Nokia

Product Security Specialist

Nokia  •  Republic of India (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

We are looking for an experienced Product Security Specialist with 8+ years of experience in securing cloud-native applications and platforms. The role is responsible for driving product security through threat modeling, secure design reviews, vulnerability management, security testing, and DevSecOps practices. The ideal candidate should have expertise in Kubernetes, container security, API security, IAM, OWASP, CVE/CVSS management, and security compliance frameworks. Exposure to OAM/FCAPS, 4G/5G Core Networks and telecom security is desirable. The specialist will collaborate with Engineering, Architecture, Product Security Managers to identify risks, drive remediation, strengthen the product security posture, and ensure compliance with customer and industry security requirements.

  • Drive product security across the entire product lifecycle, including both active development and maintenance releases in production, through threat modeling, secure design reviews, risk assessments, and security-by-design practices.
  • Define, propose, and drive adoption of product security requirements, standards, and controls aligned with customer expectations, industry frameworks, and emerging threat landscapes.
  • Identify security gaps and continuously improve the product security posture by leveraging AI-powered security scanning, code analysis, vulnerability discovery, risk prioritization, and security insights. Lead vulnerability management activities, including CVE/CVSS assessment, security advisories, remediation planning, root cause analysis, and closure of security findings across released and in-development products.
  • Design, review, and strengthen security controls for Kubernetes, containers, APIs, IAM, and cloud-native microservices architectures, ensuring adherence to OWASP and secure coding best practices.
  • Integrate and automate security testing, monitoring, and compliance validation within DevSecOps and CI/CD pipelines, including SAST, DAST, container, dependency, and configuration scanning. Collaborate with Engineering, Architecture, and Product Security teams to assess risks, prioritize mitigations, support compliance initiatives, and enhance telecom product security.
  • In the extended role as a Scrum Master of a SAFe agile team, you'll help the team to plan and execute in delivering the team's objectives as per the committments.

You Have:

  • Engineering degree with 8+ years of relevant experience. Strong expertise in Product Security and the Secure Software Development Lifecycle (SSDLC), including threat modeling, secure architecture and design reviews, risk assessments, threat analysis, and security-by-design practices for cloud-native products.
  • Hands-on experience securing Kubernetes, OpenShift, containers, microservices, APIs, service mesh, IAM/RBAC, secrets management, and cloud-native platforms.
  • Strong knowledge of Application Security and DevSecOps, including OWASP Top 10, secure coding practices, SAST, DAST, SCA, container security, dependency scanning, Infrastructure as Code (IaC) security, and CI/CD security automation.
  • Proven experience in vulnerability management, including CVE/CVSS assessment, security advisories, remediation planning, risk prioritization, root cause analysis, and closure of security findings across products in development and production.
  • Experience securing large-scale distributed data, observability, and telemetry platforms leveraging technologies such as Kafka, ClickHouse, VictoriaMetrics, MariaDB, OpenTelemetry, OTLP, and microservices-based architectures.
  • Strong understanding of authentication, authorization, PKI, encryption, certificate management, API security, network security, zero-trust architecture, and security compliance frameworks. Knowledge of telecom security, OAM/FCAPS, 4G/5G Core Networks, SNMP, and 3GPP security standards for carrier-grade network management and observability solutions.
  • Proven ability to drive product security strategy, collaborate with engineering and architecture teams, leverage AI-powered security analysis and automation tools, and support compliance with customer, regulatory, and industry security requirements.

Nice to Have:

  • Professional certifications such as Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, CSSLP, GIAC (GSEC/GPEN/GCSA), or equivalent security certifications.
  • Prior experience as a Scrum Master.
Nokia

About Nokia

Nokia is a global leader in connectivity for the AI era. With expertise across fixed, mobile, and transport networks, powered by the innovation of Nokia Bell Labs, we’re advancing connectivity to secure a brighter world.

Advanced connectivity is key to enable the opportunities of AI – opening new doors for us and our customers. Once known for connecting people, our technology is now essential to connecting intelligence.

Our priority is to deliver superior performance with the trust and security our customers need and we’re a committed innovation partner, shaping the future of connectivity.

For our latest updates, please visit us online www.nokia.com

To view open positions and to apply, please visit: www.nokia.com/careers

Industry
Telecommunications
Company Size
10,000+ employees
Headquarters
Espoo, FI
Year Founded
Unknown
Website
nokia.com
Social Media