386,695open jobs
10,101companies
50,443added this week
Browse all
Location
In office
Seniority
Staff · 8+ years exp
Overview
Company
Impact
Profile match
Nokia is a Finnish telecommunications equipment company founded in 1865 as a paper mill, which became the world's largest mobile phone maker in the 1990s before selling that business to Microsoft in 2014. It now supplies network infrastructure to operators and enterprises, covering radio access equipment for mobile networks, optical and IP routing for transport networks, fixed broadband access, and a technologies division that licenses its cellular patent portfolio. Headquartered in Espoo and listed in Helsinki and New York, it runs Nokia Bell Labs as its research arm and has been expanding into data centre networking as operator spending has slowed.

We are looking for an experienced Product Security Specialist with 8+ years of experience in securing cloud-native applications and platforms. The role is responsible for driving product security through threat modeling, secure design reviews, vulnerability management, security testing, and DevSecOps practices. The ideal candidate should have expertise in Kubernetes, container security, API security, IAM, OWASP, CVE/CVSS management, and security compliance frameworks. Exposure to OAM/FCAPS, 4G/5G Core Networks and telecom security is desirable. The specialist will collaborate with Engineering, Architecture, Product Security Managers to identify risks, drive remediation, strengthen the product security posture, and ensure compliance with customer and industry security requirements.

  • Drive product security across the entire product lifecycle, including both active development and maintenance releases in production, through threat modeling, secure design reviews, risk assessments, and security-by-design practices.
  • Define, propose, and drive adoption of product security requirements, standards, and controls aligned with customer expectations, industry frameworks, and emerging threat landscapes.
  • Identify security gaps and continuously improve the product security posture by leveraging AI-powered security scanning, code analysis, vulnerability discovery, risk prioritization, and security insights. Lead vulnerability management activities, including CVE/CVSS assessment, security advisories, remediation planning, root cause analysis, and closure of security findings across released and in-development products.
  • Design, review, and strengthen security controls for Kubernetes, containers, APIs, IAM, and cloud-native microservices architectures, ensuring adherence to OWASP and secure coding best practices.
  • Integrate and automate security testing, monitoring, and compliance validation within DevSecOps and CI/CD pipelines, including SAST, DAST, container, dependency, and configuration scanning. Collaborate with Engineering, Architecture, and Product Security teams to assess risks, prioritize mitigations, support compliance initiatives, and enhance telecom product security.
  • In the extended role as a Scrum Master of a SAFe agile team, you'll help the team to plan and execute in delivering the team's objectives as per the committments.

You Have:

  • Engineering degree with 8+ years of relevant experience. Strong expertise in Product Security and the Secure Software Development Lifecycle (SSDLC), including threat modeling, secure architecture and design reviews, risk assessments, threat analysis, and security-by-design practices for cloud-native products.
  • Hands-on experience securing Kubernetes, OpenShift, containers, microservices, APIs, service mesh, IAM/RBAC, secrets management, and cloud-native platforms.
  • Strong knowledge of Application Security and DevSecOps, including OWASP Top 10, secure coding practices, SAST, DAST, SCA, container security, dependency scanning, Infrastructure as Code (IaC) security, and CI/CD security automation.
  • Proven experience in vulnerability management, including CVE/CVSS assessment, security advisories, remediation planning, risk prioritization, root cause analysis, and closure of security findings across products in development and production.
  • Experience securing large-scale distributed data, observability, and telemetry platforms leveraging technologies such as Kafka, ClickHouse, VictoriaMetrics, MariaDB, OpenTelemetry, OTLP, and microservices-based architectures.
  • Strong understanding of authentication, authorization, PKI, encryption, certificate management, API security, network security, zero-trust architecture, and security compliance frameworks. Knowledge of telecom security, OAM/FCAPS, 4G/5G Core Networks, SNMP, and 3GPP security standards for carrier-grade network management and observability solutions.
  • Proven ability to drive product security strategy, collaborate with engineering and architecture teams, leverage AI-powered security analysis and automation tools, and support compliance with customer, regulatory, and industry security requirements.

Nice to Have:

  • Professional certifications such as Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, CSSLP, GIAC (GSEC/GPEN/GCSA), or equivalent security certifications.
  • Prior experience as a Scrum Master.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
386,695 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$52k – $111k per year (Estimated) • In office • Full-Time • 5+ years exp • Paris
Python
AI/ML
LLM
DevOps
Ansible
AWS
Azure
CI/CD
Docker
GCP
GitLab
GitLab CI
Jenkins
Kubernetes
Terraform
Apply
$81k – $183k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Basel
Java
Kotlin
Python
SQL
Databases
PostgreSQL
DevOps
AWS
CI/CD
Docker
Kubernetes
Rest API
Apply
$191k – $397k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Tel Aviv • Yokneam
AI/ML
CUDA
CUDA Toolkit
NCCL
DevOps
Kubernetes
Apply
$99k – $132k per year • In office • Full-Time • Heilbronn
SQL
DevOps
Azure
Grafana
Kubernetes
Prometheus
Apply
$56k – $120k per year • In office • Full-Time • 1+ year exp • Master's Degree • Toronto
Python
AI/ML
Amazon SageMaker
NumPy
Pandas
PyTorch
Scikit-learn
TensorFlow
DevOps
Amazon CloudWatch
Amazon S3
API Gateway
AWS
AWS Lambda
CI/CD
Git
IAM
Apply
In office • 8+ years exp
Go
Databases
Apache Kafka
ClickHouse
Kafka
MariaDB
AI/ML
AI Agents
Anomaly Detection
DevOps
CI/CD
Helm
Jenkins
Kubernetes
OpenShift
OpenTelemetry
VictoriaMetrics
Analytics
ETL/ELT
Apply
In office • 5+ years exp
Java
Python
Databases
Apache Kafka
Kafka
DevOps
CI/CD
Git
Helm
Jenkins
Kubernetes
OpenShift
Analytics
ETL/ELT
Apply
In office • 5+ years exp
Databases
Apache Kafka
Kafka
DevOps
AIOps
CI/CD
Helm
Jenkins
Kubernetes
OpenShift
OpenTelemetry
Rest API
VictoriaMetrics
Apply
In office • 8+ years exp
Databases
Apache Kafka
Kafka
AI/ML
AI Agents
DevOps
CI/CD
Kubernetes
OpenShift
Apply
In office • 12+ years exp
C++
Python
AI/ML
AI Agents
DevOps
CI/CD
Docker
Envoy
gRPC
Helm
Kubernetes
Apply
See all jobs
This is one of many
386,695 more open roles from verified company boards, updated every day.