Technical Program Manager - Vulnerability Management

Oracle
Boston, MA
**Job Description** Oracle's Global Physical Security (GPS) team protects our people, facilities, data centers, and our customer operations worldwide. We design and operate resilient, scalable, and privacy-aware physical security solutions in close partnership with Real Estate & Facilities, Oracle Cloud Infrastructure, Data Center Engineering, Legal/Privacy, Procurement, and Regional Security Operations. GPS is seeking a Technical Program Manager to lead a risk-driven, enterprise-scale vulnerability management program across cyber-physical security technologies. You will own strategy and execution for discovery, assessment, prioritization, and remediation of vulnerabilities impacting access control, video management, SOC platforms, security networks, servers/endpoints, cloud services, and integrations. The role emphasizes risk-based decisioning, automation, cross-functional influence, and audit-ready governance aligned to Oracle's security, privacy, and compliance standards. **Responsibilities** + Daily Responsibilities + Operate a risk-driven vulnerability program that prioritizes by exploitability, asset criticality, exposure, and business impact (e.g., KEV, EPSS, threat intel). + Manage end-to-end workflow: discovery, validation, owner assignment, remediation/mitigation, verification, and closure. + Distinguish and handle internet-exposed vs. internal and OT/IoT assets differently; ensure appropriate SLAs and controls by tier. + Maintain defensible evidence: scan results, ticket trails, approvals, exception/risk-acceptance records, and verification artifacts. + Provide clear, actionable remediation guidance; escalate high-velocity or zero-day risks rapidly and calmly. + Project Participation + Embed vulnerability requirements into new builds, retrofits, and cloud/service integrations for GPS systems. + Review designs for hardening, segmentation, least privilege, and logging; validate secure configurations during FAT/SAT/commissioning. + Coordinate remediation windows with operations and site teams; validate fixes and regressions post-change. + Governance, risk, and compliance + Align program with ISO 27001, NIST 800-53/CSF, and Oracle policies; map controls to audit evidence. + Define risk tiers, SLAs/OLAs, exception processes, and reporting; drive remediation accountability with service owners. + Support privacy-by-design for systems processing personal data (e.g., video, access logs) and coordinate with Legal/Privacy as needed. + Operations enablement + Publish standards, secure baselines, and hardening guides (e.g., CIS Benchmarks) for servers, endpoints, networks, containers/K8s, and cloud. + Build runbooks and playbooks for scanning, validation, patching, compensating controls, and verification. + Mentor developers and regional teams; uplift practices in threat-informed prioritization and measurement. + Technology evaluation + Evaluate and tune scanners and pipelines (e.g., network/agent-based, container/K8s, cloud-native, SCA/SBOM, SAST/DAST/IAST) for coverage and signal quality. + Automate deduplication, asset-owner routing, and fix verification; reduce false positives and toil through APIs and integrations. + Assess vendor solutions for interoperability, API security, data handling, and alignment with zero trust and segmentation principles. + Stakeholder engagement + Influence without authority across OCI, Data Center Engineering, RE&F, Regional Security Operations, IT/Network, SRE, AppSec, and GRC. + Communicate risk, trade-offs, and progress to both technical and executive audiences with crisp, data-driven reporting. + Engage vendors/integrators to track advisories, patches, and secure configurations for GPS platforms. **Minimum Qualifications** + 5+ years running or leading vulnerability management in large, complex enterprises. + Strong understanding of networks, operating systems, cloud (IaaS/PaaS/SaaS), containers/K8s, endpoints, and application security. + Hands-on with scanners and code/dependency tools (e.g., Qualys/Tenable/Rapid7, cloud-native scanners, SCA/SBOM, SAST/DAST/IAST). + Knowledge of CVE/CWE patterns, CVSS and risk modifiers (e.g., EPSS, CISA KEV), exploit timelines, and compensating controls. + Experience with segmentation, zero trust, least privilege, logging/monitoring, and secure baselines (CIS Benchmarks). + Proven ability to manage internet-exposed, internal, and OT/IoT asset classes with differentiated controls and SLAs. + Demonstrated capability to maintain audit-ready evidence and drive remediation through others. **Preferred Qualifications** + Certifications such as CISSP, CISM, GCSA, GCDA, GCIH, GCTI, or comparable. + Familiarity with GPS technology stacks (ACS, VMS, PSIM/C2, SOC platforms) and their supporting networks. + Experience with CMDB/asset intelligence, ITSM/GRC tools, SIEM/SOAR, and automation via APIs/integrations. + Background in incident response for zero-day events and rapid patch/mitigation programs. **Key Competencies** + Risk-driven prioritization and threat-informed decision making. + Technical breadth across infra, cloud, containers, applications, and OT/IoT. + Program design, metrics, and continuous improvement; KPI/KRI-driven reporting. + Cross-functional influence and stakeholder management without formal authority. + Clear written/verbal communication and executive-ready storytelling. + Calm under pressure; decisive during zero-day events; resilient and composed. + High integrity, discretion, and commitment to privacy and compliance. **Work Model and Travel** + Strong ability to work independently and with teams across global time zones. **Notes** + Adherence to Oracle's security, privacy, and compliance standards is mandatory. + When proposing or integrating third-party tools or services, ensure alignment with Oracle's internal security, privacy, and procurement guidelines. \#LI-CG2 Disclaimer: **Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.** **Range and benefit information provided in this posting are specific to the stated locations only** US: Hiring Range in USD from: $106,300 to $223,400 per annum. May be eligible for bonus and equity. Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. Oracle US offers a comprehensive benefits package which includes the following: 1. Medical, dental, and vision insurance, including expert medical opinion 2. Short term disability and long term disability 3. Life insurance and AD&D 4. Supplemental life insurance (Employee/Spouse/Child) 5. Health care and dependent care Flexible Spending Accounts 6. Pre-tax commuter and parking benefits 7. 401(k) Savings and Investment Plan with company match 8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation. 9. 11 paid holidays 10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours. 11. Paid parental leave 12. Adoption assistance 13. Employee Stock Purchase Plan 14. Financial planning and group legal 15. Voluntary benefits including auto, homeowner and pet insurance The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted. Career Level - IC4 **About Us** As a world leader in cloud solutions, Oracle uses tomorrow's technology to tackle today's challenges. We've partnered with industry-leaders in almost every sector-and continue to thrive after 40+ years of change by operating with integrity. We know that true innovation starts when everyone is empowered to contribute. That's why we're committed to growing an inclusive workforce that promotes opportunities for all. Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs. We're committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing [email protected] or by calling +1 888 404 2494 in the United States. Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans' status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
Posted 2025-11-11

