Product Security Specialist

Nokia

Bengaluru

On-site

INR 3,500,000 - 6,000,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Nokia in Bengaluru is seeking a Product Security Specialist to drive security across the product lifecycle, performing threat modeling, secure design reviews, vulnerability management, and DevSecOps integration.

You will collaborate with Engineering and Security teams to identify risks, implement controls for cloud-native architectures, and ensure compliance with industry standards and customer requirements.

Qualifications

  • Engineering degree in a relevant field with strong security focus.
  • Hands-on experience securing Kubernetes/OpenShift and cloud-native architectures.
  • Solid knowledge of OWASP Top 10, SSDLC, and secure coding practices.
  • Proficiency in threat modeling, risk assessment, and vulnerability management.

Responsibilities

  • Drive product security across the full lifecycle with threat modeling and secure design reviews.
  • Lead vulnerability management, CVE/CVSS assessments, and remediation planning.
  • Define and enforce security requirements and controls for cloud-native apps.
  • Integrate security testing in CI/CD pipelines (SAST/DAST) and monitor compliance.

Skills

Threat modeling
SSDLC
Kubernetes security
Secure coding
Python scripting
DevSecOps

Education

Engineering degree

Tools

Kubernetes security tooling
OpenShift
SAST
DAST
IaC security tooling
CI/CD security automation

Job description

As a Product Security Specialist, you will be responsible for driving product security through threat modeling, secure design reviews, vulnerability management, security testing, and DevSecOps practices. The specialist will collaborate with Engineering, Architecture, Product Security Managers to identify risks, drive remediation, strengthen the product security posture, and ensure compliance with customer and industry security requirements.

Your responsibilities

  • Drive product security across the entire product lifecycle, including both active development and maintenance releases in production, through threat modeling, secure design reviews, risk assessments, and security-by-design practices.
  • Define, propose, and drive adoption of product security requirements, standards, and controls aligned with customer expectations, industry frameworks, and emerging threat landscapes.
  • Identify security gaps and continuously improve the product security posture by leveraging AI-powered security scanning, code analysis, vulnerability discovery, risk prioritization, and security insights. Lead vulnerability management activities, including CVE/CVSS assessment, security advisories, remediation planning, root cause analysis, and closure of security findings across released and in-development products.
  • Design, review, and strengthen security controls for Kubernetes, containers, APIs, IAM, and cloud-native microservices architectures, ensuring adherence to OWASP and secure coding best practices.
  • Integrate and automate security testing, monitoring, and compliance validation within DevSecOps and CI/CD pipelines, including SAST, DAST, container, dependency, and configuration scanning. Collaborate with Engineering, Architecture, and Product Security teams to assess risks, prioritize mitigations, support compliance initiatives, and enhance telecom product security.
Your skills and experience
  • Engineering degree with 8+ years of relevant experience. Strong expertise in Product Security and the Secure Software Development Lifecycle (SSDLC), including threat modeling, secure architecture and design reviews, risk assessments, threat analysis, and security-by-design practices for cloud-native products.
  • Hands-on experience securing Kubernetes, OpenShift, containers, microservices, APIs, service mesh, IAM/RBAC, secrets management, and cloud-native platforms.
  • Strong knowledge of Application Security and DevSecOps, including OWASP Top 10, secure coding practices, SAST, DAST, SCA, container security, dependency scanning, Infrastructure as Code (IaC) security, and CI/CD security automation.
  • Security Architecture, Scanning Tools, Threat Analysis, Data Privacy, Scripting (Python), Security Test Automation, Cloud and Kubernetes Security Certifications, Agentic AI tools, OAM/OSS/EMS/NMS Domain Experience
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

Atlas Consolidated • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Senior Product Security Engineer
Senior Product Security Engineer

Dun & Bradstreet • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Cybersecurity Subject Matter Expert
Cybersecurity Subject Matter Expert

Sunovaa Tech • Pune District, Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Ecolab Global Services • Bengaluru

On-site
INR 3,500,000 - 6,500,000
Product Security Architect (Threat Modeling)
Product Security Architect (Threat Modeling)

JUARA IT SOLUTIONS • Chennai District

On-site
INR 3,000,000 - 5,000,000
Senior Security Engineer
Senior Security Engineer

Insight Global • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Product Security Engineer
Product Security Engineer

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Product Security Engineer
Product Security Engineer

Emerson • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Senior Security Analyst
Senior Security Analyst

McKinsey & Company • Gurugram District

On-site
INR 1,800,000 - 2,400,000