01 Oct
|
NOKIA
|
Bengaluru
Your responsibilities
- Drive product security across the entire product lifecycle, including both active development and maintenance releases in production, through threat modeling, secure design reviews, risk assessments, and security-by-design practices.
- Define, propose, and drive adoption of product security requirements, standards, and controls aligned with customer expectations, industry frameworks, and emerging threat landscapes.
- Identify security gaps and continuously improve the product security posture by leveraging AI-powered security scanning, code analysis, vulnerability discovery, risk prioritization, and security insights. Lead vulnerability management activities, including CVE/CVSS assessment, security advisories, remediation planning, root cause analysis, and closure of security findings across released and in-development products.
- Design, review, and strengthen security controls for Kubernetes, containers, APIs, IAM, and cloud-native microservices architectures, ensuring adherence to OWASP and secure coding best practices.
- Integrate and automate security testing, monitoring, and compliance validation within DevSecOps and CI/CD pipelines, including SAST, DAST, container, dependency, and configuration scanning. Collaborate with Engineering, Architecture, and Product Security teams to assess risks, prioritize mitigations, support compliance initiatives, and enhance telecom product security.
- In the extended role as a Scrum Master of a SAFe agile team, you'll help the team to plan and execute in delivering the team's objectives as per the committments.
Your skills and experience
- Engineering degree with 8+ years of relevant experience.
Solid expertise in Product Security and the Secure Software Development Lifecycle (SSDLC), including threat modeling, secure architecture and design reviews, risk assessments, threat analysis, and security-by-design practices for cloud-native products.
- Hands-on experience securing Kubernetes, OpenShift, containers, microservices, APIs, service mesh, IAM/RBAC, secrets management, and cloud-native platforms.
- Strong knowledge of Application Security and DevSecOps, including OWASP Top 10, secure coding practices, SAST, DAST, SCA, container security, dependency scanning, Infrastructure as Code (IaC) security, and CI/CD security automation.
- Proven experience in vulnerability management, including CVE/CVSS assessment, security advisories, remediation planning, risk prioritization, root cause analysis, and closure of security findings across products in development and production.
- Experience securing large-scale distributed data, observability, and telemetry platforms leveraging technologies such as Kafka, ClickHouse, VictoriaMetrics, MariaDB, OpenTelemetry, OTLP, and microservices-based architectures.
- Strong understanding of authentication, authorization, PKI, encryption, certificate management, API security, network security, zero-trust architecture, and security compliance frameworks. Knowledge of telecom security, OAM/FCAPS, 4G/5G Core Networks, SNMP, and 3GPP security standards for carrier-grade network management and observability solutions.
- Proven ability to drive product security strategy, collaborate with engineering and architecture teams, leverage AI-powered security analysis and automation tools, and support compliance with customer, regulatory, and industry security requirements.
📌 Product Security specialist (Bengaluru)
🏢 NOKIA
📍 Bengaluru