02 Oct
|
ValueLabs
|
Hyderabad
02 Oct
ValueLabs
Hyderabad
Role & responsibilities
Security Architecture &
• Design:
- Architect and implement end-to-end security frameworks for OCI tenancies aligned with CIS OCI Foundations Benchmark, NIST CSF, and ISO 27001.
- Design multi-layer security architectures including perimeter security, network security, workload security, data security, and identity security.
- Conduct cloud security architecture reviews and threat modeling for OCI-hosted applications and infrastructure.
- Define and enforce security baselines, guardrails, and security landing zones for OCI environments.
- Evaluate and recommend OCI-native and third-party security tools and services. Identity &
- Access Management (IAM):
- Design and implement OCI IAM policies, Compartments, Groups, Dynamic Groups, and Federation (SAML, SCIM, LDAP) for enterprise-grade access governance.
- Implement Principle of Least Privilege (PoLP) and Role-Based Access Control (RBAC) across OCI resources.
- Manage OCI Identity Domains, Multi-Factor Authentication (MFA), and Privileged Access Management (PAM) integrations.
- Conduct periodic IAM access reviews and entitlement certifications.
- Implement service account and API key lifecycle management for OCI resources. Data Security &
- Encryption:
- Design and implement data encryption strategies for data at rest and data in transit across OCI services.
- Manage OCI Vault (Key Management Service) for customer-managed encryption keys (CMEKs), secrets, and certificates.
- Implement OCI Data Protected for Oracle Database security assessment, data masking, and sensitive data discovery.
- Configure and manage OCI Object Storage encryption, Block Volume encryption, and Database encryption.
- Define and enforce data classification and data handling policies on OCI.
Network Security
- Design and implement network security controls using OCI Network Firewall, Web Application Firewall (WAF), Security Lists, and Network Security Groups (NSGs).
- Configure OCI DDoS protection, rate limiting, and traffic scrubbing for internet-facing workloads.
- Implement Zero Trust Network Access (ZTNA) principles on OCI.
- Monitor and analyze VCN Flow Logs, Firewall logs, and WAF logs for threat detection.
- Conduct network security assessments and penetration testing coordination.
Threat
Detection, Monitoring &
- Incident Response:
- Implement and manage OCI Cloud Guard for continuous security posture monitoring, threat detection, and automated remediation.
- Configure OCI Security Zones and Security Advisor to enforce security policies at the compartment level.
- Integrate OCI Logging, OCI Logging Analytics, and OCI Events with SIEM platforms (Splunk, IBM QRadar, Microsoft Sentinel) for centralized security monitoring.
- Define and respond to security incidents including investigation, containment, eradication, and recovery.
- Develop and maintain Incident Response (IR) plans, playbooks, and runbooks for OCI environments.
- Conduct regular threat hunting and vulnerability management activities.
Vulnerability
Management &
• Compliance:
- Conduct security assessments, vulnerability scans, and CIS benchmark compliance checks across OCI environments.
- Manage and track remediation of vulnerabilities identified in OCI workloads and infrastructure.
- Ensure compliance with regulatory standards including PCI-DSS, HIPAA, GDPR, SOC 2, and ISO 27001 on OCI.
- Leverage OCI Compliance Documents and perform audit evidence collection for security certifications.
- Implement and manage OCI Audit Service for comprehensive activity logging and forensic readiness. DevSecOps &
- Automation:
- Embed security controls into CI/CD pipelines (shift-left security) including SAST, DAST, SCA, and container image scanning.
- Automate security policy enforcement and compliance checks using Terraform, OCI CLI, and custom Python/Bash scripts.
- Implement OCI Functions for automated security response and remediation.
- Develop security-as-code policies using OPA (Open Policy Agent) or equivalent frameworks.
- Manage secure configuration baselines using Ansible and OCI OS Management Service. Collaboration &
- Stakeholder Engagement:
- Provide security advisory and consultation to project teams during design and implementation phases.
- Conduct security awareness sessions and training for cloud operations and development teams.
- Engage with Oracle security teams, third-party auditors, and regulatory bodies as required.
- Mentor junior security engineers and contribute to security capability building within the organization.
- Prepare security reports, dashboards, and executive summaries for leadership and clients.
📌 OCI Security (Hyderabad)
🏢 ValueLabs
📍 Hyderabad