Principal Regulatory Compliance Specialist (m/f/*) (IC3/IC4)
OracleGermany-berlinUpdate time: January 18,2023
Job Description

This role is being sought at IC4 (Principal) grade although it is possible we may also hire at IC3 (senior grade)

Come join the fastest growing Cloud organization with world-class engineering and laser focus on excellence. Oracle’s extensive enterprise customer base is looking for rock-solid cloud solutions that provide the same reliability and effectiveness that they have come to expect from Oracle. Oracle Cloud Infrastructure (OCI) provides highly cost effective and high-performance IaaS & PaaS Cloud solutions to its customer and they come to expect industry-leading security and compliance programs, creating a stable and highly effective foundation for their workloads and an infrastructure that meets their security and compliance needs.

We are looking for a Principal Regulatory Compliance Specialist who is looking to grow their career in Cloud. You will be responsible for the support and implementation of scalable audit programs to support Oracle Cloud Infrastructure’s growth in regulated markets within the European Union region.

 

Functions include:

• Plan, manage, lead, and execute multiple audit programs within OCI with third-party auditors

• Evaluate the effectiveness of controls and corresponding evidence in alignment with audit framework requirements

• Provide high quality, professional day-to-day execution of audit engagements

• Conduct interactions with third party auditors that exhibit control understanding and confidence

• Effectively communicate audit engagement status to executive leadership

• Ability to communicate in remote working environments over video, phone, email, and other tools

• Provide clear expectations and direction to security and engineering teams within OCI on audit requirements

• Review audit evidence from the businesses within OCI and analyze for auditor consumption

• Communicate within the team autonomously and drive communication across partner teams

• Drive project scheduling, tracking, and communications up to the Director level independently

• Build, manage, and enhance the efficiency of audit programs as the business scales

• Collaborate with subject matter experts to refine operating processes to increase the value and scale of our audit programs and decrease the operational impact to OCI

 

 

The ideal candidate will have the following skills:

 

• 8+ years auditing experience

• 4+ years of above experience in the IT or Cloud industry is preferred

• Knowledge of industry and regulatory frameworks is preferable, such as, Cyber Essentials, ENS, IT Health Checks, IT-Grundschutz, ISO Series, EU CoC, TISAX

• Demonstrates ability to identify problem areas in a program and build projects to correct, enhance, reduce the impact of those issues

• Proven ability to combine business acumen, technical acumen and process expertise to define client (internal/external) engagement and program execution

• Proven ability to influence & gain buy-in at multiple levels, across divisions, functions and cultures; comfort working with executive level management

• Possess ability to explain complex auditing topics to audiences with no auditing experience

• Ability to prioritize, manage, and deliver on multiple projects simultaneously and partner with management in support of key initiatives and projects

• Bachelor’s degree or equivalent experience

PMP, PgMP, CISA, CISM, CISSP, CIPP, desirable but not essential

Assists and supports the organization in complying with, as well as the ongoing preparation, testing and monitoring of conformance to, the requirements of government regulations and/or regulatory agencies.

Performs evaluation of internal operations, controls, communications, risk assessments and maintenance of documentation as related to regulatory compliance and recommends appropriate changes. Conducts and facilitates internal and external audits to identify, evaluate, disclose and appropriately remedy risks and deficiencies. Coordinates the preparation of and may prepare document packages for regulatory submissions from all areas of company as well as for internal and external audits and inspections. May serve as point of contact for interactions with regulatory agencies for defined matters. Support the creation of a comprehensive risk management and regulatory oversight program, including specifications for product and service design aligned with Oracle Software Security Assurance and Security Architecture. Review specifications. Develop training for GBU development, cloud services, services and operations teams on industry regulatory specifications applicable to their products and services. Execute risk assessments and evaluate risks to the business and develop risk mitigation strategies. Work with members of GBU development, cloud services, services and operations teams to incorporate applicable industry regulatory standards, Oracle security policies and customer-contractual obligations into GBU processes and standards. Coordinate industry and regulatory certifications, including managing certification vendors (e.g., PCI, HIPAA,HITECH, ISO, SOC2). Build security documentation and collateral for customers and internal users allowing security to be a differentiator in this GBUs. Build management level metrics and reporting for activities that are owned by the Risk Manager. Execute a vendor security program.

Leading contributor individually and as a team member, providing direction and mentoring to others. Work is non-routine and very complex, involving the application of advanced technical/business skills in area of specialization. . Ability to travel. 8 plus years experience. BA/BS or advanced degree preferred. 5-7 years work in governance and compliance for a large corporation. CISA, CISM, CISSP, CIPP desired. Strong knowledge of IT auditing and controls, preferable with SOX, SSAE 16 - SOC 1 & SOC 2, PCI compliance, NIST, DIACAP, FedRAMP, ISO 27001 & ISO 27002. Experience with 21 CFR Part 11 and HIPAA. Knowledge and understanding of the delivery process for validated systems; specifically Computer System Validation process or CSV. Have an understanding of security standards and risk management. Experience working in Information Technology, Cloud or managed hosting services. Excellent written and verbal communication skills. Ability to adjust and adapt to changing priorities in a dynamic environment. Technical acumen and the ability to understand and interpret technical specifications. Technical knowledge of Oracle Applications and Database and/or infrastructure components. Project Management skills.

As part of Oracle's employment process candidates will be required to successfully complete a pre-employment screening process. This will involve identity and employment verification, professional references, education verification and professional qualifications and memberships (if applicable).

Get email alerts for the latest"Principal Regulatory Compliance Specialist (m/f/*) (IC3/IC4) jobs in Germany-berlin"