Skip to Main Content

Job Title


Senior Principal Offensive Security Researcher


Company : Oracle


Location : Reading, South East


Created : 2025-06-19


Job Type : Full Time


Job Description

As a member of our technical leadership team, you will be responsible for leading the planning and delivery of in-depth security assessments across a variety of products and services, you will author reports and be the owner from cradle to grave while presenting to executive leadership your findings and taking ownership of your teams work. Your next project could be anything from secure systems design, static and dynamic analysis of a multi-node Java infrastructure, to writing a fuzzer for an undocumented network protocol or the grammar of a new programming language, to analysis and reverse engineering of firmware used in the thousands of servers supporting our cloud services. Other responsibilities include:Apply below after reading through all the details and supporting information regarding this job opportunity.Designing and evaluating complex systems for computer securityScope and execute security assessments and vulnerability researchPerform in-depth security assessments using results from static and dynamic analysisCreate testing tools to help engineering teams identify security-related weaknessesCollaborate with engineering teams to help them triage and fix security issuesMentor members of the team in computer and software security as a role model and team leaderCareer Level - IC5What Youll BringBachelors or Masters degree in Computer Science or related field (e.g. Electrical Engineering)15+ years of relevant experience in one or more of the following areas: software/product security assessments, penetration testing, red teaming, web application assessmentsInterest in vulnerability research and exploit development leading groups of 5 -10 engineers past experience requiredUnderstanding of operating systems, CPU instruction sets and their associated security designsUnderstanding of exploit mitigations (DEP, ASLR, CFG, PAC, CET, etc.)Demonstrable experience in designing and evaluating complex systems for securityAptitude for self-study, setting and achieving long term goals (for example, learning an unfamiliar programming language)Ability to effectively assess and communicate risks and appropriate levels of urgency to management and engineering staffExcellent organizational, presentation, verbal, and written communication skills as mentioned before you will be the leader of a team and be presenting your findings and reports while authoring large bodies of evidence strong writing skills are requiredNice to HaveExperience working in a large cloud or Internet software companyProficiency with multiple programming languages, preferably Go, Java, Python or C/C++Ability to perform manual source code reviews in one of the aforementioned languages, or assisted review with code analysis tools such as CodeQLExperience navigating and working with extremely large codebases is also highly desirableExperience using common security assessment tools and techniques in one or more the following categories:Mobile Application Assessment (iOS / Android)Reverse Engineering (e.g. IDA Pro/Ghidra/Frida)Fuzzing (e.g. Jazzer/AFL/Peach)Web Application assessment (e.g. Burp Suite Proxy, ZAP, REST API testing)Proven experience with security research including any published CVEsExperience developing proof of concept exploits bypassing modern exploit mitigationsActive participant or organiser of Capture The Flag competitionsKnowledge of common vulnerabilities in different types of software and programming languages, including:How to test for/exploit themReal world mitigations that can be appliedFamiliarity with vulnerability classification frameworks (e.g. OWASP Top 10, CVSS, MITRE CVE)What Well Give YouA team of very skilled and diverse personnel across the globeAbility to work in a hybrid work environmentExposure to mind blowing large-scale cutting-edge systemsThe resources of a large, global operation while still having the small, start-up feel of a smaller team day to dayDevelop new skills and competencies working with our vast cloud product offeringsOngoing extensive training and skills development to further your career aspirationsIncredible benefits and company perksAn organization filled with smart, enthusiastic, and motivated colleaguesThe opportunity to impact and improve our systems and delight our customers