Product Security Specialist

Posted Yesterday
Be an Early Applicant
2 Locations
Remote or Hybrid
Senior level
Software
The Role
Drive product security across cloud-native products through threat modeling, secure design reviews, vulnerability management, security testing, and DevSecOps automation. Secure Kubernetes, containers, APIs, IAM, and microservices; prioritize remediation and compliance activities; and collaborate with engineering and architecture teams. Support telecom security for distributed observability platforms and serve as Scrum Master for a SAFe agile team.
Summary Generated by Built In

We are looking for an experienced Product Security Specialist with 8+ years of experience in securing cloud-native applications and platforms. The role is responsible for driving product security through threat modeling, secure design reviews, vulnerability management, security testing, and DevSecOps practices. The ideal candidate should have expertise in Kubernetes, container security, API security, IAM, OWASP, CVE/CVSS management, and security compliance frameworks. Exposure to OAM/FCAPS, 4G/5G Core Networks and telecom security is desirable. The specialist will collaborate with Engineering, Architecture, Product Security Managers to identify risks, drive remediation, strengthen the product security posture, and ensure compliance with customer and industry security requirements.

Responsibilities
  • Drive product security across the entire product lifecycle, including both active development and maintenance releases in production, through threat modeling, secure design reviews, risk assessments, and security-by-design practices.
  • Define, propose, and drive adoption of product security requirements, standards, and controls aligned with customer expectations, industry frameworks, and emerging threat landscapes.
  • Identify security gaps and continuously improve the product security posture by leveraging AI-powered security scanning, code analysis, vulnerability discovery, risk prioritization, and security insights. Lead vulnerability management activities, including CVE/CVSS assessment, security advisories, remediation planning, root cause analysis, and closure of security findings across released and in-development products.
  • Design, review, and strengthen security controls for Kubernetes, containers, APIs, IAM, and cloud-native microservices architectures, ensuring adherence to OWASP and secure coding best practices.
  • Integrate and automate security testing, monitoring, and compliance validation within DevSecOps and CI/CD pipelines, including SAST, DAST, container, dependency, and configuration scanning. Collaborate with Engineering, Architecture, and Product Security teams to assess risks, prioritize mitigations, support compliance initiatives, and enhance telecom product security.
  • In the extended role as a Scrum Master of a SAFe agile team, you'll help the team to plan and execute in delivering the team's objectives as per the committments.
Qualifications

You Have:

  • Engineering degree with 8+ years of relevant experience. Strong expertise in Product Security and the Secure Software Development Lifecycle (SSDLC), including threat modeling, secure architecture and design reviews, risk assessments, threat analysis, and security-by-design practices for cloud-native products.
  • Hands-on experience securing Kubernetes, OpenShift, containers, microservices, APIs, service mesh, IAM/RBAC, secrets management, and cloud-native platforms.
  • Strong knowledge of Application Security and DevSecOps, including OWASP Top 10, secure coding practices, SAST, DAST, SCA, container security, dependency scanning, Infrastructure as Code (IaC) security, and CI/CD security automation.
  • Proven experience in vulnerability management, including CVE/CVSS assessment, security advisories, remediation planning, risk prioritization, root cause analysis, and closure of security findings across products in development and production.
  • Experience securing large-scale distributed data, observability, and telemetry platforms leveraging technologies such as Kafka, ClickHouse, VictoriaMetrics, MariaDB, OpenTelemetry, OTLP, and microservices-based architectures.
  • Strong understanding of authentication, authorization, PKI, encryption, certificate management, API security, network security, zero-trust architecture, and security compliance frameworks. Knowledge of telecom security, OAM/FCAPS, 4G/5G Core Networks, SNMP, and 3GPP security standards for carrier-grade network management and observability solutions.
  • Proven ability to drive product security strategy, collaborate with engineering and architecture teams, leverage AI-powered security analysis and automation tools, and support compliance with customer, regulatory, and industry security requirements.

Nice to Have:

  • Professional certifications such as Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, CSSLP, GIAC (GSEC/GPEN/GCSA), or equivalent security certifications.
  • Prior experience as a Scrum Master.

Skills Required

  • Engineering degree
  • 8+ years of relevant product security experience
  • Experience with secure software development lifecycle, threat modeling, secure architecture and design reviews, risk assessments, and security-by-design practices
  • Hands-on experience securing Kubernetes, OpenShift, containers, microservices, APIs, service mesh, IAM/RBAC, secrets management, and cloud-native platforms
  • Strong application security and DevSecOps knowledge, including OWASP Top 10, secure coding, SAST, DAST, SCA, dependency scanning, container security, IaC security, and CI/CD automation
  • Vulnerability management experience, including CVE/CVSS assessment, security advisories, remediation planning, risk prioritization, root cause analysis, and closure of findings
  • Experience securing distributed data, observability, and telemetry platforms using Kafka, ClickHouse, VictoriaMetrics, MariaDB, OpenTelemetry, OTLP, and microservices
  • Understanding of authentication, authorization, PKI, encryption, certificate management, API security, network security, zero-trust architecture, and security compliance frameworks
  • Knowledge of telecom security, OAM/FCAPS, 4G/5G Core Networks, SNMP, and 3GPP security standards
  • Professional security certifications such as CKS, CISSP, CCSP, CSSLP, or GIAC certifications
  • Prior experience as a Scrum Master

Nokia Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Nokia and has not been reviewed or approved by Nokia.

  • Equity Value & Accessibility Equity programs include a global employee share purchase plan with company matching and multi‑year share awards. These mechanisms broaden participation and tie rewards to long‑term outcomes.
  • Healthcare Strength Health coverage includes major medical plans with supplementary options such as vision, legal services, and care navigation. The range of offerings indicates comprehensive support for medical needs.
  • Parental & Family Support A global policy grants paid leave for new parents regardless of gender and provides structured return‑to‑work support. Company‑paid life insurance further strengthens family protection across regions.

Nokia Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Espoo
132,624 Employees

What We Do

At Nokia, we create technology that helps the world act together. As a trusted partner for critical networks, we are committed to innovation and technology leadership across mobile, fixed and cloud networks. We create value with intellectual property and long-term research, led by the award-winning Nokia Bell Labs. Adhering to the highest standards of integrity and security, we help build the capabilities needed for a more productive, sustainable and inclusive world.

Similar Jobs

Atlassian Logo Atlassian

Principal Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Atlassian Logo Atlassian

Software Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Atlassian Logo Atlassian

Principal Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Bengaluru, Bengaluru Urban, Karnataka, IND
11000 Employees

Comcast Logo Comcast

Test Engineer

Digital Media • Information Technology • News + Entertainment
Remote or Hybrid
India
115000 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account