Negotiable
Undetermined
Undetermined
London Area, United Kingdom
Summary: The Database Security Specialist at HCLTech will focus on Oracle database security engineering, managing security control onboarding, and ensuring compliance with security policies. The role requires collaboration with product teams to integrate security controls and prepare for audits. Candidates should possess a strong background in security engineering and database management, particularly with Oracle technologies. This position offers opportunities for professional growth within a diverse and supportive team environment.
Key Responsibilities:
- Possess expertise in Oracle database security principles, best practices, and configurations.
- Design, implement, and review security controls for Oracle platform.
- Perform security assessments and vulnerability reviews specifically for Oracle environments.
- Troubleshoot and resolve security-related issues within Oracle database environments.
- Manage security control onboarding streams concurrently, from initiation to closure.
- Develop and execute plans for onboarding controls, including scope definition, resource allocation, timelines, and risk management.
- Track progress, identify dependencies, and proactively address impediments.
- Communicate onboarding status, risks, and issues to stakeholders at all levels.
- Ensure timely and high-quality delivery of all security onboarding deliverables.
- Collaborate closely with Product Team to integrate and onboard product to security controls.
- Work with CSO to agree compliance and onboarding requirements to CSO controls.
- Interpret security policies and standards to define appropriate control compliance for new and existing products.
- Facilitate the implementation of security controls, including but not limited to: certificate management, (automation) access management and Authorisation, data encryption, and secure configuration.
- Work with engineering teams to implement and test security controls.
- Develop and maintain documentation for security onboarding processes and control implementation.
- Proactively identify and collect evidence demonstrating compliance with security controls and mapping to client Standards and policies.
- Prepare and maintain detailed documentation, reports, and artifacts for internal and external audits.
- Act as a primary point of contact during security control reviews, effectively explaining and demonstrating control effectiveness.
- Identify and track any gaps in control implementation or evidence, working with relevant teams to remediate them.
Key Skills:
- Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field.
- Relevant industry certifications (e.g., CISSP, Oracle Certified Professional - Security) are highly desirable.
- Proven experience in security engineering, security architecture, or security compliance roles.
- Strong understanding of security principles, frameworks (e.g., NIST, ISO 27001), and compliance requirements (e.g., SOC 2, GDPR, HIPAA).
- Experience with various security controls, including access management (IAM), data encryption, network security, vulnerability management, and SIEM.
- Experience with Oracle databases, including installation, configuration, administration, and security hardening.
- Understanding of Oracle security features (e.g., TDE, auditing).
- Experience with database patching, upgrades, and performance tuning from a security perspective.
- Familiarity with other database technologies (e.g., PostgreSQL, SQL Server, NoSQL) is a plus.
- Demonstrated experience in managing and implementing controls.
- Proficiency with project management methodologies (e.g., Agile, Waterfall) and tools (e.g., JIRA, Asana, Microsoft Project).
- Strong organizational skills, ability to prioritize tasks, and manage multiple parallel initiatives.
- Experience in preparing for security control reviews and evidencing.
- Excellent written and verbal communication skills, with the ability to articulate complex security concepts to technical and non-technical audiences.
- Proven ability to build strong relationships and collaborate effectively with diverse teams (Product, Engineering, Operations, Audit).
- Strong analytical and problem-solving skills.
- Self-motivated, proactive, and able to work independently and as part of a team.
Salary (Rate): undetermined
City: London Area
Country: United Kingdom
Working Arrangements: undetermined
IR35 Status: undetermined
Seniority Level: undetermined
Industry: IT
We are a $13+ billion global technology company, home to more than 224,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud, and AI, powered by a broad portfolio of technology services and products. HCLTech is a globally recognized leader in the Tech and IT industry, but we’ve never forgotten the startup mindset that got us here. We’ve always approached our work with an idea-first attitude because every one of our accomplishments —no matter how big or small —can be traced back to an idea’s single spark. It’s that spark —that inner drive —that sets our people apart from our competitors. It enables us not just to pull off game-changing feat after game-changing feat but to better our world in the process. We want you to find your spark. Because that’s what drives you to be better, be more and ultimately, be more fulfilled.
