The Vulnerability Assessment Engineer is responsible for identifying, analyzing, and reporting security vulnerabilities across the organization's IT infrastructure, with a specific focus on integrating and securing new servers during their onboarding and commissioning phases using industry-leading tools like Qualys or Tenable.The Vulnerability Assessment Engineer is responsible for identifying, analyzing, and reporting security vulnerabilities across the organization's IT infrastructure, with a specific focus on integrating and securing new servers during their onboarding and commissioning phases using industry-leading tools like Qualys or Tenable.
Responsibilities- Execute regular and ad-hoc vulnerability scans across the enterprise network, applications, and systems using Qualys Vulnerability Management (VMDR) or Tenable.io/Nessus.
- Analyze scan results, prioritize vulnerabilities based on risk, and provide detailed reports to relevant stakeholders.
- Actively participate in the server commissioning process, ensuring all new servers are integrated into the vulnerability management program from day one.
- Perform initial baseline vulnerability assessments on newly provisioned servers before they enter production, identifying and reporting critical security gaps.
- Collaborate with server administrators and project teams to ensure identified vulnerabilities on new servers are remediated or mitigated according to security policies and timelines.
- Verify the secure configuration of new servers against established security baselines and compliance requirements.
- Work closely with IT operations, development, and system owners to facilitate the remediation of identified vulnerabilities.
- Track remediation efforts and re-scan systems to confirm the effectiveness of applied patches and configuration changes.
- Maintain, configure, and optimize vulnerability scanning platforms (Qualys or Tenable) to ensure accurate and comprehensive coverage.
- Develop and refine scanning policies, profiles, and reporting templates.
- Generate comprehensive vulnerability reports, dashboards, and metrics for various audiences, including technical teams and management.
- Maintain accurate documentation of vulnerability assessment processes, findings, and remediation activities.
Must-Have:
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.
- Up to 10-14 years of experience in cybersecurity, with a strong focus on vulnerability management or security operations.
- Demonstrable hands-on experience with either Qualys (VMDR, Cloud Agent) or Tenable (Nessus, Tenable.io, Security Center) platforms.
- Solid understanding of network protocols, operating systems (Windows, Linux), and common enterprise applications.
- Familiarity with security frameworks and standards (e.g., NIST, ISO 27001, CIS Benchmarks).
Nice-to-Have:
- Strong analytical and problem-solving skills, with attention to detail.
- Excellent written and verbal communication skills, capable of explaining complex technical issues to both technical and non-technical audiences.
- Ability to prioritize tasks, manage multiple projects, and work effectively in a fast-paced environment.
- Scripting skills (e.g., Python, PowerShell) for automation and data analysis are a plus.
Nokia is a global leader in connectivity for the AI era. With expertise across fixed, mobile and transport networks, powered by the innovation of Nokia Bell Labs, we’re advancing connectivity to secure a brighter world.
Our recruitment process
We act inclusively and respect the uniqueness of people. Our employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law. We are committed to a culture of inclusion built upon our core value of respect.
If you’re interested in this role but don’t meet every listed requirement, we still encourage you to apply. Unique backgrounds, perspectives, and experiences enrich our teams, and you may be just the right candidate for this or another opportunity.
The length of the recruitment process may vary depending on the specific role's requirements. We strive to ensure a smooth and inclusive experience for all candidates. Discover more about the recruitment process at Nokia.
- Flexible and hybrid working schemes
- A minimum of 90 days of Maternity and Paternity Leave, with the option to return to work within a year following the birth or adoption of a child (based on eligibility)
- Life insurance to all employees to provide peace of mind and financial security
- Well-being programs to support your mental and physical health
- Opportunities to join and receive support from Nokia Employee Resource Groups (NERGs)
- Employee Growth Solutions to support your personalized career & skills development
- Diverse pool of Coaches & Mentors to whom you have easy access
- A learning environment which promotes personal growth and professional development - for your role and beyond
Skills Required
- 9+ years in Offensive Security/Red Teaming within Telecommunications or ISP environments
- OSCP certification (minimum)
- Expert knowledge of the MITRE ATT&CK framework and NIST security standards
- Proficiency in Kerberoasting, Pass-the-Hash, Golden Ticket techniques
- PowerShell and Bash scripting proficiency and EDR bypass experience
- Foundational knowledge of SS7, GTP, Diameter, Network Segmentation, Active Directory, and NOC/SOC workflows
- Hands-on experience with Burp Suite, Cobalt Strike/Sliver, Metasploit, Nessus, and ASM platforms
- Ability to create custom C2 channels and bypass Antivirus/WAF to demonstrate adversary capability
- Experience conducting telecom-specific attacks against OSS/BSS, HLR/VLR, MSC to assess subscriber data and call routing risks
- Advanced Offensive Certifications (OSEP, OSWE, CRTP)
- Expertise in automated tools and manual deep-web search techniques for reconnaissance
- Experience coordinating telecom knowledge with quarterly telecom exercises
Nokia Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Nokia and has not been reviewed or approved by Nokia.
-
Equity Value & Accessibility — Equity programs include a global employee share purchase plan with company matching and multi‑year share awards. These mechanisms broaden participation and tie rewards to long‑term outcomes.
-
Healthcare Strength — Health coverage includes major medical plans with supplementary options such as vision, legal services, and care navigation. The range of offerings indicates comprehensive support for medical needs.
-
Parental & Family Support — A global policy grants paid leave for new parents regardless of gender and provides structured return‑to‑work support. Company‑paid life insurance further strengthens family protection across regions.
Nokia Insights
What We Do
At Nokia, we create technology that helps the world act together. As a trusted partner for critical networks, we are committed to innovation and technology leadership across mobile, fixed and cloud networks. We create value with intellectual property and long-term research, led by the award-winning Nokia Bell Labs. Adhering to the highest standards of integrity and security, we help build the capabilities needed for a more productive, sustainable and inclusive world.








