hireejobsgulf

NI Product Security Manager

1.00 to 10.00 Years   Oman   13 Jun, 2022
Job LocationOman
EducationNot Mentioned
SalaryNot Mentioned
IndustryOther Business Support Services
Functional AreaNot Mentioned

Job Description

Come create the technology that helps the world act togetherNokia is committed to innovation and technology leadership across mobile, fixed and cloud networks. Your career here will have a positive impact on people?s lives and will help us build the capabilities needed for a more productive, sustainable, and inclusive world.We challenge ourselves to create an inclusive way of working where we are open to new ideas, empowered to take risks and fearless to bring our authentic selves to work.The team youll be part ofThe pandemic has highlighted how important telecoms networks are to society. Nokia?s Network Infrastructure group is at the heart of a revolution to bring more and faster network capacity to people worldwide through our ambition, innovation, and technical expertise.The Product Security Manager (PSM) role is a key part of the Network Infrastructure (NI) Security & Privacy Team. The NI Security & Privacy Team is part of the NI Quality organization within the NI Operations unit. Its role is to support NI business functions to assure that security & privacy is taken into practice across all activities within the business. Be a mentor and subject matter expert when it comes to security and privacy to ensure that Nokia NI products, services and solutions are successful in complying with the Nokia Design for Security (DFSEC) processes, practices, and requirements.The Product Security Manager plays a vital role within NI business operations, products, services, and solutions. The NI Security & Privacy Team is looking for a candidate to fill this role and join the work of the existing NI PSMs.What you will learn and contribute toNI is looking for an experienced cybersecurity professional to fill the role of Product Security Manager. In this role you will support various NI business functions, including Product R&D, Services, Customer Teams and Regional Business Centers (RBC?s) to drive enhancement and/or compliance to security & privacy requirements into different aspects of the NI business and evaluate the effectiveness of implemented security controls to mitigate, reduce, or eliminate risks related to Security & Privacy.Knowledge on product security engineering and experience in security compliance assessment are prerequisites for this job. Nokia DFSEC is based on both proactive and reactive security engineering. This includes understanding how to translate security controls sets into implementation requirements. An understanding of software engineering and programming is a fundamental requirement for this role, because NI products, services and solutions are software based and product security begins with understanding design aspects that can introduce security risks. Candidates should have knowledge and experience in conducting product security risk assessment, including use of threat and risk modelling and Privacy Impact Assessments using techniques and tools to successfully coaching teams to identify gaps, develop risk treatment plans or development roadmaps to address issues identified.Experience in performing security vulnerability scanner-based product security assessments and analysis and remediation planning of findings is required. Knowledge on the use of the DFSEC Compliance Tool and the Vulnerability Assessment and Management System tools are desired skills sets for this job.This role will require knowledge of application security engineering and testing, secure software development practices and broad knowledge of application and network vulnerabilities, including how attacker types exploit them. Configuring and running various types of security test tools (EG, Threat Modeler, SAST, DAST, Fuzz, Vulnerability, Security Hardening tool types), generating reports, communicating findings with development teams and negotiating remediation of issues are key components of the role.You play a key role to promote Nokia standards and guidance for applying the Nokia DFSEC process, as well as collaborate with other Nokia security teams on continual improvement to these standards and guidance to build a stronger security culture across NI.As a senior engineer you will help define and build NI security expertise, including NI specific security standards, guidelines and standard operating procedures and execute the targets of the security program across NI. You will be a source of coaching and mentoring for security expertise within NI and Nokia.Are you passionate about solving problems?As part of our team, you will:

  • Act as a Subject Matter Expert (SME) on key software security engineering topics
  • To increase security awareness in the NI business units
  • Drive adoption of the Nokia CREATE and DFSEC processes across NI business units
  • Influence product roadmaps to include relevant security and privacy features
  • Working with software designers, developers, project managers, DevOps, and testers, to review, assist and recommend changes and solutions to address the security of web, cloud-based and mobile solutions
  • Conducting security assessments using industry-standard tools and techniques
  • Lead security reviews in NI Quality product development lifecycle milestone meetings
  • Analyzing and assisting in the secure testing of applications and network infrastructure
  • Reviewing and explaining vulnerability assessment and penetration test report findings to key stakeholders
  • Producing reports to demonstrate assessment coverage and remediation effectiveness, and working with the product engineers and software teams to ensure corrective actions are implemented
  • Supporting engineering teams securing software and platforms
  • Ensure that Nokia DFSEC and Security Vulnerability Monitoring (SVM) processes are being implemented
  • Continuous contribute to improving the NI security maturity, Nokia product security policies, processes, standards, requirements and guidelines
  • Provide support to incident response management teams
  • Coaching and mentoring NI security team member
  • Support NI Incident Response activities (Security & Privacy)
  • Be a key point of contact for Customer Security requests
  • Support the NI business in ISO 27001 Certification efforts through program coordination or site SPoC leadership.
  • Be a subject matter expert (SME) for Security & Privacy to all aspects of the NI business related to different global Legal & Regulatory compliance requirements (e.g., GDPR, NIST, CCPA, ANSSI, CSL etc.)
Your skills and experience You have:
  • Bachelors Degree in Computer Science or related degree
  • 5+ years of experience in product security compliance roles
  • Technical proficiency with secure product development skills

Keyskills :

APPLY NOW

Related Jobs

© 2023 HireeJobsGulf All Rights Reserved