, analytics platforms, AI-enabled workloads, or enterprise-scale cloud environments supporting sensitive or regulated data.
- Working knowledge of PHI protection, data classification, masking, encryption, audit logging, evidence capture, access reviews, and compliance-oriented security controls.
- Ability to collaborate effectively with platform, data engineering, DevOps, governance, privacy, compliance, business, and leadership stakeholders while communicating technical risks and trade-offs clearly.
Preferred Qualifications, Capabilities, and Skills
- Experience with OCI Data Safe, Cloud Guard, Security Zones, Vault, KMS, Logging, Monitoring, identity federation, Autonomous Data Warehouse, Autonomous AI Lakehouse, OCI Data Integration, Object Storage, and related OCI platform services.
- Experience implementing security automation using Terraform, OCI CLI, OCI SDK, Python, policy-as-code, CI/CD pipelines, automated validation, or comparable DevSecOps tooling.
- Familiarity with healthcare payer, claims, member, provider, finance, acquisition integration, PHI, HIPAA-adjacent, privacy-sensitive, or other regulated data environments.
- Experience with AI security and responsible AI controls, including OWASP LLM risks, NIST AI RMF, ISO/IEC 42001, prompt and context protection, model access governance, and agentic workflow controls.
- Relevant OCI, cloud security, IAM, data protection, cybersecurity, privacy, or governance certifications such as OCI Security Skilled, CISSP, CCSP, CISM, CISA, or comparable credentials are preferred.
- Experience producing professional security artifacts such as control designs, reference patterns, runbooks, threat models, security standards, audit evidence templates, architecture review materials, and executive-level risk summaries.
📌 Security & IAM Engineer (India)
🏢 Vericence
📍 India