Get introduced to vetted companies that are still hiring

Create a profile to become searchable by hiring managers.

0
JOBS
0
COMPANIES

Third-Party Incident Management Lead

 Oracle Cloud Infrastructure

Oracle Cloud Infrastructure

Nashville, TN, USA
USD 104,200-223,400 / year + Equity
Posted on Sep 10, 2025

Third-Party Incident Management Lead

Nashville, TN, United States
  • Job Identification 306965
  • Job Category Information Security Engineer
  • Posting Date 08/09/2025, 22:38
  • Role Individual Contributor
  • Job Type Regular Employee
  • Does this position require a security clearance? No
  • Years 10+ years
  • Additional Info Visa / work permit sponsorship is not available for this position
  • Applicants are required to read, write, and speak the following languages English

Job Description

The Third-Party Incident Management Lead is responsible for coordinating Oracle’s response to cybersecurity incidents involving third-party partners and suppliers. This role ensures that incidents are logged, assessed, escalated, managed, and closed in a manner that protects Oracle’s assets, meets contractual and regulatory obligations, and drives continual improvement in Third-Party Risk Management (TPRM) practices.

Responsibilities

1. Third-Party Breach Management

  • Acknowledge and log breach notifications received from Third-Parties.
  • Perform criticality and risk assessments based on breach information and third-party profiles.
  • Coordinate information gathering from impacted Third-Parties.
  • Activate and manage internal incident response processes when Oracle data, services, or assets may be affected.

2. Incident Coordination and Stakeholder Management

  • Serve as the central point of coordination across GIS, Legal, Privacy, Corporate Communications, and affected LoBs.
  • Facilitate joint response calls, action tracking, and unified decision-making across business areas.
  • Prepare and distribute timely and consistent communications to executive leadership and key stakeholders.

3. Regulatory and Contractual Compliance

  • Assess whether the Third-Party has met its contractual obligations to Oracle regarding breach notification, remediation efforts, and information sharing.
  • Review breach response activities against the terms outlined in the vendor’s contract, including timelines for notification, disclosure requirements, and security obligations.
  • Collaborate with Legal and Procurement teams to evaluate if any failures to meet obligations require escalation, remediation demands, or contractual enforcement actions.
  • Ensure that all third-party responses are documented thoroughly to demonstrate compliance (or non-compliance) with Oracle’s legal, regulatory, and contractual standards.
  • Support preparation of customer or regulator disclosures if a Third-Party’s failure impacts Oracle’s compliance obligations.

4. Response Procedure Execution

  • Manage processes including:
    • Monitoring and detection of threats.
    • Dissemination of Indicators of Compromise (IOCs) and threat intelligence.
    • Access revocation and system isolation when needed.
    • Deployment of temporary security controls to contain or mitigate threats.
    • Oversight of SSO integration responses and API-related risk mitigations.

5. Remediation Monitoring and Post-Incident Analysis

  • Track and validate Third-Party remediation efforts.
  • Lead post-incident reviews to capture lessons learned.
  • Recommend updates to playbooks, TPRM processes, and vendor engagement strategies based on incident outcomes.

Qualifications

Disclaimer:

Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.

Range and benefit information provided in this posting are specific to the stated locations only

US: Hiring Range in USD from: $104,200 to $223,400 per annum. May be eligible for bonus and equity.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto, homeowner and pet insurance

The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.

Career Level - IC4


Required Skills

10+ years experience in cybersecurity incident management, third-party risk management, or security operations. Ability to work under pressure during active incident response situations. Excellent communication, stakeholder management, and organizational skills. Practical experience coordinating multi-party breach responses involving third-parties. Strong knowledge of breach notification requirements, regulatory, and third-party contract structures. Understanding of technical security concepts (e.g., threat detection, SIEM, endpoint monitoring, access controls, API security).

About Us

As a world leader in cloud solutions, Oracle uses tomorrow’s technology to tackle today’s challenges. We’ve partnered with industry-leaders in almost every sector—and continue to thrive after 40+ years of change by operating with integrity.

We know that true innovation starts when everyone is empowered to contribute. That’s why we’re committed to growing an inclusive workforce that promotes opportunities for all.

Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.

We’re committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing accommodation-request_mb@oracle.com or by calling +1 888 404 2494 in the United States.

Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

Request a referral from an Oracle employee.

Similar Jobs