Nokia Logo

Nokia

Security Operations Specialist

Posted Yesterday
Be an Early Applicant
In-Office or Remote
Hiring Remotely in India
Expert/Leader
In-Office or Remote
Hiring Remotely in India
Expert/Leader
Lead offensive security activities including vulnerability management, deep-dive penetration testing (infrastructure, web, mobile), red teaming/assume-breach simulations, telecom-targeted attacks, APT simulation using MITRE ATT&CK, attack surface and dark-web monitoring, and producing PoCs and remediation roadmaps while mentoring Blue Team members.
The summary above was generated by AI

As a Security Operations Specialist, you will monitor and maintain security operations, ensuring alignment with regulatory requirements and business policies. You will actively contribute to improving the organizational security posture and support continuous compliance efforts. This role involves implementing robust security controls to safeguard systems and data. Furthermore, you will be responsible for responding effectively to security incidents within established frameworks.

Responsibilities
  • Vulnerability Management: Conduct continuous asset discovery, automated vulnerability scanning, false positive analysis, and manage the closure and re-testing of identified vulnerabilities.
  • Penetration Testing: Perform deep-dive infrastructure, web, mobile application (DAST/manual, OWASP Top 10, OMTG), and segmentation penetration testing.
  • Red Teaming & Adversary Simulation: Lead "Assume Breach" simulations, execute complex attack chains (lateral movement, privilege escalation), and develop evasion techniques against security controls.
  • Telecom Core Targeting: Conduct specialized attacks against critical telecom systems (OSS/BSS, HLR, VLR, MSC) to identify risks to subscriber data and call routing.
  • APT Simulation: Replicate real-world adversary Tactics, Techniques, and Procedures (TTPs) using the MITRE ATT&CK framework.
  • Attack Surface Management (ASM): Monitor for "Shadow IT" and exposed digital assets through automated black-box reconnaissance and risk prioritization.
  • Dark Web Monitoring: Proactively monitor dark web forums, paste-sites, and messaging channels for leaked telecom-specific data and credentials.
  • Reporting & Mentorship: Evaluate Blue Team performance during exercises, and produce high-quality Proof-of-Concepts (PoCs) and remediation roadmaps for technical and executive stakeholders.
Qualifications

Must-Have:

  • A minimum of 9+ years in Offensive Security/Red Teaming, specifically within a Telecommunications or ISP environment.
  • This is explicitly stated as a minimum required certification is OSCP Certification.
  • Expert MITRE ATT&CK Framework understanding and applying adversary tactics, techniques, and procedures.
  • Advanced Exploitation Techniques proficiency in methods such as Kerberoasting, Pass-the-Hash, Golden Ticket, PowerShell/Bash scripting, and EDR bypass.
  • Foundational Telecom Protocol understanding of SS7, GTP, and Diameter, which is critical for the specified environment.

Nice-To-Have:

  • Advanced Certifications (OSEP, OSWE, or CRTP): While OSCP is a minimum, possessing one of these advanced certifications demonstrates a higher level of specialized expertise.
  • NIST Security Standards Knowledge: Beyond the expert knowledge of MITRE ATT&CK, familiarity with NIST security standards would be a valuable complementary skill.
  • Deep Understanding of NOC/SOC Workflows: While a deep understanding of Network Segmentation and Active Directory is listed, specific insight into NOC/SOC workflows would be beneficial for red teamers to understand blue team operations and evasion techniques.
About Us
Advancing connectivity to secure a brighter world.

Nokia is a global leader in connectivity for the AI era. With expertise across fixed, mobile and transport networks, powered by the innovation of Nokia Bell Labs, we’re advancing connectivity to secure a brighter world. 

Learn more about life at Nokia.


Our recruitment process

We act inclusively and respect the uniqueness of people. Our employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law. We are committed to a culture of inclusion built upon our core value of respect.

If you’re interested in this role but don’t meet every listed requirement, we still encourage you to apply. Unique backgrounds, perspectives, and experiences enrich our teams, and you may be just the right candidate for this or another opportunity.

The length of the recruitment process may vary depending on the specific role's requirements. We strive to ensure a smooth and inclusive experience for all candidates. Discover more about the recruitment process at Nokia. 

About the Team
Some of our benefits:
  • Flexible and hybrid working schemes
  • A minimum of 90 days of Maternity and Paternity Leave, with the option to return to work within a year following the birth or adoption of a child (based on eligibility)
  • Life insurance to all employees to provide peace of mind and financial security
  • Well-being programs to support your mental and physical health
  • Opportunities to join and receive support from Nokia Employee Resource Groups (NERGs)
  • Employee Growth Solutions to support your personalized career & skills development
  • Diverse pool of Coaches & Mentors to whom you have easy access
  • A learning environment which promotes personal growth and professional development - for your role and beyond

Learn about additional benefits in specific countries.

Similar Jobs

Yesterday
In-Office or Remote
India
Senior level
Senior level
Blockchain • Fintech • Software • Cryptocurrency • Metaverse
Analyze complex Web3 security incidents, extract attack patterns, and maintain SOPs. Identify workflow gaps and improve operations, partner with AI agents to build a security knowledge base, and convert manual analyses into automated detection rules while staying ahead of emerging DeFi and wallet exploit techniques.
Top Skills: Ai AgentsAi ToolsBlockchainDefiWalletsWeb3
Yesterday
In-Office or Remote
India
Expert/Leader
Expert/Leader
Software
Lead and align MSS with telecom cybersecurity strategy; implement GRC and risk frameworks; manage risk registers, audits, and incident response; ensure compliance with ISO 27001, NIST CSF, GDPR and communicate risk to executives and customers.
Top Skills: 5GEncryptionFirewallsGdprGrc ToolsIotIso 27001Iso 31000Managed Security Services (Mss)MplsNfvNist CsfNist RmfSdnSIEM
2 Hours Ago
Remote or Hybrid
India
Senior level
Senior level
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Lead business analysis for Risk Weighted Assets (RWA) and Counterparty Credit Risk (CCR) initiatives. Translate Basel III/IV and SA-CCR/IMM/EAD regulatory requirements into BRDs, FRDs, user stories, process flows and data mappings. Liaise with Market Risk, CCR, Regulatory Reporting, Finance, Quant and Technology teams to support capital calculations, RWA optimization and regulatory reporting for transformation programs.

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account