Key Responsibilities:
- Database Security Engineering (Oracle Focus): Possess expertise in Oracle database security principles, best practices, and configurations.
- Design, implement, and review security controls for Oracle platform.
- Perform security assessments and vulnerability reviews specifically for Oracle environments.
- Troubleshoot and resolve security-related issues within Oracle database environments.
- Management & Delivery: Manage security control onboarding streams concurrently, from initiation to closure.
- Develop and execute plans for onboarding controls, including scope definition, resource allocation, timelines, and risk management.
- Track progress, identify dependencies, and proactively address impediments.
- Communicate onboarding status, risks, and issues to stakeholders at all levels.
- Ensure timely and high-quality delivery of all security onboarding deliverables.
- Security Onboarding & Product Integration: Collaborate closely with Product Team to integrate and onboard product to security controls.
- Work with CSO to agree compliance and onboarding requirements to CSO controls.
- Interpret security policies and standards to define appropriate control compliance for new and existing products.
- Facilitate the implementation of security controls, including but not limited to: certificate management, (automation) access management and Authorisation, data encryption, and secure configuration.
- Work with engineering teams to implement and test security controls.
- Develop and maintain documentation for security onboarding processes and control implementation.
- Security Control Evidencing & Audit Readiness: Proactively identify and collect evidence demonstrating compliance with security controls and mapping to client Standards and policies.
- Prepare and maintain detailed documentation, reports, and artifacts for internal and external audits.
- Act as a primary point of contact during security control reviews, effectively explaining and demonstrating control effectiveness.
- Identify and track any gaps in control implementation or evidence, working with relevant teams to remediate them.
Required Skills & Experience:
- Education: Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field.
- Relevant industry certifications (e.g., CISSP, Oracle Certified Professional - Security) are highly desirable.
- Security Expertise: Proven experience in security engineering, security architecture, or security compliance roles.
- Strong understanding of security principles, frameworks (e.g., NIST, ISO 27001), and compliance requirements (e.g., SOC 2, GDPR, HIPAA).
- Experience with various security controls, including access management (IAM), data encryption, network security, vulnerability management, and SIEM.
- Database Engineering (primarily Oracle): Experience with Oracle databases , including installation, configuration, administration, and security hardening.
- Understanding of Oracle security features (e.g., TDE, auditing).
- Experience with database patching, upgrades, and performance tuning from a security perspective.
- Familiarity with other database technologies (e.g., PostgreSQL, SQL Server, NoSQL) is a plus.
- Delivery Management: Demonstrated experience in managing and implementing controls.
- Proficiency with project management methodologies (e.g., Agile, Waterfall) and tools (e.g., JIRA, Asana, Microsoft Project).
- Strong organizational skills, ability to prioritize tasks, and manage multiple parallel initiatives.
- Compliance: Experience in preparing for security control reviews and evidencing.
- Ability to gather, organize, and present evidence of design and control effectiveness.
- Understanding of compliance requirements and expectations.
- Communication & Collaboration: Excellent written and verbal communication skills, with the ability to articulate complex security concepts to technical and non-technical audiences.
- Proven ability to build strong relationships and collaborate effectively with diverse teams (Product, Engineering, Operations, Audit).
- Strong analytical and problem-solving skills.
- Self-motivated, proactive, and able to work independently and as part of a team.
Benefits: A supportive, diverse and global team with a brilliant culture. Great opportunities to make the role your own, upskill yourself and get involved with exciting projects. Total Wellbeing is our focus. Alongside your professional excellence, you join the likeminded colleagues to create a larger impact within the company and society at large in your chosen area of passion - CSR Council, Diversity Council, Women Connect, Sparks – Engagement Champion to name a few. To know more about us visit – www.hcltech.com For more information on how we process your personal data, please refer to HCLTech’s Candidate Data Privacy Notice.