Lead Principal Security Researcher

Oracle

Position Summary

Responsible for providing independent assurance that a large-scale advertising system that includes ad serving, targeting, bidding, measurement, privacy, and data-handling systems is operating according to documented policies, business rules, contractual obligations, and regulatory requirements.

Key Responsibilities

  • Independently validate platform behavior against policies and requirements
  • Design and execute processes that provide empirical validation of policies and controls, control testing, and assurance reviews
  • Review raw data, logs, metrics, architecture, and operational evidence
  • Participate in threat modeling, identify risks, gaps, and control weaknesses
  • Support audits, regulatory reviews, and customer assurance requests
  • Produce executive-ready assurance reports and remediation recommendations

Minimum Qualifications for this role

  • AdTech domain knowledge (SSPs, DSPs, RTB, auctions, attribution, measurement)
  • Strong technical background in software engineering, architecture, security, or platform operations
  • Strong knowledge of adversarial threat groups, including tactics, techniques, and procedures
  • Controls and assurance experience
  • Evidence-based validation and testing skills
  • Risk assessment and remediation planning experience
  • Executive and technical communication skills

Preferred Qualifications for this role

  • Working knowledge of privacy frameworks like GDPR
  • Data engineering expertise
  • Strong problem-solving skills, desire to learn new tools, new areas of expertise
  • Security architecture and compliance experience
  • Internal audit certifications
  • Privacy engineering experience
  • Fraud, IVT, and measurement expertise
  • Cloud platform expertise