Job Description
In this role, you will help strengthen Nokia's IT security and access management environment, ensuring compliance with company policies, regulatory requirements, and industry best practices. Working closely with the Digital Office, IT Operations teams, Business Groups, and external partners, you will drive the continuous improvement of access controls, privileged access management, and security governance while promoting simplification, standardization, and operational excellence across the organization.
Responsibilities
- Conduct regular assessments and audits of IT operations and services to ensure compliance with internal security policies, external regulations (e.g., GDPR, SOX), and industry standards.
- Develop and maintain key performance indicators (KPIs) to track the effectiveness of access management solutions and compliance posture. Regularly report on performance to stakeholders.
- Proactively identify opportunities to improve the efficiency, effectiveness, and cost‑optimization of access management processes, compliance activities, and vulnerability management.
- Collaborate in defining and executing the overall strategy for Nokia's identity and privileged access programs, aligning with broader security objectives and business needs.
- Manage and maintain privileged access technologies, ensuring optimal performance, security, and integration with other systems.
- Oversee the lifecycle of identities and access rights, from provisioning and de‑provisioning to regular reviews.
- Implement and enforce robust access control policies and governance frameworks across Nokia's IT landscape, managing Role‑Based Access Control (RBAC) and Attribute‑Based Access Control (ABAC).
Key Skills and Experience
- Master's degree in computer science or related technical field, with specializations in Cybersecurity, Information Assurance, or Information Security.
- English proficiency.
- 7 years overall experience in Cybersecurity, with at least 3 years hands‑on experience in Security Services related to Cloud Security, Identity and Access Management (IAM), and Privileged Access Management (PAM).
- Strong understanding of IAM/PAM principles, access control models (RBAC, ABAC), and identity federation technologies (e.g., SAML, OAuth).
- Proven experience with privileged access technology administration, policy configuration, and integration with various IT systems.
- Experience in IT operations compliance, security auditing, and risk management.
- Experience collaborating with diverse technical and non‑technical stakeholders.
- Excellent communication, interpersonal, and presentation skills.
- Ability to work independently and as part of a team.
- Strong analytical and problem‑solving skills.
Preferred Certifications
- Certified Information Systems Security Professional (CISSP), Certified Identity and Access Manager (CIAM), or similar.
- Experience with cloud security cloud‑based identity and access management solutions.
- Knowledge of scripting languages for automation of access management tasks.
- Experience with security frameworks and regulations (e.g., NIST, ISO 27001, GDPR, SOX).
Recruitment Process
We act inclusively and respect the uniqueness of people. Our employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law. We are committed to a culture of inclusion built upon our core value of respect. If you’re interested in this role but don’t meet every listed requirement, we still encourage you to apply. Unique backgrounds, perspectives, and experiences enrich our teams, and you may be just the right candidate for this or another opportunity.