Senior Compliance Assessor

Nokia

Amadora

Presencial

EUR 70 000 - 100 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Nokia is seeking a Senior Compliance Assessor to lead the selection and implementation of security and privacy controls on Nokia's business-critical assets. You will assess overall effectiveness of controls and determine risk to operations and assets, as part of the Information Security SAS team.

You will gather threat intelligence, define assessment strategies, and execute testing to verify control implementation, maturity, and effectiveness.

Qualificações

  • Strong expertise in network & application security, IAM & privacy controls, architectural implementations across Windows & Linux systems.
  • Deep understanding of corporate IT operational environments.
  • Experience with security platforms (firewalls, proxies, IPS, vulnerability management, endpoint security, SIEM).
  • Ability to use MITRE ATT&CK lifecycle tools on Windows and Linux.
  • Experience reviewing/testing results and proposing remediation with SAS teams.

Responsabilidades

  • Gather threat intelligence on security control weaknesses and vulnerabilities across Nokia’s infrastructure.
  • Define security assessment and testing strategy based on system specs, roles, and threat data.
  • Execute assessment to verify controls are implemented and assess maturity against Nokia’s security goals.
  • Model threats to determine exploitability and criticality of vulnerabilities.
  • Execute testing strategies by building and running payloads to validate weaknesses.
  • Document identified gaps and vulnerabilities in security assessment reports.
  • Collaborate with IT and business teams to mitigate identified gaps.
  • Contribute assessment outputs to red and purple teams for ongoing improvement.

Conhecimentos

Network security
Application security
IAM
Privacy controls
Windows & Linux
MITRE ATT&CK
Vulnerability management
Security testing
Threat modeling
Presentations

Formação académica

Bachelor's degree in CS/IT
Security certifications (CISSP / CISM)

Ferramentas

Firewalls
Proxies
IPS
SIEM
Vulnerability scanning tools
Cloud security (Azure/GCP/AWS)

Descrição da oferta de emprego

Job Description

As a Senior Compliance Assessor, the selection & implementation of security & privacy controls on business-critical assets within Nokia is an important task, which can have implications on the operations and assets of Nokia. Understanding the overall effectiveness of those security & privacy controls is essential in determining the risk to the organization’s operations and assets resulting from the use of the system.

As a Senior Compliance Assessor, the selection & implementation of security & privacy controls on business-critical assets within Nokia is an important task, which can have implications on the operations and assets of Nokia. Understanding the overall effectiveness of those security & privacy controls is essential in determining the risk to the organization’s operations and assets resulting from the use of the system. As part of Nokia Information Security, you will become part of the Security Architecture & Solutions (SAS) team, wherein you will join the Security Assessment & Testing Team.

