Role: Cloud Security Engineer OCI & SaaS Security
Location : Phoenix, AZ (Onsite)
Role Overview
We are seeking an experienced Cloud Security Engineer with strong expertise in Oracle Cloud Infrastructure (OCI), SaaS Security, Cloud Security Assessments, and Security Governance.
The ideal candidate will evaluate OCI services, SaaS applications, cloud architectures, integrations, and configurations to ensure alignment with enterprise security standards, regulatory requirements, and risk management practices.
This role combines hands-on cloud security engineering, SaaS security assessments, security architecture, governance, and security automation.
Key Responsibilities
Cloud & SaaS Security Assessments
- Conduct security reviews of OCI services, SaaS applications, cloud architectures, integrations, and configurations.
- Identify security risks, control gaps, vulnerabilities, and remediation opportunities.
- Evaluate solutions against enterprise security standards, policies, and regulatory requirements.
- Provide security recommendations to support secure-by-design cloud and SaaS adoption.
- Participate in architecture reviews, onboarding assessments, risk reviews, and security certification processes.
Security Domains
Perform security assessments across:
- Identity & Access Management (IAM)
- Network Security
- Data Protection & Encryption
- Logging & Monitoring
- Compute & Container Security
- API Security
- SaaS Security Posture Management (SSPM)
- CASB / SaaS Security
- AI / GenAI Security
- Third-Party & Vendor Risk
OCI Security & Engineering
- Assess and support security controls within Oracle Cloud Infrastructure (OCI).
- Review OCI IAM, networking, data protection, logging, monitoring, and workload security.
- Support OCI security capabilities such as Cloud Guard and Security Zones.
- Help establish and maintain OCI security baselines, guardrails, and reference architectures.
- Partner with cloud/platform engineering teams to implement security controls.
SaaS Security Governance
- Perform SaaS onboarding and security certification assessments.
- Evaluate SaaS architectures, integrations, data flows, identity controls, and security configurations.
- Assess SaaS security posture, configuration drift, excessive permissions, identity risks, and data exposure.
- Support SSPM and CASB capabilities.
- Support SaaS inventory management and Shadow IT discovery.
- Participate in third-party SaaS/vendor security assessments.
Security Standards & Governance
- Map OCI and SaaS security implementations to recognized frameworks and enterprise controls, including:
- NIST
- ISO 27001
- CIS
- CSA Cloud Controls Matrix (CCM)
- Validate cloud and SaaS environments against secure configuration baselines.
- Support development and maintenance of cloud/SaaS security standards, guardrails, and onboarding requirements.
- Document findings, recommendations, evidence, and remediation requirements.
Security Automation
- Support security automation using Terraform / Infrastructure-as-Code (IaC).
- Assist with policy-as-code and automated compliance/security controls.
- Support integration of security monitoring, posture management, and compliance capabilities into cloud environments.
- Partner with DevOps/platform engineering teams to embed security into CI/CD and operational processes.
Required Qualifications
- Strong experience performing cloud security assessments in OCI or another major cloud platform.
- Hands-on understanding of:
- IAM
- Network Security
- Data Protection & Encryption
- Cloud Logging & Monitoring
- Compute / Container Security
- Experience performing SaaS security assessments, onboarding, or certification reviews.
- Strong understanding of SaaS security posture management (SSPM) and/or CASB technologies.
- Experience reviewing cloud architecture and Infrastructure-as-Code, preferably Terraform.
- Knowledge of cloud shared responsibility models and secure-by-design principles.
- Strong understanding of security risk assessment and remediation processes.
- Ability to communicate security findings and recommendations to both technical and non-technical stakeholders.
Preferred Qualifications
- Oracle Cloud Infrastructure (OCI) certification.
- Hands-on experience with:
- OCI Cloud Guard
- OCI Security Zones
- OCI IAM and security controls
- Oracle SaaS platforms
- SSPM
- CASB
- Policy-as-Code
- Automated compliance/security tooling
- Experience with AI/GenAI security assessments.
- Experience with GitHub, CI/CD pipelines, DevSecOps, and cloud security automation.
- Experience with security frameworks such as NIST, ISO 27001, CIS, and CSA CCM.