
Security Architect
- Amadora, Lisboa
- Permanente
- Horário completo
- Identify & understand Nokia's threat landscape and main security risks using several Threat Intelligence Sources as well as support various IT & Business Digitalization Programs
- Define the target security solution architecture and corresponding security architecture requirements remediating the identified threats, vulnerabilities, and security risks.
- Technically define, test & validate security controls integrated into IT & Business Digitalization Programs
- Technically assess & vet (new) Nokia Solution Offerings (CNS SaaS, NDAC, RXRM, AIMS,…) and provide recommendation on how to effectively further harden these solutions.
- Support various Nokia IT & BG teams in advising on security best practices to ensure that Nokia's critical assets & data always remain fully protected & secure (support in new supplier contract negotiations, support on merger & acquisitions activities, etc…).
- Act as Trusted Security Advisor towards your peers and other Nokia stakeholders in S&T, BG's and other central functions across various security domains (Zero Trust Network Architecture, evolution to IPv6, IAM, secure Network & Application Segmentation, cloud & network security, application security, AI technologies, Software Security, Security Automation, Data Security, BC/DR & Cyber Resiliency, malicious attack types & penetration testing techniques…)
- Detect security flaws in existing digital solutions and provide recommendations on how to overcome these findings in a secure and cost-efficient manner by performing pro-active security architecture assessments and by staying abreast of new attack tactics and techniques.
- Define & introduce new innovative security solutions into Nokia's Corporate Infrastructure. This effort encompasses activities like strategic solution thinking, solution budgeting, solution presentations, solution design, solution testing & validation, solution delivery.
- Three to five years of security architecture experience, including auditing, security compliance testing, project risk management, security, or other internal controls.
- Solid & demonstrated experience in organizing teams, establishing priorities, and leading IT- & Business-related security projects.
- Able to work independently as well as in a team in a fast-paced environment and with demonstrated track record for completing work in a timely and organized fashion.
- Able to facilitate good stakeholder management in business or IT projects is a must, including outstanding written, verbal, and oral communication skills.
- Solid knowledge of current and future (information) security technologies, including business processes, data, applications, and network and systems infrastructure.
- This role acts in a transformational environment from traditional IT to digital cloud-based. Developments, in a variety of DevOps & agile structures. In depth understanding of these technologies and development methodologies is essential
- Experience in the design, implementation, and administration of multi-cloud security testing environments such as Azure, GCP, and/or AWS
- Capable of modeling threats & risks using standard frameworks (MITRE, STRIDE, Kill-Chain,…)
- Being familiar with NIST standards and other relevant security frameworks
- Good scripting knowledge (such as Java, C, python, PowerShell, Ansible)
- Relevant security certifications (CISSP, CISM, CEH, GPEN, OSCP) are considered as a plus.
- Passionate about technology and information security
- Strong and creative problem-solving abilities
- Highly self-motivated and self-directed
- Comfortable in fast-paced, ever-changing environments with ability to successfully translate diverse and complex ambiguities into actionable plans
- A team player - even when working in a virtual team - with a strong customer focus
- Ability to effectively prioritize and execute tasks in a high-pressure environment.
- Be convincing - including when working with remote teams
- Pro-Active - don't await taking action when identifying a security need
We challenge ourselves to create an inclusive way of working where we are open to new ideas, empowered to take risks and fearless to bring our authentic selves to workWhat we offerNokia offers continuous learning opportunities, well-being programs to support you mentally and physically, opportunities to join and get supported by employee resource groups, mentoring programs and highly diverse teams with an inclusive culture where people thrive and are empowered.Nokia is committed to inclusion and is an equal opportunity employerNokia has received the following recognitions for its commitment to inclusion & equality:
- One of the World's Most Ethical Companies by Ethisphere
- Gender-Equality Index by Bloomberg
- Workplace Pride Global Benchmark
We are committed to a culture of inclusion built upon our core value of respect.Join us and be part of a company where you will feel included and empowered to succeed.About the Team: Strategy and Technology lays the path for Nokia's future technology innovation and identifies the most promising areas for Nokia to create new value. We set the company's strategy and technology vision, offer an unparalleled research foundation for innovation, and provide critical support infrastructure for Nokia.