How You Will Contribute And What You Will Learn
  • Gather, create & maintain relevant threat intelligence of potential security control weaknesses and security vulnerabilities across Nokia’s corporate system infrastructure. This effort will be performed in close collaboration with other Information Security Teams.
  • Define security assessment & testing strategy for the target system by taking into account system specifications, system mechanisms, system activities, user roles & associated privileges and permissions in the context of all available threat intelligence data.
  • Execute the security assessment strategy to verify & validate if relevant security & privacy controls are implemented on targeted system(s) & their operational environment. You will also assess their maturity and effectiveness in meeting Nokia’s security goals & objectives.
  • Model threats to determine the exploitability & the criticality of various security vulnerabilities on the target system(s).
  • Execute the security testing strategy by building and executing payloads to validate & confirm these identified weaknesses.
  • List all identified security control gaps and security vulnerabilities for each target system(s) and document those in “security assessment & testing” reports.
  • Advise and collaborate with all relevant Information Security Teams & other key stakeholders (IT, business teams) to provide conclusive strategies on how to best mitigate all identified security control gaps and vulnerabilities for each target system(s).
  • Be a key contributor to provide relevant assessment and testing outputs to red and purple teams to support their continuous improvement actions of response processes and architectural capabilities.
Key Skills And Experience
Must- Have
  • Strong expertise in network & application security, IAM & privacy controls, networking concepts and architectural implementations and expertise in Windows & Linux operating systems in various roles in both user-level and privileged-user capacities
  • Deep understanding of a corporate IT operational environments
  • Diverse operational security experience with security platforms, such as: firewalls, proxies, IPS, Vulnerability Management, endpoint security & SIEM solutions.
  • The ability to effectively use command-line tools to achieve functions throughout the MITRE ATT@CK lifecycle (Windows and Linux)
  • Demonstrated & proven ability to review & validate test results and Demonstrated & proven ability to propose, design & implement IT and security solutions remediating the detected findings & vulnerabilities in close collaboration with other SAS teams (security analysts, security specialists and security architects)
  • Familiarity with zero trust principles, API security, and associated attack vectors and The ability to conduct technical security assessments, advise & pursue stakeholders on remediation strategies & action plans
  • Vulnerability management lifecycle skills including identification, validation, rating, and remediation of identified weaknesses and experience in the operational use of multi-cloud security assessment, vulnerability, and testing solutions in Azure, GCP and/or AWS
  • Strong presentation skills and the ability to convey technical security concepts to non-technical audiences
Nice-To-Have
  • Experience in the design, implementation, and administration of multi-cloud security testing environments such as Azure, GCP, and/or AWS and Ability to secure applications throughout the Software Development Lifecycle (SDLC) using SAST, DAST, and/or IAST tools
  • Capable of modeling threats across standard frameworks (MITRE, STRIDE, Kill-Chain) ad Demonstrated penetration testing experience
  • Experience participating in red, blue, and purple team attack/defense engagements as a key contributor and Proven ability to assemble and execute offensive security payloads using diverse testing toolsets
  • Being familiar with NIST standards, such as: NIST Cyber Security Framework and NIST SP 800-53A related to assessing security & privacy controls and Good scripting knowledge (such as Java, C, python, PowerShell, Ansible)
  • Relevant security certifications, such as: CISSP, CISM, CEH, GPEN, OSCP.
About Us
Advancing connectivity to secure a brighter world.

Nokia is a global leader in connectivity for the AI era. With expertise across fixed, mobile and transport networks, powered by the innovation of Nokia Bell Labs, we’re advancing connectivity to secure a brighter world.

Learn more about life at Nokia .

Our recruitment process

We act inclusively and respect the uniqueness of people. Our employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law. We are committed to a culture of inclusion built upon our core value of respect.

Unique backgrounds, perspectives, and experiences enrich our teams, and you may be just the right candidate for this or another opportunity.

The length of the recruitment process may vary depending on the specific role's requirements. We strive to ensure a smooth and inclusive experience for all candidates. Discover more about the recruitment process at Nokia .

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior Security Compliance Assessor
Senior Security Compliance Assessor

Nokia • Amadora

Presencial
EUR 70 000 - 90 000
Technical Delivery Lead
Technical Delivery Lead

Nokia • Amadora

Presencial
EUR 70 000 - 90 000
Senior Security Assessment & Controls Lead
Senior Security Assessment & Controls Lead

Nokia • Amadora

Presencial
EUR 70 000 - 100 000
Senior Security Compliance Assessor
Senior Security Compliance Assessor

Jobtailor • Amadora

Presencial
EUR 60 000 - 90 000
Knowledge Services - Systems Operations Engineer
Knowledge Services - Systems Operations Engineer

Nokia • Lisboa

Presencial
EUR 52 000 - 76 000
Staff Software QA Engineer
Staff Software QA Engineer

Nokia • Lisboa

Presencial
EUR 40 000 - 60 000
Java SW Developer
Java SW Developer

Nokia • Lisboa

Presencial
EUR 45 000 - 75 000
Flexible working arrangements
Maternity and paternity leave
Medical and life insurance
+5
Identity Access Program Manager
Identity Access Program Manager

Nokia • Amadora

Híbrido
EUR 60 000 - 80 000
Medical insurance plan
Flexible working arrangements
On-site fitness center
+3
SW Trainee - Development
SW Trainee - Development

Nokia • Aveiro

Híbrido
EUR 12 000 - 16 000
Flexible/hybrid work
Meal allowance
Well-being programs
+2
Lead TPM for T2G
Lead TPM for T2G

Nokia • Amadora

Presencial
EUR 90 000 - 120 000
Flexible working arrangements
Maternity and Paternity Leave
Medical and life insurance
+4