Nokia Logo

Nokia

Technical Compliance Specialist

Posted 28 Days Ago
In-Office or Remote
Hiring Remotely in United States
Entry level
In-Office or Remote
Hiring Remotely in United States
Entry level
Provides technical cybersecurity compliance and risk assessment support for product vulnerabilities, CVEs, security incidents, and remediation activities. Evaluates customer and regulatory impact, supports National Security Agreement reviews, assists with government notifications and audits, and maintains technical compliance documentation. Acts as a liaison between Product Security, Engineering, Vulnerability Management, and the National Security Office while translating complex technical information into actionable business and regulatory assessments.
The summary above was generated by AI

The Technical Compliance Specialist serves as a member of Nokia's National Security Office (NSO) and provides technical analysis, compliance support, and regulatory assessment capabilities related to product security vulnerabilities, cybersecurity incidents, and technical risk matters affecting Nokia's U.S. operations.

Working closely with Product Security, Engineering, Vulnerability Management, and the National Security Office, the role assists in evaluating security vulnerabilities, understanding potential customer impacts, assessing remediation activities, and supporting the NSA Security Officer in determining whether security-related matters warrant further compliance review or potential notification to U.S. Government stakeholders.

The role acts as a bridge between technical organizations and regulatory compliance functions by transforming complex technical information into actionable compliance and business risk assessments.

Responsibilities

Product Security Analysis

  • Review significant product security vulnerabilities, CVEs, security advisories, and cybersecurity incidents affecting Nokia products and services.
  • Analyze vulnerability severity, exploitability, affected products, remediation plans, and potential customer impact.
  • Evaluate technical risks associated with vulnerabilities affecting U.S. telecommunications customers and critical infrastructure.
  • Monitor emerging cybersecurity threats and vulnerability trends relevant to Nokia products.

Regulatory Impact Assessments

  • Assist the NSA Security Officer in evaluating the regulatory significance of product security vulnerabilities and cybersecurity incidents.
  • Assess potential implications to Nokia's obligations under the U.S. National Security Agreement.
  • Support reviews to determine whether incidents or vulnerabilities may warrant escalation, regulatory review, or government notification.
  • Develop risk-based assessments supporting regulatory decision-making.

Product Security Liaison Activities

  • Work closely with Product Security personnel to understand vulnerability investigations, security findings, and remediation activities.
  • Facilitate information exchange between Product Security organizations and NSO leadership.
  • Support vulnerability governance reviews and related compliance activities.
  • Assist with tracking significant remediation activities and corrective actions.

Technical Compliance Documentation

  • Support maintenance of the NSA Technical Compliance Manual and associated technical compliance procedures.
  • Prepare technical summaries, security assessments, compliance analyses, and executive briefing materials.
  • Maintain records supporting vulnerability reviews and regulatory assessments.
  • Assist with development of technical compliance guidance and reference materials.

Audit & Compliance Support

  • Support third-party audit activities involving product security, vulnerability management, and technical compliance requirements.
  • Assist in gathering technical evidence and documentation required for audits and regulatory reviews.
  • Support responses to government inquiries involving product security matters.
  • Contribute to the continuous improvement of technical compliance and governance processes.
Qualifications

Knowledge & Experience

  • Understanding of product security, cybersecurity, vulnerability management, and security risk assessment concepts.
  • Ability to evaluate technical security information and communicate business and regulatory implications.
  • Experience working with Product Security, Engineering, Information Security, Vulnerability Management, or related technical functions.
  • Familiarity with compliance, audit, governance, or regulatory oversight activities.
  • Strong analytical, organizational, writing, and communication skills.
  • Experience within telecommunications, software development, cybersecurity, or highly regulated environments preferred.

Similar Jobs

12 Days Ago
Remote
United States
Senior level
Senior level
Other
Owns technical execution of government compliance programs, including FedRAMP Moderate, FedRAMP 20x, TX-RAMP, IRAP, and GovRAMP. Responsibilities include continuous monitoring, SSP and SDR documentation, POA&M and remediation tracking, KSI interpretation, evidence automation, assessor coordination, compliance roadmap development, and cross-functional collaboration with engineering, security, cloud operations, legal, and agency stakeholders.
Top Skills: Cloud Compliance AutomationFedrampFedramp 20XGovrampGrc ToolingIrapNist Sp 800-53Tx-Ramp
37 Minutes Ago
Easy Apply
Remote or Hybrid
San Jose, CA, USA
Easy Apply
146K-182K Annually
Mid level
146K-182K Annually
Mid level
Cloud • Information Technology • Security • Software • Cybersecurity
Manages the Quote-to-Order function, including Salesforce CPQ operations, systems strategy, roadmap development, backlog prioritization, application support, and process improvements. Partners with Sales Operations, Deal Desk, Finance, Pricing, and business leaders to improve quote-to-cash execution. Leads and develops analysts and QA engineers while driving operational excellence, solution design, Agile delivery, and adoption of AI tools.
Top Skills: Agile MethodologiesAi ToolsConfigure Price Quote (Cpq)SalesforceSalesforce Cpq
39 Minutes Ago
Remote or Hybrid
118K-201K Annually
Senior level
118K-201K Annually
Senior level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Deploy, monitor, automate, and support large-scale distributed IaaS, PaaS, and SaaS environments. Build reliable infrastructure, measure production performance, resolve complex service issues, scale systems through automation, and collaborate across engineering, DevOps, security, and IT operations teams. The role requires expertise in networking, cloud technologies, storage, virtualization, infrastructure automation, and service lifecycle management, with eligibility for Secret and TS/SCI clearances.
Top Skills: AnsibleAzure StackCephHelmIaasJdfsJuniperKubernetesNfsOpenstackPaasS3SaaSSecurity+TerraformVMware

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account