Qureos

FIND_THE_RIGHTJOB.

Technical Program Manager

JOB_REQUIREMENTS

Hires in

Not specified

Employment Type

Not specified

Company Location

Not specified

Salary

Not specified

We are seeking a Technical Program Manager to lead integrated change governance and incident response for GPS technologies and operations. You will balance speed with control—switching seamlessly between crisis leadership and disciplined governance—to protect the availability, safety, and privacy of security systems across Oracle offices, data centers, and regional operations. The role spans risk-based decisioning, stakeholder communication, CAB facilitation, war-room leadership, automation of low-risk workflows, and data-driven continuous improvement.

About the team

  • Oracle’s Global Physical Security (GPS) team protects our people, facilities, data centers, and our customer operations worldwide. We design and operate resilient, scalable, and privacy-aware physical security solutions in close partnership with Real Estate & Facilities, Oracle Cloud Infrastructure, Data Center Engineering, Legal/Privacy, Procurement, and Regional Security Operations.


  • Daily Responsibilities
    • Lead incident triage, severity assignment, war-room facilitation, and time-boxed decision making; coordinate workarounds/rollbacks and guide post-incident reviews with clear actions and owners.
    • Manage the end-to-end change lifecycle: RFC quality checks, risk assessments, scheduling, validation, and enforcement of change freezes/blackouts for high-risk periods.
    • Provide clear, concise updates to executives, operations teams, and engineers; establish and maintain a single source of truth for status, timelines, and next steps.
    • Apply risk-based decisioning tailored to business impact, asset criticality, exposure, and blast radius.
    • Maintain audit-ready evidence and artifacts (incident timelines, approvals, tickets, test results, and exceptions).
  • Project Participation
    • Embed incident-readiness and change-governance requirements into site builds, data center expansions, retrofits, and technology upgrades for access control, VMS, SOC platforms, and security networks.
    • Champion pre-change testing strategies (lab validation, canary/gradual rollouts, rollback plans).
    • Coordinate cross-functional readiness (runbooks, spares, monitoring, alerting, on-call coverage) prior to go-live.
  • Governance, risk, and compliance
    • Operate within Oracle policies and align to frameworks such as ISO 27001/22301 and NIST; ensure segregation of duties, approvals, and traceability.
    • Define severity, priority, and risk criteria; manage change and emergency change processes; document exceptions and risk acceptances.
    • Partner with Legal/Privacy to ensure changes and incident handling respect privacy-by-design principles for video, access logs, and visitor data.
  • Operations enablement
    • Standardize incident runbooks and communications templates; automate approvals for low-risk standard changes to reduce toil and cycle time.
    • Build dashboards and metrics to spot trends, bottlenecks, and systemic risks; drive corrective actions and problem management.
    • Coach regional teams in mode-switching between crisis response and governance discipline; support knowledge base and SOP development.
  • Technology evaluation
    • Assess and tune ITSM, monitoring/observability, on-call/paging, and collaboration tools for reliability, signal quality, and secure data handling.
    • Evaluate integrations and automations (APIs, webhooks) that streamline RFC intake, risk scoring, owner routing, and verification.
    • Ensure telemetry and logging support rapid incident detection and post-incident analysis while meeting privacy and retention requirements.
    • When recommending third-party tools, verify alignment with Oracle’s security, privacy, and procurement guidelines.
  • Stakeholder engagement
    • Influence without authority across GPS, OCI, Data Center Engineering, Regional Security Operations, IT/Network, vendors/integrators, and compliance teams.
    • Facilitate clear decision-making among diverse stakeholders; escalate effectively and ensure roles and responsibilities are understood.
    • Communicate status and risk in business terms to leadership and operational teams.

Minimum Qualifications

  • 5+ years in change, incident, or service management roles within large, complex, or 24x7 environments.
  • Solid grasp of infrastructure, networks, operating systems, cloud (IaaS/PaaS/SaaS), containers/K8s, and application stacks sufficient to challenge plans and validate risk.
  • Demonstrated experience running war rooms, conducting post-incident reviews, and managing change processes.
  • Proven ability to apply risk-based decisioning and tailor responses to business impact and criticality.
  • Strong written and verbal communication; executive-ready status reporting and stakeholder management.
  • Experience with ITSM platforms, monitoring/observability, and on-call/paging tools; evidence and audit discipline.

Preferred Qualifications

  • Certifications: ITIL, PMP, CISM, or equivalent.
  • Experience in physical security ecosystems (access control, VMS, SOC platforms, badge/visitor systems) and converged cyber-physical environments.
  • Background in problem management, resilience engineering, and business continuity.
  • Familiarity with change risk models, error budgets/SLOs, and automated change gating.

Key Competencies

  • Balance speed with control; switch seamlessly between crisis leadership and governance discipline.
  • Clear, concise communicator to executives, customers, and engineers; establishes a single source of truth.
  • Mastery of incident management (triage, severity, war-room, workaround/rollback, PIRs) and change management (RFC quality, risk assessment, CAB, scheduling, validation, freeze/blackout).
  • Data-driven; leverages dashboards to identify trends and systemic risks.
  • Makes time-boxed decisions; conducts retrospectives and drives learning.
  • Empathy and resilience; supports team well-being during sustained on-call periods; strong collaboration across global teams.

Work Model and Travel

Strong ability to work independently and with teams across global time zones.

Notes

  • Adherence to Oracle’s security, privacy, and compliance standards is mandatory.
  • When proposing or integrating third-party tools or services, ensure alignment with Oracle’s internal security, privacy, and procurement guidelines.

© 2025 Qureos. All rights reserved.