What are the responsibilities and job description for the Third-Party Incident Management Lead position at Oracle and Careers?
The Third-Party Incident Management Lead is responsible for coordinating Oracle’s response to cybersecurity incidents involving third-party partners and suppliers. This role ensures that incidents are logged, assessed, escalated, managed, and closed in a manner that protects Oracle’s assets, meets contractual and regulatory obligations, and drives continual improvement in Third-Party Risk Management (TPRM) practices.
1. Third-Party Breach Management
- Acknowledge and log breach notifications received from Third-Parties.
- Perform criticality and risk assessments based on breach information and third-party profiles.
- Coordinate information gathering from impacted Third-Parties.
- Activate and manage internal incident response processes when Oracle data, services, or assets may be affected.
2. Incident Coordination and Stakeholder Management
- Serve as the central point of coordination across GIS, Legal, Privacy, Corporate Communications, and affected LoBs.
- Facilitate joint response calls, action tracking, and unified decision-making across business areas.
- Prepare and distribute timely and consistent communications to executive leadership and key stakeholders.
3. Regulatory and Contractual Compliance
- Assess whether the Third-Party has met its contractual obligations to Oracle regarding breach notification, remediation efforts, and information sharing.
- Review breach response activities against the terms outlined in the vendor’s contract, including timelines for notification, disclosure requirements, and security obligations.
- Collaborate with Legal and Procurement teams to evaluate if any failures to meet obligations require escalation, remediation demands, or contractual enforcement actions.
- Ensure that all third-party responses are documented thoroughly to demonstrate compliance (or non-compliance) with Oracle’s legal, regulatory, and contractual standards.
- Support preparation of customer or regulator disclosures if a Third-Party’s failure impacts Oracle’s compliance obligations.
4. Response Procedure Execution
- Manage processes including:
- Monitoring and detection of threats.
- Dissemination of Indicators of Compromise (IOCs) and threat intelligence.
- Access revocation and system isolation when needed.
- Deployment of temporary security controls to contain or mitigate threats.
- Oversight of SSO integration responses and API-related risk mitigations.
5. Remediation Monitoring and Post-Incident Analysis
- Track and validate Third-Party remediation efforts.
- Lead post-incident reviews to capture lessons learned.
- Recommend updates to playbooks, TPRM processes, and vendor engagement strategies based on incident outcomes.
#LI-LD1