Nokia

Senior Compliance Assessor

Nokia  •  Republic of India (Onsite)  •  1 day ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

As a Senior Compliance Assessor, the selection & implementation of security & privacy controls on business-critical assets within Nokia is an important task, which can have implications on the operations and assets of Nokia. Understanding the overall effectiveness of those security & privacy controls is essential in determining the risk to the organization’s operations and assets resulting from the use of the system.

As part of Nokia Information Security, you will become part of the Security Architecture & Solutions (SAS) team, wherein you will join the Security Assessment & Testing Team

  • Gather, create & maintain relevant threat intelligence of potential security control weaknesses and security vulnerabilities across Nokia’s corporate system infrastructure. This effort will be performed in close collaboration with other Information Security Teams.
  • Define security assessment & testing strategy for the target system by taking into account system specifications, system mechanisms, system activities, user roles & associated privileges and permissions in the context of all available threat intelligence data.
  • Execute the security assessment strategy to verify & validate if relevant security & privacy controls are implemented on targeted system(s) & their operational environment. You will also assess their maturity and effectiveness in meeting Nokia’s security goals & objectives.
  • Model threats to determine the exploitability & the criticality of various security vulnerabilities on the target system(s).
  • Execute the security testing strategy by building and executing payloads to validate & confirm these identified weaknesses.
  • List all identified security control gaps and security vulnerabilities for each target system(s) and document those in “security assessment & testing” reports.
  • Advise and collaborate with all relevant Information Security Teams & other key stakeholders (IT, business teams) to provide conclusive strategies on how to best mitigate all identified security control gaps and vulnerabilities for each target system(s).
  • Be a key contributor to provide relevant assessment and testing outputs to red and purple teams to support their continuous improvement actions of response processes and architectural capabilities.

Must- Have

  • Strong expertise in network & application security, IAM & privacy controls, networking concepts and architectural implementations and expertise in Windows & Linux operating systems in various roles in both user-level and privileged-user capacities
  • Deep understanding of a corporate IT operational environments
  • Diverse operational security experience with security platforms, such as: firewalls, proxies, IPS, Vulnerability Management, endpoint security & SIEM solutions.
  • The ability to effectively use command-line tools to achieve functions throughout the MITRE ATT@CK lifecycle (Windows and Linux)
  • Demonstrated & proven ability to review & validate test results and Demonstrated & proven ability to propose, design & implement IT and security solutions remediating the detected findings & vulnerabilities in close collaboration with other SAS teams (security analysts, security specialists and security architects)
  • Familiarity with zero trust principles, API security, and associated attack vectors and The ability to conduct technical security assessments, advise & pursue stakeholders on remediation strategies & action plans
  • Vulnerability management lifecycle skills including identification, validation, rating, and remediation of identified weaknesses and experience in the operational use of multi-cloud security assessment, vulnerability, and testing solutions in Azure, GCP and/or AWS
  • Strong presentation skills and the ability to convey technical security concepts to non-technical audiences

Nice-To-Have

  • Experience in the design, implementation, and administration of multi-cloud security testing environments such as Azure, GCP, and/or AWS and Ability to secure applications throughout the Software Development Lifecycle (SDLC) using SAST, DAST, and/or IAST tools
  • Capable of modeling threats across standard frameworks (MITRE, STRIDE, Kill-Chain) ad Demonstrated penetration testing experience
  • Experience participating in red, blue, and purple team attack/defense engagements as a key contributor and Proven ability to assemble and execute offensive security payloads using diverse testing toolsets
  • Being familiar with NIST standards, such as: NIST Cyber Security Framework and NIST SP 800-53A related to assessing security & privacy controls and Good scripting knowledge (such as Java, C, python, PowerShell, Ansible)
  • Relevant security certifications, such as: CISSP, CISM, CEH, GPEN, OSCP.
Advancing connectivity to secure a brighter world.

Nokia is a global leader in connectivity for the AI era. With expertise across fixed, mobile and transport networks, powered by the innovation of Nokia Bell Labs, we’re advancing connectivity to secure a brighter world.



Our recruitment process

We act inclusively and respect the uniqueness of people. Our employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law. We are committed to a culture of inclusion built upon our core value of respect.

If you’re interested in this role but don’t meet every listed requirement, we still encourage you to apply. Unique backgrounds, perspectives, and experiences enrich our teams, and you may be just the right candidate for this or another opportunity.

The length of the recruitment process may vary depending on the specific role's requirements. We strive to ensure a smooth and inclusive experience for all candidates. Discover more about the recruitment process at Nokia

Nokia

About Nokia

Nokia is a global leader in connectivity for the AI era. With expertise across fixed, mobile, and transport networks, powered by the innovation of Nokia Bell Labs, we’re advancing connectivity to secure a brighter world.

Advanced connectivity is key to enable the opportunities of AI – opening new doors for us and our customers. Once known for connecting people, our technology is now essential to connecting intelligence.

Our priority is to deliver superior performance with the trust and security our customers need and we’re a committed innovation partner, shaping the future of connectivity.

For our latest updates, please visit us online www.nokia.com

To view open positions and to apply, please visit: www.nokia.com/careers

Industry
Telecommunications
Company Size
10,000+ employees
Headquarters
Espoo, FI
Year Founded
Unknown
Website
nokia.com
Social Media