Recommended Jobs

Dir Admitting, Registration and Fin Clearance

Brown University Health
Fall River, MA

SUMMARY: Under the general direction of the Vice President of Revenue Cycle, the Director of Patient Admitting, Registration, and Financial Clearance provides strategic and operational leadership …

View Details
Posted 2025-11-05

Dental Receptionist

Cronin's Dental, PC
Waltham, MA

Job Description Job Description We are seeking for a motivated individual who is responsible and can offer excellent customer service. Although we offer specialized training for this position, pr…

View Details
Posted 2025-11-06

Registered Nurse - Adult Psychiatry

Natick, MA

Registered Nurse - Adult Psychiatry Full-Time, Days Natick, Massachusetts $30,000 Sign-on Bonus Salary $95,000 to $135,000 + Full Benefits Willing to train Entry Level RNs Position …

View Details
Posted 2025-10-24

Supply Chain Supervisor

CEDENT
Melrose, MA

Supply Chain Supervisor Location Melrose, IL : Title: Supply Chain Supervisor @ Melrose Park, IL. Terms of Hire: Full Time. Salary: $ 90,000-$100,000/ YR + Benefits. : The Raw Materials Supervisor is…

View Details
Posted 2025-11-14

Host / Hostess

Waffle House, Inc.
Northampton, MA

At Waffle House, we are not in the food business. We are in the People Business and we are hiring immediately for full time and part time servers (all shifts). Being in the People Business, we don’t…

View Details
Posted 2025-11-13

Outside Sales Representative

Fire Equipment Inc
Westford, MA

Service Sales Representative Location: Westford, MA Department: Sales & Business Development Reports To: Sales Manager Compensation: $68k-$215k About Fire Equipment Inc. (FEI) Fire…

View Details
Posted 2025-11-06

Registered Nurse - Hospital Setting

ProPivotal Staffing
Boston, MA

Registered Nurse - Hospital Setting Are you a dedicated and compassionate Registered Nurse looking for a rewarding career in a supportive and dynamic environment? Join us where you can make a diff…

View Details
Posted 2025-11-06

Therapist - Massachusetts

Talkiatry
Massachusetts

Talkiatry’s mission is to transform psychiatry with accessible, human, and responsible care. We’re a national mental health practice co-founded by a patient and a triple-board-certified psychiatrist …

View Details
Posted 2025-09-10

Material Handler 2nd shift - Inventory Control

Johnson Service Group
Auburn, MA

Job Description Job Description Johnson Service Group, has an several openings both part time and full time for a Material Handler with a medical device manufacturer in Auburn, MA Onsite | $18.…

View Details
Posted 2025-11-04

SAH Environmental Service Associate I

Brown University Health
Fall River, MA

SUMMARY: Performs various cleaning functions in assigned work area following established policies and procedures necessary to maintain the hospital in a sanitary, attractive, and orderly condition. Ot…

View Details
Posted 2025-10-23