India
4 days ago
Product Security Lead

Family Description

Applied R&D (AR) consists of target-oriented research either with the goal of solving a particular problem / answering a specific question or for multi-discipline design, development, and implementation of hardware, software, and systems including maintenance support. Supplies techno-economic consulting to clients. AR work is characterised by its detailed and complex nature in order to systematically combine existing knowledge and practices to further developing and incrementally improving products, operational processes, and customer-specific feature development.

Subfamily Description

Software (SWA) comprises the definition, specification, and allocation of requirements from different sources utilising knowledge of systems engineering processes (specification & architecture). Contains processing of use case and feature requirements into conceptual models, operational scenarios, technical requirements, and functional description. Covers specification, design, implementation, and unit testing of Software (e.g. device drivers, microcode, hardware-related software & firmware) according to the requirements and architecture defined in the systems engineering process. Covers establishment and maintenance of Software Configuration Management (SCM) practices into software development projects, continuously building and integrating infrastructure tools and systems.

 

Impact

Impact is short-term and usually departmental/project in scope. Accountable for quality, accuracy and efficiency of own and/or team achievements. Actions and errors can have program, project, functional impact.

Scope & Contribution

Individual Contributor: Performs and/or coordinates day-to-day activities to meet departmental/project objectives. Carries out root/cause analysis in more complex problems. Can develop and implement recommendations. Managerial/Supervisory: Direct supervisory responsibilities for people. Typically first level (and lowest level) of solid line management. Carries out variety of complex activities according to plan within broader area of responsibility, analyses problems. Decision-making typically according to established solutions.

Innovation

Accepts responsibility for and demonstrates support for delegated decisions. Requires minimum supervision. Uses non standard approaches to resolving issues. Suggests improvements and seeks opportunities for innovation. Demonstrates initiative & adaptability to changing business environments. Is willing to take on new roles or jobs appropriate to skill set in different environments and/or locations.

Communication

Works to influence others to accept job function’s view/practices and agree/accept new concepts, practices, and approaches. Requires ability to communicate with functional leadership regarding team & technical matters. May conduct briefings with senior leaders within the job function. May at times be required to negotiate regarding operational issues.Has cross-cultural knowledge and global mindset

Knowledge & Experience

Management experience / Achieved advanced skills and knowledge within a specific professional discipline involving the integration of theory and principles with organisational practices and precedents. 

Experience: 9+ years in software development or testing within Telecommunications Networks, with expertise in cloud-native design and development.Knowledge about the security architecture of the product.Experience with Vulnerability assessment, management and CVE analysis along with impact analysis  Hands on experience with any vulnerability management tool (Ex, VAMS)Involved with Security tests (Black duck hub, Tenable, Codenomicon, Malware, NMAP, NetSparker, DOS/DDOS attack, etc) and report analysis.Design for Security and privacy kept in mind. Ensure that Design for Security & Privacy methodologyWorking knowledge on secure protocols (TLS/DTLS/SSH ), Encryption methodology, Ciphers etc.Experience on handling/managing SOC, Threat & Risk analysis for a productStrong analytical & leading skillsKnowledge on cloud, containerization and related security aspectsKnowledge on RFI/RFQ/RFP tendering processExperience in Security hardening and Secure DevOpsPreparing security test reports/security evidences for C3/C5 milestonesAny Certification on Security Management is an added advantageExposure to SAFe agile methodologies will be a plus.Handle security and privacy aspects of CSCF product.Able to understand telecom security topics and do impact analysis on products / feature areas.Interface with Customer teams, Product management and connect well internally with feature teamsContribute to R&D improvements from product security point of view.
Confirm your E-mail: Send Email
All Jobs from Nokia