Product Security Specialist
Nokia · India
About The Role
We are looking for an experienced Product Security Specialist with 8+ years of experience in securing cloud-native applications and platforms. The role is responsible for driving product security through threat modeling, secure design reviews, vulnerability management, security testing, and DevSecOps practices. The ideal candidate should have expertise in Kubernetes, container security, API security, IAM, OWASP, CVE/CVSS management, and security compliance frameworks. Exposure to OAM/FCAPS, 4G/5G Core Networks and telecom security is desirable. The specialist will collaborate with Engineering, Architecture, Product Security Managers to identify risks, drive remediation, strengthen the product security posture, and ensure compliance with customer and industry security requirements.
- Drive product security across the entire product lifecycle, including both active development and maintenance releases in production, through threat modeling, secure design reviews, risk assessments, and security-by-design practices.
- Define, propose, and drive adoption of product security requirements, standards, and controls aligned with customer expectations, industry frameworks, and emerging threat landscapes.
- Identify security gaps and continuously improve the product security posture by leveraging AI-powered security scanning, code analysis, vulnerability discovery, risk prioritization, and security insights. Lead vulnerability management activities, including CVE/CVSS assessment, security advisories, remediation planning, root cause analysis, and closure of security findings across released and in-development products.
- Design, review, and strengthen security controls for Kubernetes, containers, APIs, IAM, and cloud-native microservices architectures, ensuring adherence to OWASP and secure coding best practices.
- Integrate and automate security testing, monitoring, and compliance validation within DevSecOps and CI/CD pipelines, including SAST, DAST, container, dependency, and configuration scanning. Collaborate with Engineering, Architecture, and Product Security teams to assess risks, prioritize mitigations, support compliance initiatives, and enhance telecom product security.
- In the extended role as a Scrum Master of a SAFe agile team, you'll help the team to plan and execute in delivering the team's objectives as per the committments.
You Have
- Engineering degree with 8+ years of relevant experience. Strong expertise in Product Security and the Secure Software Development Lifecycle (SSDLC), including threat modeling, secure architecture and design reviews, risk assessments, threat analysis, and security-by-design practices for cloud-native products.
- Hands-on experience securing Kubernetes, OpenShift, containers, microservices, APIs, service mesh, IAM/RBAC, secrets management, and cloud-native platforms.
- Strong knowledge of Application Security and DevSecOps, including OWASP Top 10, secure coding practices, SAST, DAST, SCA, container security, dependency scanning, Infrastructure as Code (IaC) security, and CI/CD security automation.
- Proven experience in vulnerability management, including CVE/CVSS assessment, security advisories, remediation planning, risk prioritization, root cause analysis, and closure of security findings across products in development and production.
- Experience securing large-scale distributed data, observability, and telemetry platforms leveraging technologies such as Kafka, ClickHouse, VictoriaMetrics, MariaDB, OpenTelemetry, OTLP, and microservices-based architectures.
- Strong understanding of authentication, authorization, PKI, encryption, certificate management, API security, network security, zero-trust architecture, and security compliance frameworks. Knowledge of telecom security, OAM/FCAPS, 4G/5G Core Networks, SNMP, and 3GPP security standards for carrier-grade network management and observability solutions.
- Proven ability to drive product security strategy, collaborate with engineering and architecture teams, leverage AI-powered security analysis and automation tools, and support compliance with customer, regulatory, and industry security requirements.
Nice to Have
- Professional certifications such as Certified Kubernetes Security Specialist (CKS), CISSP, CCSP, CSSLP, GIAC (GSEC/GPEN/GCSA), or equivalent security certifications.
- Prior experience as a Scrum Master.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
