Senior Compliance Assessor

Nokia

Bengaluru

On-site

INR 1,800,000 - 3,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nokia is seeking a Senior Compliance Assessor to drive security and privacy controls across business-critical assets, shaping risk posture and assurance for operations.

You will define assessment strategies, execute testing, model threats, and collaborate with SAS teams to remediate findings and strengthen Nokia’s security landscape across multi-cloud and on-prem environments.

Qualifications

  • Strong expertise in network & application security and IAM & privacy controls.
  • Deep understanding of corporate IT operational environments.
  • Experience with security platforms (firewalls, proxies, IPS, SIEM).
  • Ability to use MITRE ATT&CK lifecycle tools & techniques.
  • Proven ability to design and implement remediation for security findings.

Responsibilities

  • Gather threat intelligence on security control weaknesses and vulnerabilities across Nokia’s assets.
  • Define security assessment & testing strategy considering system specs, user roles, and threat data.
  • Execute assessment strategy to verify controls and assess maturity against Nokia security goals.
  • Model threats to determine exploitability and criticality of vulnerabilities.
  • Execute testing strategy by building and executing payloads to validate weaknesses.
  • Document all identified gaps and vulnerabilities in assessment reports.
  • Collaborate with IT, business teams, and SAS to mitigate identified gaps and vulnerabilities.
  • Contribute assessment outputs to red/purple teams for improvement actions.

Skills

Network security
Application security
IAM & privacy controls
MITRE ATT&CK lifecycle
Threat modeling
Vulnerability management
Multi-cloud security (Azure/GCP/AWS)
Windows & Linux administration
Security architecture & solutions
Public speaking / presentation

Tools

SIEM
Firewalls
IPS
Proxies
Vulnerability scanners
Cloud security tooling

Job description

Job Description

As a Senior Compliance Assessor, the selection & implementation of security & privacy controls on business-critical assets within Nokia is an important task, which can have implications on the operations and assets of Nokia. Understanding the overall effectiveness of those security & privacy controls is essential in determining the risk to the organization’s operations and assets resulting from the use of the system.

As a Senior Compliance Assessor, the selection & implementation of security & privacy controls on business-critical assets within Nokia is an important task, which can have implications on the operations and assets of Nokia. Understanding the overall effectiveness of those security & privacy controls is essential in determining the risk to the organization’s operations and assets resulting from the use of the system. As part of Nokia Information Security, you will become part of the Security Architecture & Solutions (SAS) team, wherein you will join the Security Assessment & Testing Team.

How You Will Contribute And What You Will Learn
  • Gather, create & maintain relevant threat intelligence of potential security control weaknesses and security vulnerabilities across Nokia’s corporate system infrastructure. This effort will be performed in close collaboration with other Information Security Teams.
  • Define security assessment & testing strategy for the target system by taking into account system specifications, system mechanisms, system activities, user roles & associated privileges and permissions in the context of all available threat intelligence data.
  • Execute the security assessment strategy to verify & validate if relevant security & privacy controls are implemented on targeted system(s) & their operational environment. You will also assess their maturity and effectiveness in meeting Nokia’s security goals & objectives.
  • Model threats to determine the exploitability & the criticality of various security vulnerabilities on the target system(s).
  • Execute the security testing strategy by building and executing payloads to validate & confirm these identified weaknesses.
  • List all identified security control gaps and security vulnerabilities for each target system(s) and document those in “security assessment & testing” reports.
  • Advise and collaborate with all relevant Information Security Teams & other key stakeholders (IT, business teams) to provide conclusive strategies on how to best mitigate all identified security control gaps and vulnerabilities for each target system(s).
  • Be a key contributor to provide relevant assessment and testing outputs to red and purple teams to support their continuous improvement actions of response processes and architectural capabilities.
Key Skills And Experience
Must- Have
  • Strong expertise in network & application security, IAM & privacy controls, networking concepts and architectural implementations and expertise in Windows & Linux operating systems in various roles in both user-level and privileged-user capacities
  • Deep understanding of a corporate IT operational environments
  • Diverse operational security experience with security platforms, such as: firewalls, proxies, IPS, Vulnerability Management, endpoint security & SIEM solutions.
  • The ability to effectively use command-line tools to achieve functions throughout the MITRE ATT@CK lifecycle (Windows and Linux)
  • Demonstrated & proven ability to review & validate test results and Demonstrated & proven ability to propose, design & implement IT and security solutions remediating the detected findings & vulnerabilities in close collaboration with other SAS teams (security analysts, security specialists and security architects)
  • Familiarity with zero trust principles, API security, and associated attack vectors and The ability to conduct technical security assessments, advise & pursue stakeholders on remediation strategies & action plans
  • Vulnerability management lifecycle skills including identification, validation, rating, and remediation of identified weaknesses and experience in the operational use of multi-cloud security assessment, vulnerability, and testing solutions in Azure, GCP and/or AWS
  • Strong presentation skills and the ability to convey technical security concepts to non-technical audiences
Nice-To-Have
  • Experience in the design, implementation, and administration of multi-cloud security testing environments such as Azure, GCP, and/or AWS and Ability to secure applications throughout the Software Development Lifecycle (SDLC) using SAST, DAST, and/or IAST tools
  • Capable of modeling threats across standard frameworks (MITRE, STRIDE, Kill-Chain) ad Demonstrated penetration testing experience
  • Experience participating in red, blue, and purple team attack/defense engagements as a key contributor and Proven ability to assemble and execute offensive security payloads using diverse testing toolsets
  • Being familiar with NIST standards, such as: NIST Cyber Security Framework and NIST SP 800-53A related to assessing security & privacy controls and Good scripting knowledge (such as Java, C, python, PowerShell, Ansible)
  • Relevant security certifications, such as: CISSP, CISM, CEH, GPEN, OSCP.
About Us
Advancing connectivity to secure a brighter world.

