Lead Principal Security Researcher
Oracle
Position Summary
Responsible for providing independent assurance that a large-scale advertising system that includes ad serving, targeting, bidding, measurement, privacy, and data-handling systems is operating according to documented policies, business rules, contractual obligations, and regulatory requirements.
Key Responsibilities
- Independently validate platform behavior against policies and requirements
- Design and execute processes that provide empirical validation of policies and controls, control testing, and assurance reviews
- Review raw data, logs, metrics, architecture, and operational evidence
- Participate in threat modeling, identify risks, gaps, and control weaknesses
- Support audits, regulatory reviews, and customer assurance requests
- Produce executive-ready assurance reports and remediation recommendations
Minimum Qualifications for this role
- AdTech domain knowledge (SSPs, DSPs, RTB, auctions, attribution, measurement)
- Strong technical background in software engineering, architecture, security, or platform operations
- Strong knowledge of adversarial threat groups, including tactics, techniques, and procedures
- Controls and assurance experience
- Evidence-based validation and testing skills
- Risk assessment and remediation planning experience
- Executive and technical communication skills
Preferred Qualifications for this role
- Working knowledge of privacy frameworks like GDPR
- Data engineering expertise
- Strong problem-solving skills, desire to learn new tools, new areas of expertise
- Security architecture and compliance experience
- Internal audit certifications
- Privacy engineering experience
- Fraud, IVT, and measurement expertise
- Cloud platform expertise