Massachusetts Veterans Jobs

MassHire JobQuest Logo

Job Information

Oracle Principal Program Manager in Boston, Massachusetts

Job Description

We are seeking a results-driven Principal Program Manager to lead and elevate our Oracle Health Release Management function. This strategic role involves orchestrating end-to-end processes to reduce critical vulnerabilities, oversee OWASP 3rd-party dependency checks, manage SAST (Static Application Security Testing) findings, and address container security vulnerabilities.

As the driving force behind our application security efforts, you will work closely with development, DevOps, and cybersecurity teams to ensure secure releases and mitigate risks effectively. This is an excellent opportunity to blend your technical expertise and program management skills to make a tangible impact on Oracle Health application security.

Key Responsibilities

Technical and Program Leadership

  • Develop and manage the overall program for application security release management, aligning with organizational objectives and security standards.

  • Establish, monitor, and refine KPIs to measure progress in vulnerability reduction and secure software delivery.

  • Lead cross-functional efforts to streamline and integrate security checks into CI/CD pipelines, enabling secure and timely releases.

Vulnerability Management and Mitigation

  • Drive the resolution of all critical vulnerabilities, prioritizing based on business impact and risk exposure.

  • Ensure adherence to security best practices and addressing supply chain risks.

  • Manage security findings and container vulnerability remediation efforts, partnering with development and DevOps teams.

Stakeholder Collaboration

  • Act as the primary interface between application security, development, DevOps, and business teams to align release goals with security requirements.

  • Foster strong communication and accountability by leading regular status updates, meetings, and executive reporting.

  • Advocate for security by design, integrating it into software development lifecycles (SDLC).

  • Lead product Security Champions to scale reviews and ensure compliance

Risk Reduction and Governance

  • Establish governance frameworks to track and report on remediation progress, ensuring compliance with internal and external standards.

  • Collaborate with audit and compliance teams to address regulatory requirements and maintain audit readiness.

  • Escalate unmitigated risks appropriately and propose compensating controls where immediate fixes are not feasible following OHSC exception process.

Continuous Improvement

  • Identify process inefficiencies and lead initiatives to enhance vulnerability management workflows.

  • Stay informed on emerging threats, application security trends, and tools to recommend improvements to the program.

  • Champion a culture of continuous improvement by driving training and awareness programs for development teams.

Required Qualifications

  • Education: Degree in Computer Science, Cybersecurity, Information Technology, or a related field. Advanced degrees are a plus.

  • Experience:

  • 15+ years of experience in cybersecurity, application security, or DevSecOps, with at least 3 years in a program or project management role.

  • Proven expertise in managing remediation of critical vulnerabilities, dependency checks, SAST, DAST findings, and container vulnerabilities.

  • Deep understanding of application security frameworks, tools, and standards (e.g., OWASP Top 10, NIST, ISO 27001).

  • Certifications:

  • Relevant certifications such as SANS, CISSP, CSSLP, or PMP are highly desirable.

Desired Skills

  • Strong knowledge of modern development practices, including Agile, DevOps, and CI/CD pipelines.

  • Hands-on experience with security tools such as Veracode, Checkmarx, SonarQube, Black Duck, Snyk, or similar.

  • Excellent communication and interpersonal skills for engaging technical and non-technical stakeholders.

  • Experience in container orchestration and security, including Kubernetes and Docker.

  • Ability to balance strategic thinking with tactical execution.

  • Navigate ambiguity, change and shifting priorities

If you are passionate about building secure applications and have a proven track record of driving impactful remediation programs, we want to hear from you. Apply now and help shape the future of Oracle Health application security initiatives.

Career Level - IC5

Responsibilities

Technical and Program Leadership

  • Develop and manage the overall program for application security release management, aligning with organizational objectives and security standards.

  • Establish, monitor, and refine KPIs to measure progress in vulnerability reduction and secure software delivery.

  • Lead cross-functional efforts to streamline and integrate security checks into CI/CD pipelines, enabling secure and timely releases.

Vulnerability Management and Mitigation

  • Drive the resolution of all critical vulnerabilities, prioritizing based on business impact and risk exposure.

  • Ensure adherence to security best practices and addressing supply chain risks.

  • Manage security findings and container vulnerability remediation efforts, partnering with development and DevOps teams.

Stakeholder Collaboration

  • Act as the primary interface between application security, development, DevOps, and business teams to align release goals with security requirements.

  • Foster strong communication and accountability by leading regular status updates, meetings, and executive reporting.

  • Advocate for security by design, integrating it into software development lifecycles (SDLC).

  • Lead product Security Champions to scale reviews and ensure compliance

Risk Reduction and Governance

  • Establish governance frameworks to track and report on remediation progress, ensuring compliance with internal and external standards.

  • Collaborate with audit and compliance teams to address regulatory requirements and maintain audit readiness.

  • Escalate unmitigated risks appropriately and propose compensating controls where immediate fixes are not feasible following OHSC exception process.

Continuous Improvement

  • Identify process inefficiencies and lead initiatives to enhance vulnerability management workflows.

  • Stay informed on emerging threats, application security trends, and tools to recommend improvements to the program.

  • Champion a culture of continuous improvement by driving training and awareness programs for development teams.

Disclaimer:

Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.

Range and benefit information provided in this posting are specific to the stated locations only

US: Hiring Range in USD from: $109,200 to $223,400 per annum. May be eligible for bonus and equity.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.

Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following:

  1. Medical, dental, and vision insurance, including expert medical opinion

  2. Short term disability and long term disability

  3. Life insurance and AD&D

  4. Supplemental life insurance (Employee/Spouse/Child)

  5. Health care and dependent care Flexible Spending Accounts

  6. Pre-tax commuter and parking benefits

  7. 401(k) Savings and Investment Plan with company match

  8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.

  9. 11 paid holidays

  10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.

  11. Paid parental leave

  12. Adoption assistance

  13. Employee Stock Purchase Plan

  14. Financial planning and group legal

  15. Voluntary benefits including auto, homeowner and pet insurance

The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.

About Us

As a world leader in cloud solutions, Oracle uses tomorrow’s technology to tackle today’s problems. True innovation starts with diverse perspectives and various abilities and backgrounds.

When everyone’s voice is heard, we’re inspired to go beyond what’s been done before. It’s why we’re committed to expanding our inclusive workforce that promotes diverse insights and perspectives.

We’ve partnered with industry-leaders in almost every sector—and continue to thrive after 40+ years of change by operating with integrity.

Oracle careers open the door to global opportunities where work-life balance flourishes. We offer a highly competitive suite of employee benefits designed on the principles of parity and consistency. We put our people first with flexible medical, life insurance and retirement options. We also encourage employees to give back to their communities through our volunteer programs.

We’re committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by calling +1 888 404 2494, option one.

Disclaimer:

Oracle is an Equal Employment Opportunity Employer*. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

* Which includes being a United States Affirmative Action Employer

DirectEmployers