Act as a Subject Matter Expert (SME) on security & privacy regional regulations, including CSL, EU-CRA, RED, NIS2, UK-TSR, ITSAR, and emerging regulations
Coordinate with NI Market Organizations and Business Centers to understand customers’ demands for improved product & services security, support assessment and impact analysis of new regional security & privacy regulations.
Coordinate cross team with NI Privacy Lead.
Assist in negotiation of security clauses in supply-contracts and statements of work (SoW) for services projects with customers and customer security teams.
Coordinate with Customer Security organization to perform gap and impact analysis for regulatory and contractual requirements for compliance with security and privacy requirements impacting NI products or services.
Assist in the coordination of reporting of high-profile vulnerabilities related to NI products to customers.
Provide NI BG support for customer requests for audits and assessments and co-ordinate the necessary activities in Nokia.
Requirements
Bachelor’s degree in computer science or related degree
5+ years of experience in product security compliance roles with technical proficiency with secure product development skills
Experience applying security engineering in an agile development environment
Experience providing security assurance support to engineering and product management teams
Ability to analyze and solve complex problems while enhancing team learning environment with coaching and mentoring
Strong oral and written communication skills, including customer facing interactions.
Demonstrated ability to work and collaborate within globally distributed development teams, as well as externally with Nokia service provider customers.
Knowledge and experience with Nokia DFSEC Compliance Tool and Nokia Vulnerability Assessment and Management System tools
Exposure to globally recognized security certifications, such as Common Criteria, GSMA NESAS, FIPS, NIST.
Knowledge of security requirements for cloud native and containerized products
Knowledge and Experience in the implementation and management of FOSS software components through their lifecycle.
Knowledge of securing web applications, mobile applications and network elements
(ISC)2 Certified Information Systems Security Professional (CISSP)
problem solvingcoachingmentoringoral communicationwritten communicationcollaborationteamworkcustomer interactionanalysiscoordination
Certifications
(ISC)2 Certified Information Systems Security Professional (CISSP)EC-Council Certified Application Security Engineer (CASE)Common CriteriaGSMA NESASFIPSNIST