
Software Developer 4
Oracle · United States
- Hybrid
- Full-time
- $234,600 / year
- United States
Job highlights
- Lead WAF platform development and scaling.
- Design highly available cloud-scale security services.
- Drive distributed systems architecture for security features.
- Partner with cross-functional teams on technical vision.
- Mentor engineers and influence technical strategy.
About the role
Principal Software Engineer - OCI Edge Security
Join OCI’s Edge Security team as a Principal Software Engineer focused on building and scaling Oracle Cloud Infrastructure’s Web Application Firewall (WAF) platform. You will lead the design and development of highly available, cloud-scale services that protect customer applications from web-based threats, automate security enforcement, and deliver advanced traffic inspection and policy management capabilities across OCI’s global infrastructure.
In this role, you will drive the architecture of distributed systems that power WAF features such as threat detection, rule evaluation, bot mitigation, API protection, and security analytics. You will partner closely with security engineers, product managers, and platform teams to deliver secure, performant, and reliable services while helping define the long-term technical vision for OCI’s application security portfolio.
What You'll Do
- Lead the architecture and delivery of cloud-scale backend services that power OCI's Web Application Firewall (WAF) platform.
- Design and evolve highly available policy management, rule evaluation, traffic inspection, bot mitigation, API protection, and security analytics services.
- Build scalable distributed systems that process and analyze high volumes of HTTP/HTTPS traffic while maintaining low latency and high reliability.
- Drive engineering excellence through software architecture reviews, design documentation, code quality standards, and operational best practices.
- Partner closely with Security Engineering, Product Management, SRE, and OCI platform teams to define and deliver next-generation application security capabilities.
- Establish robust observability through metrics, logging, tracing, alerting, and performance monitoring to ensure service health and customer visibility.
- Lead automation initiatives across the software development lifecycle, including CI/CD, testing frameworks, deployment automation, and Infrastructure-as-Code.
- Drive reliability, scalability, and operational readiness through capacity planning, incident response, root cause analysis, and continuous improvement.
- Mentor engineers, influence technical strategy across organizations, and help raise the engineering bar through design reviews and technical leadership.
Qualifications
- 7–10+ years building production software systems, including experience developing large-scale distributed services in cloud or SaaS environments.
- Strong proficiency in one or more of the following languages: Java, Go, Python, C++, or Rust.
- Deep expertise in distributed systems design, including scalability, resiliency, concurrency, fault tolerance, service communication, and API design.
- Strong understanding of HTTP/HTTPS, REST APIs, TLS, reverse proxies, caching, load balancing, and web application architectures.
- Experience building customer-facing platform services with strict requirements around availability, performance, and operational excellence.
- Proven experience with cloud-native technologies, including containers, Kubernetes, CI/CD pipelines, Infrastructure-as-Code, and automated testing frameworks.
- Strong software engineering fundamentals, including design patterns, performance optimization, code quality, and secure software development practices.
- Experience building observability solutions using metrics, distributed tracing, centralized logging, dashboards, and alerting systems.
- Demonstrated ability to lead complex technical initiatives and influence architecture decisions across multiple engineering teams.
- Excellent communication and collaboration skills with a track record of working effectively across engineering, security, product, and operations organizations.
Preferred Qualifications
- Experience building or operating Web Application Firewall (WAF), API Security, Bot Management, CDN, Edge Computing, or related security products.
- Knowledge of common web application attack vectors, including OWASP Top 10 vulnerabilities, credential abuse, automated attacks, and API threats.
- Experience with rule engines, policy evaluation systems, threat detection platforms, or traffic inspection technologies.
- Background building high-throughput analytics, telemetry, or event-processing pipelines for real-time security insights.
- Experience operating globally distributed services across multiple regions and availability domains.
- Familiarity with modern security architectures, Zero Trust principles, identity and access management, and secure service-to-service communication.
- Experience with compliance, audit readiness, and security-by-design development practices.
- Contributions to open-source software, security tooling, or cloud infrastructure projects are a plus.
How You'll Have Impact
- Deliver core WAF capabilities that protect OCI customers from application-layer attacks while maintaining performance and availability.
- Launch customer-facing security features that provide visibility, protection, automation, and policy control at cloud scale.
- Improve the scalability, reliability, and operational maturity of OCI's application security platform.
- Raise engineering quality and technical standards through mentorship, architectural leadership, and continuous improvement initiatives.
Ways of Working
- Security, privacy, and reliability by design with secure development practices embedded throughout the software lifecycle.
- Data-driven decision making supported by clear metrics, SLOs, operational reviews, and measurable customer outcomes.
