Nokia Logo

Nokia

Senior Compliance Assessor

Reposted 3 Days Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in India
Senior level
Remote or Hybrid
Hiring Remotely in India
Senior level
Lead security assessment and testing for business-critical systems: gather threat intelligence, define and execute assessment strategies, validate security and privacy controls, model threats, execute payloads to verify vulnerabilities, report findings, and advise stakeholders on remediation. Support red and purple teams and collaborate across InfoSec and IT teams.
The summary above was generated by AI

As a Senior Compliance Assessor, the selection & implementation of security & privacy controls on business-critical assets within Nokia is an important task, which can have implications on the operations and assets of Nokia.  Understanding the overall effectiveness of those security & privacy controls is essential in determining the risk to the organization’s operations and assets resulting from the use of the system.

As part of Nokia Information Security, you will become part of the Security Architecture & Solutions (SAS) team, wherein you will join the Security Assessment & Testing Team

Responsibilities
  • Gather, create & maintain relevant threat intelligence of potential security control weaknesses and security vulnerabilities across Nokia’s corporate system infrastructure.  This effort will be performed in close collaboration with other Information Security Teams.
  • Define security assessment & testing strategy for the target system by taking into account system specifications, system mechanisms, system activities, user roles & associated privileges and permissions in the context of all available threat intelligence data.
  • Execute the security assessment strategy to verify & validate if relevant security & privacy controls are implemented on targeted system(s) & their operational environment.  You will also assess their maturity and effectiveness in meeting Nokia’s security goals & objectives.
  • Model threats to determine the exploitability & the criticality of various security vulnerabilities on the target system(s).
  • Execute the security testing strategy by building and executing payloads to validate & confirm these identified weaknesses.
  • List all identified security control gaps and security vulnerabilities for each target system(s) and document those in “security assessment & testing” reports.
  • Advise and collaborate with all relevant Information Security Teams & other key stakeholders (IT, business teams) to provide conclusive strategies on how to best mitigate all identified security control gaps and vulnerabilities for each target system(s).
  • Be a key contributor to provide relevant assessment and testing outputs to red and purple teams to support their continuous improvement actions of response processes and architectural capabilities.
Qualifications

Must- Have

  • Strong expertise in network & application security, IAM & privacy controls, networking concepts and architectural implementations and expertise in Windows & Linux operating systems in various roles in both user-level and privileged-user capacities
  • Deep understanding of a corporate IT operational environments
  • Diverse operational security experience with security platforms, such as: firewalls, proxies, IPS, Vulnerability Management, endpoint security & SIEM solutions.
  • The ability to effectively use command-line tools to achieve functions throughout the MITRE ATT@CK lifecycle (Windows and Linux)
  • Demonstrated & proven ability to review & validate test results and Demonstrated & proven ability to propose, design & implement IT and security solutions remediating the detected findings & vulnerabilities in close collaboration with other SAS teams (security analysts, security specialists and security architects)
  • Familiarity with zero trust principles, API security, and associated attack vectors and The ability to conduct technical security assessments, advise & pursue stakeholders on remediation strategies & action plans
  • Vulnerability management lifecycle skills including identification, validation, rating, and remediation of identified weaknesses and experience in the operational use of multi-cloud security assessment, vulnerability, and testing solutions in Azure, GCP and/or AWS
  • Strong presentation skills and the ability to convey technical security concepts to non-technical audiences

 

Nice-To-Have

  • Experience in the design, implementation, and administration of multi-cloud security testing environments such as Azure, GCP, and/or AWS and Ability to secure applications throughout the Software Development Lifecycle (SDLC) using SAST, DAST, and/or IAST tools
  • Capable of modeling threats across standard frameworks (MITRE, STRIDE, Kill-Chain) ad Demonstrated penetration testing experience
  • Experience participating in red, blue, and purple team attack/defense engagements as a key contributor and Proven ability to assemble and execute offensive security payloads using diverse testing toolsets
  • Being familiar with NIST standards, such as: NIST Cyber Security Framework and NIST SP 800-53A related to assessing security & privacy controls and Good scripting knowledge (such as Java, C, python, PowerShell, Ansible)
  • Relevant security certifications, such as: CISSP, CISM, CEH, GPEN, OSCP.
About Us
Advancing connectivity to secure a brighter world.

Nokia is a global leader in connectivity for the AI era. With expertise across fixed, mobile and transport networks, powered by the innovation of Nokia Bell Labs, we’re advancing connectivity to secure a brighter world. 

Learn more about life at Nokia.


Our recruitment process

We act inclusively and respect the uniqueness of people. Our employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law. We are committed to a culture of inclusion built upon our core value of respect.

If you’re interested in this role but don’t meet every listed requirement, we still encourage you to apply. Unique backgrounds, perspectives, and experiences enrich our teams, and you may be just the right candidate for this or another opportunity.

The length of the recruitment process may vary depending on the specific role's requirements. We strive to ensure a smooth and inclusive experience for all candidates. Discover more about the recruitment process at Nokia. 

About the Team

Some of our benefits in India:

  • Flexible and hybrid working arrangements to support work–life balance
  • Health and well-being support – medical insurance for you and your family, health check-ups, life and accident insurance, well-being programs, and employee resource groups 
  • A minimum of 90 days of Maternity and Paternity Leave based on eligibility
  • Personal Support Service 24/7 – a confidential support channel open to all Nokia employees and their families in challenging situations
  • Career growth & mobility – technical career paths, job rotations, international assignments, and relocation support
  • Continuous learning – technical certifications, mentoring programs, coaching, and digital learning platforms
  • Opportunities to innovate and contribute through Nokia’s research and development environment
  • Recognition programs that celebrate outstanding contributions
  • Workplace support – ergonomic working support and mobile device programs based on eligibility

Nokia Mumbai, Maharashtra, IND Office

Mumbai, India

Similar Jobs

2 Hours Ago
Remote or Hybrid
India
Entry level
Entry level
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
As an ML Engineer, you will design, experiment, and deploy AI/ML models, evaluate their performance, and leverage Python and SQL.
Top Skills: PythonPyTorchScikit-LearnSQL
4 Hours Ago
Remote or Hybrid
India
Entry level
Entry level
Financial Services
Review, verify, and report client data to ensure accuracy and AML/regulatory compliance. Prepare Currency Transaction Reports and compliance documentation, respond to operational requests, escalate issues, and support process improvements. Use digital tools to manage data, resolve service issues, and contribute to operational excellence.
Top Skills: MainframeMS OfficePc-Based Systems
4 Hours Ago
Easy Apply
Remote
India
Easy Apply
Mid level
Mid level
Cloud • Security • Software • Cybersecurity • Automation
Provide hands-on technical consultancy to APJ customers to drive GitLab adoption, unblock implementations, lead workshops/demos, and align technical recommendations with account goals. Manage multiple engagements, produce enablement content, mentor peers and customers, and stay current on DevSecOps tooling and GitLab capabilities to support renewals and expansion.
Top Skills: Agile PlanningCi/CdDevsecopsGitlabSource Code ManagementZoom

What you need to know about the Mumbai Tech Scene

From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account