> Markdown version of [/jobs/ext/272842-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/272842-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - **Company:** Hollstadt Consulting - **Location:** United States (Remote available) - **Salary:** $116,792.0 - $129,085.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Application Firewall, Audit Trail, User Authentication, Cloud Computing, Cyber Security, Identity and Access Management, Internet Security, Key Management, Network Security, Local Security Policy, Oracle (Applications), Platform as a Service (PAAS), Role-Based Access Control, Cloud Services, Security Information and Event Management, Oracle Fusion Middleware, System Integration Testing, Data Logging, Machine Learning Operations, Oracle Ebusiness, CIS Benchmarks, Api Gateway, Firewall Services Module, Elastic Beanstalk, Oracle Integration, Oracle Cloud Infrastructure, Web Api - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3c7a2e6135c5eda7 ## About the Role Do you have experience in WAF? ## Description The client is seeking an Information Security Engineer with Oracle security expertise to implement, configure, and operationalize security controls for the migration from Oracle E-Business Suite (EBS) to Oracle Fusion Cloud, supported by Oracle Cloud Infrastructure (OCI) and PaaS services such as Oracle Integration Cloud (OIC) and Visual Builder Cloud Service (VBCS). This role is responsible for executing and validating security implementations across Oracle platforms, including RBAC configuration, Segregation of Duties (SoD) enforcement, system hardening, identity integration (SSO/MFA), and monitoring. The Engineer works closely with architects, implementation partners, and business teams to ensure controls are deployed correctly, tested thoroughly, and audit-ready at go-live and beyond., 1) Security Implementation & Configuration * Implement security controls across Oracle Fusion, OCI, and PaaS (OIC, VBCS) environments. * Configure: + Fusion roles, privileges, and data security policies + OCI IAM users, groups, compartments, and policies + PaaS security settings and service configurations * Translate architectural designs into working, enforceable controls. * Troubleshoot and resolve security configuration issues and defects during build and testing. 2) Access Model Deployment (RBAC / SoD / SA) * Execute and configure: + RBAC models aligned to job roles and least privilege + SoD and Sensitive Access (SA) rules within Oracle and supporting tools * Support and facilitate: + Role build, configuration, and iterative refinement + System Integration Testing (SIT) and User Acceptance Testing (UAT) * Perform: + Access validation and conflict testing (positive/negative scenarios) + Remediation of SoD conflicts in coordination with business owners * Assist in maintaining accurate and audit-ready role and access documentation. 3) Automated Controls Implementation & Testing * Configure automated business process controls (ABPC) within Oracle Fusion. * Execute: + Control testing and validation of effectiveness + Audit policy configuration for high-risk transactions * Implement compensating controls where automation is not feasible: + Document procedures and evidence requirements + Support control owners in execution and validation 4) Identity Integration (SSO / MFA) Implementation * Configure and validate identity integration across: + Oracle Fusion + OCI and OIC * Implement: + Federation with enterprise identity provider + SSO and MFA enforcement policies + Conditional access and session controls * Configure and test: + Break-glass/emergency access accounts + Authentication logging and traceability * Support end-to-end identity testing across environments. 5) OCI & PaaS Security Hardening * Implement OCI security configurations, including: + IAM policies, dynamic groups, and least-privilege access + Environment segregation (Dev/Test/Pre-Prod/Prod) * Configure network security controls: + Security lists, private endpoints, service gateways + Firewall rules and egress restrictions * Deploy and tune: + OCI Web Application Firewall (WAF) * Implement platform hardening: + CIS-aligned configurations + Vault/key management and secrets protection + Secure object storage settings * Enable logging and monitoring: + OCI audit logs, WAF logs, and service telemetry + Integration with enterprise SIEM and alerting pipelines 6) Integration Security Implementation (OIC & Third-Party) * Configure security for integrations across OIC, Fusion, OCI, and external systems. * Implement: + API authentication and authorization mechanisms + Secure credential storage (vaults/secrets management) + Encryption of data in transit and message integrity controls * Enforce: + Least-privilege access for integration accounts + Separation of duties across service accounts * Configure: + Secure endpoints (private endpoints, API gateways where applicable) * Enable monitoring: + Logging of API calls and integration events + SIEM ingestion and alerting for anomalies * Maintain integration security documentation and evidence artifacts. 7) Testing & Validation * Execute security testing across all environments, including: + Access validation and role-based testing + SoD conflict validation + Control effectiveness testing * Identify and remediate: + Security defects, misconfigurations, and control gaps Performance expectations: Success Measures * Security controls successfully implemented and functioning across Oracle environments * RBAC and SoD models enforced with minimal access defects in testing and production * SSO/MFA fully operational across Fusion, OCI, OIC, and VBCS * OCI and PaaS environments hardened and aligned to security baselines * Automated and manual controls tested, evidenced, and audit-ready * Security issues identified and resolved early through testing cycles ## Related Videos - [Web APIs you might not know about](https://www.wearedevelopers.com/videos/281-web-apis-you-might-not-know-about) - [20 billion requests a week: Upgrading Twilio's API gateway at scale](https://www.wearedevelopers.com/videos/100234-20-billion-requests-a-week-upgrading-twilio-s-api-gateway-at-scale) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Project Fugu: Extending the web](https://www.wearedevelopers.com/videos/832-project-fugu-extending-the-web) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)