- Collaborative engineering culture focused on design reviews, code reviews, technical excellence, knowledge sharing, and continuous learning.
Responsibilities
- Lead the architecture and delivery of cloud-scale backend services that power OCI's Web Application Firewall (WAF), API Security, and application protection capabilities.
- Design and evolve scalable policy management, rule evaluation, threat detection, bot mitigation, traffic inspection, and security analytics platforms with a focus on reliability, performance, and extensibility.
- Build highly available distributed systems that inspect and process large volumes of HTTP/HTTPS traffic while maintaining low latency and a seamless customer experience.
- Drive the technical strategy for application security services, partnering with Security Engineering, Product Management, Edge Infrastructure, and Platform teams to deliver new capabilities.
- Establish operational excellence through SLOs/SLAs, incident response processes, runbooks, root cause analysis, and continuous service improvement.
- Lead automation initiatives across the software development lifecycle, including CI/CD pipelines, testing frameworks, deployment automation, Infrastructure-as-Code, and developer productivity tooling.
Key skills/competency
- Principal Software Engineer
- OCI Edge Security
- Web Application Firewall (WAF)
- Cloud-Scale Services
- Distributed Systems
- API Security
- Threat Detection
- Rule Evaluation
- Bot Mitigation
- Security Analytics
Skills & topics
- Principal Software Engineer
- Software Engineering
- Cloud Security
- Web Application Firewall
- WAF
- OCI
- Edge Security
- Distributed Systems
- Java
- Go
- Python
- C++
- Rust
- SaaS
- API Security
- Threat Detection
- Scalability
- Reliability
- Cloud Native
- Kubernetes
How to get hired
- Tailor your resume: Highlight experience with distributed systems, cloud-native technologies, and security products like WAF.
- Showcase leadership: Emphasize your experience leading technical initiatives and influencing architecture decisions.
- Demonstrate technical depth: Clearly articulate your proficiency in Java, Go, Python, C++, or Rust and your understanding of web application architectures.
- Prepare for behavioral questions: Be ready to discuss your collaboration skills and experience working across diverse teams.
- Research Oracle Cloud Infrastructure: Understand OCI's products, services, and its position in the cloud market.
Technical preparation
Behavioral questions
Frequently asked questions
- What are the key responsibilities for a Principal Software Engineer at Oracle focusing on WAF?
- As a Principal Software Engineer at Oracle, you will lead the architecture and delivery of cloud-scale backend services for the Web Application Firewall (WAF) platform. This includes designing and evolving services for policy management, rule evaluation, threat detection, bot mitigation, and security analytics, while ensuring high availability, performance, and reliability.
- What technical skills are most important for this Principal Software Engineer role at Oracle?
- Strong proficiency in languages like Java, Go, Python, C++, or Rust is essential. Deep expertise in distributed systems design, cloud-native technologies (containers, Kubernetes, IaC), and a solid understanding of HTTP/HTTPS, REST APIs, and web application architectures are critical for success in this role.
- What does Oracle look for in candidates for Principal Software Engineer positions?
- Oracle seeks candidates with 7-10+ years of experience in production software systems, particularly in building large-scale distributed services in cloud or SaaS environments. Demonstrated leadership in technical initiatives, excellent communication and collaboration skills, and a strong foundation in software engineering principles are highly valued.
- How does Oracle's WAF platform differ from other cloud security solutions?
- Oracle's OCI WAF platform is designed for cloud-scale, offering advanced traffic inspection, policy management, and bot mitigation capabilities integrated into Oracle Cloud Infrastructure. It focuses on protecting customer applications from web-based threats with a strong emphasis on reliability, performance, and automation across OCI's global infrastructure.
- Can you explain the career growth opportunities for a Principal Software Engineer at Oracle?
- As a Principal Software Engineer, you have opportunities to influence technical strategy, mentor other engineers, and lead complex initiatives. Oracle offers pathways for technical leadership and subject matter expertise, contributing to the long-term vision of its application security portfolio.
- What is the expected impact of this Principal Software Engineer role on OCI's security offerings?
- This role will directly impact OCI customers by delivering core WAF capabilities that protect against application-layer attacks. You will launch new security features, improve the platform's scalability and reliability, and help raise engineering quality standards across the organization.
- How does Oracle use AI in its recruiting process for this Principal Software Engineer role?
- Oracle utilizes Artificial Intelligence in its recruiting process to assist with candidate matching and evaluation. You can learn more about their approach by reading their Recruiting Privacy Policy, which is linked within the job posting.