Senior Director of Security Trust, Strategy and Response

New Today

Title:  Sr. Director of Security Trust, Strategy, and Response
Reporting To:  Chief Information Security Officer (CISO)
Role Overview:
As Sr. Director of Security Trust, Strategy, and Response, you are responsible for advancing Oracle’s enterprise security maturity across customer trust, industry engagement, incident response, and regulatory obligations. You will lead the Integrated Cyber Center — Oracle’s security coordination hub — and oversees global functions that directly impact how Oracle protects, responds, and communicates across lines of business.
You are the connective tissue between security operations, executive leadership, and customer trust. This role drives forward-looking security strategy, ensures operational integration, and represents Oracle’s cybersecurity commitments externally.
Key Responsibilities:
Strategic Security Leadership Shape and execute Oracle’s cross-enterprise cybersecurity strategy in alignment with the CISO and executive leadership. Lead the Cyber Integration Center as the operational and strategic hub for security incident coordination, customer engagement, and security communications. Serve as a senior representative to customers, industry bodies, and regulators on matters of Oracle’s security strategy, posture, and obligations. Customer & Industry Engagement Lead the Global Cybersecurity Lead team responsible for translating customer and industry needs into Oracle’s security programs, messaging, and roadmap. Oversee security messaging, customer advisory boards, and Oracle’s voice in industry security conversations and regulatory landscapes. Incident & Crisis Management Own Oracle’s enterprise incident response and crisis management process across business units, including executive communication and external coordination. Lead major event orchestration with clear escalation paths, playbooks, and real-time executive engagement. Trust Management Oversee the Trust Center, customer-facing security documentation, and governance around legal commitments and disclosures. Partner with legal, risk, and compliance functions to proactively manage Oracle’s transparency practices. Qualifications: 15+ years in cybersecurity, including executive-level leadership in strategy, operations, or trust functions. Proven experience leading multidisciplinary security teams in complex, global enterprises. Exceptional communication and executive presence, with experience briefing C-suite and board-level stakeholders. Deep understanding of industry regulations (., NIST, GDPR, HIPAA, FedRAMP) and customer security expectations. Bachelor’s degree required; advanced degree and certifications (., CISSP, CISM, CISA) preferred. Manages teams that maintain and/or implement information security policies and procedures. Manages the development, deployment and execution of controls and defenses to ensure the security and risk mitigation of company infrastructure technology and information systems. Identifies security architecture, goals, objectives and metrics; analyzes business needs and priorities for protection of critical systems. Build next-generation security programs and assurance, . threat and vulnerabilities management, incident response management, management of forensic investigations. Evaluates potential business impacts from security breaches and provides strategic and tactical guidance to business decision-makers. Develops and executes security systems compliance policies and procedures. Selects, develops and evaluates personnel to ensure the efficient operation of the function.
Minimum 12 years experience in the Information Security field required. Preferred but not required qualifications include: BS or MS in Computer Science, Computer Security or Computer Engineering. 8 or more years of successful management experience including 2 or more years as a second level manager. Led or participated in corporate intellectual property management program as a committee member. Contributed in 2 or more industry papers, projects, standards, etc. Recognized industry speaker at 3 or more public events historically.
Location:
Us