Principal Technical Program Manager

Oracle
Saint Paul, MN, United States
2 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$97,500.0 - $209,500.0
Working hours
Regular working hours
Job source

Tech stack

Cerner Kubernetes Security Amazon Web Services Systems Engineering Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Configuration Management Cyber Security Information Systems
+18 more
Continuous Integration Federal Information Processing Standards (FIPS) Infrastructure as a Service (IaaS) Identity and Access Management Key Management Network Segmentation Package Development Process Cloud Services Data Streaming Software Vulnerability Management Data Logging Cloud Platform System Kubernetes Infrastructure Automation Frameworks Information Technology Data Analytics RSA Archer Platform Oracle Cloud Infrastructure

Job description

Oracle Health is seeking a Principal Technical Program Manager to establish and lead the Product Authorization Team responsible for FedRAMP assessment readiness, authorization strategy, and continuous security assurance for cloud service offerings. This role combines principal-level technical program leadership with deep cloud security and compliance-engineering expertise.

You will create the operating model that turns federal security requirements into sustainable engineering practices, trusted evidence, measurable security outcomes, and clear executive decisions. You will work at the intersection of cloud architecture, security engineering, product delivery, and federal authorization. Success requires the ability to move comfortably between architecture and control discussions, third-party assessment strategy, remediation execution, and senior-leadership tradeoffs.

This is a hands-on leadership role. You will not serve as the independent assessor; however, you must have sufficient security-engineering depth to challenge design assumptions, assess evidence quality, identify material gaps, and drive practical remediation with technical teams.

Responsibilities

  • Stand up the Oracle Health Product Authorization FedRamp Team and define its charter, service model, roles, intake and prioritization process, governance cadences, quality standards, metrics, and escalation paths.

  • Own the multi-year FedRAMP authorization and certification roadmap for assigned cloud offerings, including scope, sequencing, authorization-path recommendations, dependencies, reuse opportunities, investment needs, and transition to continuous assurance.

  • Establish a scalable assessment operating model for readiness reviews, authorization-boundary definition, evidence planning, package development, 3PAO engagement, testing, findings management, remediation validation, and post-authorization monitoring.

  • Partner with architecture and security-engineering teams to evaluate service boundaries, data flows, interconnections, multi-tenancy, identity, encryption, logging, resilience, supply-chain dependencies, control inheritance, and customer-responsible controls.

  • Translate FedRAMP, NIST, and federal risk-management requirements into owned, testable, time-bound engineering and operational deliverables; set acceptance criteria for evidence, security decisions, and remediation plans.

  • Design reusable evidence and assurance patterns using security telemetry, infrastructure as code, CI/CD controls, configuration validation, GRC workflows, machine-readable data, and automation where appropriate.

  • Lead strategic engagement with 3PAOs, FedRAMP and agency stakeholders, federal customers, advisors, and critical suppliers; resolve escalations involving scope, testing, evidence, findings, or schedule.

  • Drive material risks, findings, and plans of action through root-cause analysis, prioritization, remediation, validation, risk acceptance, and closure; ensure decisions are documented and traceable.

  • Establish executive dashboards and operating reviews that show authorization readiness, critical-path dependencies, evidence quality, open findings, vulnerability and change posture, staffing needs, and decisions required.

  • Embed authorization obligations into secure software delivery, vulnerability management, incident response, change management, configuration management, contingency planning, and cloud operations.

  • Create a continuous-monitoring and ongoing-certification model that keeps authorization information current, supports required reporting, and enables agencies to make informed risk decisions.

  • Mentor TPMs and security partners, publish playbooks and reusable patterns, and raise the organization’s capacity to deliver federal authorizations consistently without weakening security outcomes.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related discipline, or equivalent practical experience.

  • Seven or more years of experience in technical program management, security program leadership, cloud delivery, compliance engineering, security engineering, or a related technology field, including responsibility for complex cross-organizational programs.

  • Demonstrated experience leading an end-to-end FedRAMP certification or authorization, federal Authority to Operate, or comparably complex regulated cloud-assurance program from strategy or readiness through assessment, remediation, decision, and ongoing monitoring.

  • Deep working knowledge of FedRAMP authorization and certification processes; NIST SP 800-53 Rev. 5; FIPS 199; federal risk management; control implementation and assessment; control inheritance; significant change; vulnerability management; remediation; and continuous monitoring.

  • Strong technical understanding of SaaS and IaaS architecture, including authorization boundaries, multi-tenancy, identity and access management, network segmentation, encryption and key management, logging and monitoring, secure software delivery, resilience, and supply-chain dependencies.

  • Demonstrated ability to define operating models, governance, roadmaps, metrics, and executive decision mechanisms across Security, Engineering, Product, Operations, Compliance, Legal, and business organizations.

  • Experience assessing technical evidence and communicating concrete security requirements to engineering teams, including cloud configuration, vulnerability, identity, logging, encryption, change, and incident-response evidence.

  • Experience leading engagements and resolving complex issues with independent assessors, agencies, authorizing stakeholders, federal customers, or comparable external oversight bodies.

  • Exceptional written, verbal, and executive communication skills, including the ability to translate technical and regulatory complexity into clear business risk, investment choices, and recommendations.

  • Proven ability to influence senior leaders and technical teams, resolve competing priorities, and drive accountable decisions without direct organizational authority.

Preferred Qualifications

  • Experience establishing or materially scaling a FedRAMP, product authorization, GRC, security-assessment, or continuous-assurance function.

  • Experience with multiple FedRAMP Moderate or High authorizations, FedRAMP 20x certifications, authorization reuse, or a portfolio of federal cloud services.

  • Experience designing compliance-as-code, automated evidence, persistent validation, Security Decision Records, Key Security Indicators, or machine-readable assurance programs integrated with engineering systems.

  • Experience with OSCAL, GRC platforms, cloud security posture management, infrastructure as code, CI/CD security, security data analytics, or automated control validation.

  • Strong hands-on experience in cloud and platform security across OCI, AWS, Azure, or another hyperscale cloud platform; working familiarity with Kubernetes or container security is highly desirable.

  • Relevant certifications such as CISSP, CCSP, CISM, CRISC, PMP, a cloud security certification, or equivalent demonstrated experience.

  • Experience supporting U.S. federal customers or cloud services subject to federal security, privacy, records-management, or health-data requirements.

Benefits & conditions

US: Hiring Range in USD from: $97,500 to $209,500 per annum. May be eligible for bonus and equity.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.

Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following:

  1. Medical, dental, and vision insurance, including expert medical opinion

  2. Short term disability and long term disability

  3. Life insurance and AD&D

  4. Supplemental life insurance (Employee/Spouse/Child)

  5. Health care and dependent care Flexible Spending Accounts

  6. Pre-tax commuter and parking benefits

  7. 401(k) Savings and Investment Plan with company match

  8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.

  9. 11 paid holidays

  10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.

  11. Paid parental leave

About the company

Only Oracle brings together the data, infrastructure, applications, and expertise to power everything from industry innovations to life-saving care. And with AI embedded across our products and services, we help customers turn that promise into a better future for all. Discover your potential at a company leading the way in AI and cloud solutions that impact billions of lives.

True innovation starts when everyone is empowered to contribute. That’s why we’re committed to growing a workforce that promotes opportunities for all with competitive benefits that support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · World Congress 2025

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

4:04 min

Overview of Kubernetes operators and custom resource definitions

Philipp Krenn · World Congress 2022

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

Videos

See all

Related articles

See all