Nokia is a global leader in connectivity for the AI era. With expertise across fixed, mobile and transport networks, powered by the innovation of Nokia Bell Labs, we’re advancing connectivity to secure a brighter world.

Learn more about life at Nokia .

Our recruitment process

We act inclusively and respect the uniqueness of people. Our employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law. We are committed to a culture of inclusion built upon our core value of respect.

Unique backgrounds, perspectives, and experiences enrich our teams, and you may be just the right candidate for this or another opportunity.

The length of the recruitment process may vary depending on the specific role's requirements. We strive to ensure a smooth and inclusive experience for all candidates. Discover more about the recruitment process at Nokia .

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Specialist
Senior Security Specialist

Nokia • Bengaluru

Hybrid
INR 2,500,000 - 4,200,000
Hybrid working arrangements in India
Medical insurance for you and family
Life and accident insurance
+2
Security Architect
Security Architect

Nokia • Bengaluru

Hybrid
INR 3,000,000 - 6,000,000
Flexible and hybrid working
Health and well-being support
Maternity and paternity leave (minimum
+2
Security Operations Specialist
Security Operations Specialist

Nokia • Gurugram District

Hybrid
INR 1,500,000 - 2,500,000
Flexible working schemes
90 days Maternity and Paternity Leave
Life insurance
+2
Senior System Architect
Senior System Architect

Nokia • Chennai District

On-site
INR 1,200,000 - 1,800,000
Solution Services Domain Architect
Solution Services Domain Architect

Nokia • Thiruporur

On-site
INR 1,800,000 - 3,000,000
Domain Architect
Domain Architect

Nokia • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Flexible and hybrid working
Health and well‑being support
Maternity/Paternity leave
+6
IT Product Owner
IT Product Owner

Nokia • Thiruporur

Hybrid
INR 1,800,000 - 2,400,000
Flexible working
Health insurance
Maternity/Paternity leave (90 days)
+3
Senior Network Solution Designer
Senior Network Solution Designer

Nokia • Thiruporur

On-site
INR 1,200,000 - 2,100,000
Flexible and hybrid working
Health and well-being support
Maternity and paternity leave
+6
MS Specialist OSS
MS Specialist OSS

Nokia • Dadri

On-site
INR 1,500,000 - 2,100,000
Flexible work
Health insurance
Maternity/Paternity Leave
+4
IT Product Owner
IT Product Owner

Nokia • Bengaluru

Hybrid
INR 2,000,000 - 3,500,000
Flexible and hybrid working
Medical insurance for you and family
Maternity and paternity leave
+3