🌎
This job posting isn't available in all website languages

For Nokia Internal Employee access Log in here

Join us in creating the technology that helps the world act together​

Search jobs

GRC SME - Security Process, Architecture Design & Advisory

📁
Customer Services
💼
CNS Cloud and Network Services
📅
22000009V6 Requisition #

About Cloud & Network Services

 

Cloud and Network Services is a leading Nokia business group that offers Network solutions on Core, Business and Enterprise segments, as well as Cloud solutions and Cognitive Services. It is a newly formed business group, that includes most of the former Nokia Software business, Nokia’s enterprise solutions, core network solutions including both voice and packet core, and managed and advanced services from its former Global Services unit. This unit will also act as a delivery channel of certain products from other business groups to enterprise customers. Cloud and Network Services (CNS) will target growth by leveraging the industry transition to cloud-based delivery, network-as-a-service business models, and software-led value creation.

 

Job Description

Leads, coordinates, communicates, integrates, and is accountable for the overall success of the Security Governance, Risk & Compliance Management Services, with focus on security processes and architecture security design, ensuring alignment with stakeholders. Ensures Security process lifecycle, audit, compliance & risk management, resiliency management, third party security governance, data protection & privacy governance activities are effectively delivered and enhanced for future.

 

Job Responsibilities & Competencies

Main Responsibility Areas:

  • Create and review policy standards and strategies to ensure procedures and guidelines comply with cybersecurity frameworks, standards & industry benchmark.
  • Participate in security governance process to provide security risks, mitigations, and input on other technical risks.
  • Determine the information security approach and operating model in consultation with stakeholders and aligned with the risk management approach and compliance monitoring of risk areas.
  • Assessing security controls and its effectiveness based on cybersecurity principles and tenets. (e.g. NIST CSF, ISO27001, ITU-T x.805, NIST SP 800-53 etc.)
  • Perform risk analysis (e.g., threat, vulnerability, and the probability of occurrence) and apply risk management framework
  • Provide regular reporting of the security program to relevant stakeholders
  • Understand and interact with related disciplines to ensure the consistent application of policies and standards across all Security Governance, Risk & Compliance Management Services.
  • Facilitate security risk, legal and regulatory assessments, including the reporting and oversight of treatment efforts to address negative findings.
  • Perform review & analysis with stakeholders to help establish the lessons learnt, create & update new/existing processes & procedures to mature the Security Governance, Risk & Compliance Management Services.
  • Support in preparing authorization and assurance documents to confirm that the level of risk is within acceptable limits for each application, system, and network.
  • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.

Develop the Frameworks

  • Facilitate a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitate decisions for appropriate resource allocation, and increase the maturity of the security, and review it with stakeholders
  • Ensure secure architecture and security is built-in by design in security GRC services

Operate the Function

  • Oversee of policy standards and strategies to ensure procedures and guidelines comply with cybersecurity frameworks, standards & industry benchmark
  • Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risks.
  • Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each application, system, and network.
  • Ensure effective delivery for Application Security , Penetration Testing, Secure configuration, Vulnerability Management and Data security projects.
  • Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
  • Continuously validate the organization against policies/guidelines/procedures/regulations/laws to ensure compliance for necessary audit & compliance activities
  • Facilitate security risk, legal and regulatory assessments, including the reporting and oversight of treatment efforts to address negative findings.
  • Perform review & analysis with stakeholders to help establish the lessons learnt, create & update new/existing processes & procedures to mature the Security Governance, Risk & Compliance Management Services.

 

Qualifications

Key Competencies:

  • Ability to develop policy, plans, and strategy in compliance with laws, regulations, policies, and standards in support of organizational cyber activities.
  • Sound knowledge of security risk management and cybersecurity technologies
  • Strong knowledge on Cloud Security driven by AI 
  • Poise and ability to act calmly and competently in high-pressure, high-stress situations
  • Must be a critical thinker, with strong problem-solving skills
  • Experience with contract and vendor negotiations
  • Excellent stakeholder management skills
  • High level of personal integrity, as well as the ability to professionally handle confidential matters and show an appropriate level of judgment and maturity
  • Perform risk analysis (e.g., threat, vulnerability, and the probability of occurrence)
  • Promote awareness of security issues among management
  • Knowledge and understanding of relevant legal and regulatory requirements e.g. Country specific telecom security conditions, CII (Critical Information Infrastructure) regulations etc.
  • Excellent analytical skills, the ability to manage multiple projects under strict timelines, as well as the ability to work well in a demanding, dynamic environment and meet overall objectives
  • Project management skills: financial/budget management, scheduling and resource management
  • Ability to lead and motivate the security team to achieve tactical and strategic goals, even when only "dotted line" reporting lines exist
  • A master of influencing entities and decisions in situations where no formal reporting structures exist, but achieving the desirable outcome is vital
  • Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT as well as those from NIST, including 800-53 and Cybersecurity Framework
  • Knowledge of Vulnerability Management, Penetration Testing principles, Secure configuration and Application Security tools, and techniques.
  • Knowledge of network security architecture concepts and principles (e.g., application of defense-in-depth).
  • Knowledge Management, innovation & skills improvement
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences at various hierarchical levels

Experience & Certification:

  • Minimum 10 years of relevant experience in a combination of Security Governance, Risk & Compliance Management services and operations technology jobs.
  • Professional security management certification is desirable, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM).
  • Proven record on Security Office position is desirable

Imagine creating technology that has the potential to change the world. Working with us, you will have a positive impact on people’s lives and help to overcome some of the world’s most pressing challenges. We act inclusively and respect the uniqueness of people. At Nokia, employment decisions are made regardless of race, colour, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law. Nokia culture welcomes people as their true selves. Come create technology that helps the world act together.

Previous Job Searches

My Profile

Create and manage profiles for future opportunities.

Go to Profile

My Submissions

Track your opportunities.

My Submissions
Life at Nokia
Explore Employee Blogs
We create the technology to connect the world

Stay in touch with us through our social media channels:

Follow us on Facebook
Follow us on LinkedIn
See us on Glassdoor
Follow us on Twitter

Similar Listings

CNS Cloud and Network Services

Lannion, France, France

📁 Customer Services

Requisition #: 21000006VW

CNS Cloud and Network Services

Lannion, France, France

📁 Customer Services

Requisition #: 21000006VJ

CNS Cloud and Network Services

Lannion, France, France

📁 Customer Services

Requisition #: 210000020P

Teams at Nokia

See all jobs

Research and Development

See new jobs

Market and Sales development

See new jobs

Corporate services

See new jobs
Nokia is an equal opportunity employer that is committed to diversity and inclusion. At Nokia, employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law.