Skip to content

Senior Oracle Database Engineer

  • Remote
    • Plovdiv, Plovdiv, Bulgaria

Job description

Job Description: Senior Oracle Database Security & Hardening Engineer (FedRAMP / IaC)

Position: Senior Oracle Database Security & Hardening Engineer (FedRAMP)

Location: Fully Remote (UK or EU-based, overlapping UK business hours)

Engagement Type: Contract (Initial 6 Months, high likelihood of extension)

Compensation: Competitive daily rate (DOE)

Role Overview

We are seeking a Senior Oracle Database Security Specialist with strong production experience in Terraform and Ansible to join our engineering team.

Our client, an Enterprise SaaS provider, is currently hardening an extensive Oracle 19c estate hosted on Azure to comply with FedRAMP Moderate standards. The current environment includes established DBA and Platform teams, but requires a hands-on engineer to bridge the gap where operating system and database security intersect—ensuring OS hardening, encryption, identity, and compliance changes seamlessly integrate across backup, cloning, and Disaster Recovery (DR) pipelines.

This is a hands-on delivery role embedded within the engineering team. You will actively take tickets, raise merge requests, implement security baselines, and author production Infrastructure as Code (IaC). Architecture-only or pure advisory profiles will not fit this role.

Key Responsibilities

  • Database & OS Hardening: Hardened Oracle 19c databases running on Enterprise Linux (OEL/RHEL 8 & 9) operating in FIPS mode.

  • Identity & Access Management: Implement and maintain Oracle authentication integrated with Azure Entra ID, Privilege Identity Management (PIM), RBAC, and Linux VM SSO.

  • Database Encryption: Configure and manage TCPS (TLS), Transparent Data Encryption (TDE) with external key management (Azure Key Vault / Oracle Wallet), and encrypted RMAN backups.

  • Automation & Infrastructure as Code: Deliver all configuration and security remediation changes via production Terraform and Ansible pipelines (zero manual production changes).

  • Compliance & Remediation: Run DISA STIG and Oracle DB-SAT scans, systematically address vulnerabilities, and determine appropriate remediations or formal exceptions.

  • Backup, Restore & DR: Maintain and validate cross-region encrypted backup and recovery workflows, including key escrow and database cloning with re-keying procedures.

Essential Requirements (Must-Have)

Candidates must demonstrate direct, hands-on delivery across all of the following criteria:

  • Oracle 19c Engineering: 8+ years as a hands-on Oracle DBA / Security Engineer working with Oracle 19c features (roles, fine-grained access control, unified auditing, privilege analysis).

  • Security & Compliance Standards: Hands-on experience delivering DISA STIG (Oracle 19c) and Oracle DB-SAT remediations, including making formal risk-based exception determinations.

  • Regulated Frameworks: Prior delivery experience within FedRAMP, DoD IL, CMMC, or equivalent regulated environments, including producing direct evidence for assessors.

  • Database Encryption: Proven experience with production TDE, Oracle Wallet, TCPS certificate/trust store management, and encrypted RMAN backups using external key stores.

  • Azure Identity & Platform: Strong knowledge of Oracle authentication via Entra ID (Azure AD), Azure Key Vault, Blob Storage, managed disk encryption, and Azure PIM/RBAC.

  • Infrastructure as Code (IaC): Deep fluency with Terraform and Ansible for environment deployment and configuration management strictly via CI/CD pipelines.

  • Linux Security: Experience administering OEL/RHEL 8/9 in FIPS mode, with an understanding of how OS-level hardening impacts Oracle binaries.

  • Cross-Functional Ownership: Demonstrated capability driving technical design and security decisions across DBA, Platform, and DevOps teams without formal line authority.

  • Eligibility & Availability: Based in the UK or EU, able to contract within Europe, and available to start within 4 weeks.

Desirable Qualifications

  • Certifications: Oracle Certified Professional (OCP), Oracle Database Security Specialist, or Azure Security Engineer (AZ-500).

  • Automated Security Pipelines: Experience setting up OpenSCAP in CI/CD pipelines with continuous drift detection.

  • Pipeline Frameworks: Experience with Argo Workflows, Kubernetes-based CI/CD, or Helm charts for connection configurations.

  • Observability & Cryptography: Familiarity with FIPS 140-3 provider changes, Filebeat/Elastic setups on FIPS hosts, or Oracle option licensing exposure (Advanced Security, RAT, OWM).

or