> Markdown version of [/jobs/ext/140732-information-security-architect](https://www.wearedevelopers.com/jobs/ext/140732-information-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Architect - **Company:** Hollstadt Consulting - **Location:** United States (Remote available) - **Salary:** $142,605.0 - $184,392.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Application Firewall, Architectural Patterns, Audit Trail, Cloud Computing, Code Coverage, Cyber Security, Data Security, Multi-Factor Authentication, Identity and Access Management, Internet Security, Key Management, Network Security, Oracle (Applications), Platform as a Service (PAAS), Role-Based Access Control, Cloud Services, Security Information and Event Management, Single Sign-On, Oracle Fusion Middleware, Data Streaming, System Integration Testing, Systems Integration, Data Logging, Software Security, Oracle Ebusiness, Elastic Beanstalk, Oracle Integration, Oracle Cloud Infrastructure - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3bf67c132cae3210 ## About the Role Do you have experience in WAF? ## Description The client is seeking an Information Security Architect with deep Oracle security expertise with financial knowledge to lead security architecture and control design for the migration from Oracle E-Business Suite (EBS) to Oracle Fusion Cloud, supported by Oracle Cloud Infrastructure (OCI) and PaaS services such as Oracle Integration Cloud (OIC) and Visual Builder Cloud Service (VBCS). This role serves as the enterprise authority for Oracle security architecture, covering application security role-based access controls (RBAC), Segregation of Duties (SoD) and Sensitive Access (SA), automated controls, system hardening, and identity architecture for single sign-on (SSO) and multi-factor authentication (MFA). The Architect partners with implementation teams, business owners, and audit stakeholders to ensure a secure, compliant, and audit-ready deployment., 1) Oracle Security Architecture Leadership * Own end-to-end security architecture across Oracle Fusion, OCI, and PaaS (OIC, VBCS) environments. * Translate security and compliance requirements into architecture patterns spanning: + Fusion roles, privileges, and data security + OCI IAM, compartments, and policies + PaaS service security + Enterprise IAM integration (SSO, MFA, federation) * Serve as the escalation point for security design decisions, risks, and deviations. 2) Access Model Governance * Govern design and delivery of: + RBAC aligned to job personas and least privilege + SoD and SA rule frameworks, analysis, and remediation + Role design workshops, configuration, system integration testing (SIT) user acceptance testing (UAT), and validation * Ensure: + Conflict identification and resolution with business owners + Test coverage (positive/negative scenarios) + Role-based license optimization + Audit-ready application security documentation 3) Automated Controls & Audit Enablement * Define and validate automated business process controls (ABPC) addressing key financial and operational risks. * Oversee: + Control design, configuration, and effectiveness testing + Audit policy enablement for high-risk transactions and configurations * Lead compensating control strategy where automation is not feasible: + Document mitigations + Align with process owner accountability + Ensure audit readiness and traceability 4) Identity Architecture integration * Lead design and validation of Oracle Cloud identity architecture across: + Fusion applications + OCI, OIC * Ensure alignment with enterprise identity and access strategy: + Federation with corporate identity provider + Conditional access and MFA enforcement + Break-glass access and logging * Oversee implementation partner deliverables across build, testing, and deployment. 5) OCI & PaaS Security Architecture and Hardening * Define and govern OCI security architecture, including: + System environment strategy (Dev/Test/Pre-Prod/Prod) + IAM policies, dynamic groups, and SoD enforcement * Secure network and perimeter controls: + Security lists, private endpoints, service gateways + OCI firewall and egress controls * Protect applications and APIs: + OCI web application firewall (WAF) deployment for Fusion/OCI elements + Certificate lifecycle management design * Secure integrations (OIC, on-prem, third-party): + Strong authentication/authorization + Encrypted and integrity-protected data flows * Establish platform hardening baseline: + CIS-aligned configurations + Vault/key management and secrets protection + Object storage security controls * Enable monitoring and detection: + Audit logs, WAF logs, service telemetry + SIEM integration, alerting, and incident response 6) Integration Security - (OIC & Third-Party) * Lead security architecture and governance for integrations across Oracle Integration Cloud (OIC), Fusion, OCI, on-prem systems, and third-party applications. * Define and enforce secure integration patterns, including: + API authentication and authorization + Secure credential management and secrets handling + Data encryption in transit and message integrity validation ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Mutation Testing and Fuzzing in C#](https://www.wearedevelopers.com/videos/703-mutation-testing-and-fuzzing-in-c) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Test-reduction - Doing more with less](https://www.wearedevelopers.com/videos/977-test-reduction-doing-more-with-less) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)