Business Security Partner for the Business Functions

NokiaApplyPublished 6 hours agoFirst seen 5 hours ago
Apply

Information Security serves as Nokia’s center of excellence for cybersecurity, responsible for defining security policies and standards, shaping the cybersecurity architecture and roadmap, and overseeing security monitoring, detection, and incident management.

We actively partner with Nokia’s Business Segments and Business Functions to drive product security, customer security, and regulatory compliance initiatives, while engaging with governments and industry stakeholders on evolving security requirements.

Together, we safeguard Nokia’s people, processes, systems, products, and services, reinforcing our position as a trusted partner in the 5G era and beyond.

In this role, you will join the Business Security team, which drives enterprise-wide security initiatives across business environments. The team focuses on protecting critical company information, securing third-party engagements, and partnering with business leaders to identify, assess, and mitigate security risks. As a trusted advisor, you will help integrate security into business operations and strategic decision-making, ensuring that security enables innovation and growth.

Qualifications

You have:

  • Strong business and technology acumen, with a clear understanding of how security and technology enable business transformation.
  • Demonstrated leadership experience and strong business judgment.
  • Deep understanding of software development practices, methodologies, and modern technology environments.
  • Strong analytical, critical thinking, and problem-solving capabilities.
  • Ability to translate complex technical and security concepts into clear business language for non-technical audiences.
  • Excellent stakeholder management and influencing skills across all organizational levels.
  • Strong written and verbal communication skills in English.
  • A master’s degree (or equivalent experience) in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field.

It would be nice if you also had:

  • Relevant industry certifications such as CISSP, CISM, or equivalent security credentials.
  • Experience working in global, matrixed organizations.
  • Knowledge of regulatory and compliance frameworks relevant to telecommunications and technology companies.

You are:

  • A confident communicator who is comfortable engaging with senior executives and business leaders.
  • Passionate about technology, business enablement, and information security.
  • Highly self-motivated, proactive, and results oriented.
  • A collaborative team player who thrives in diverse and virtual teams.
  • Able to effectively prioritize and execute tasks in a fast-paced environment with competing priorities and tight deadlines.
  • Skilled at balancing security requirements with business objectives to drive practical and sustainable outcomes.

Responsibilities

The Business Security Partner role requires an in-depth understanding of Business Segment and Business Function (BS/BF) operations, priorities, and strategic objectives, combined with broad expertise in Information Security processes, governance, risk management, and security controls. This knowledge is essential to ensure effective alignment between business needs and security requirements while driving Nokia's security objectives across the organization.

Responsibilities include, but are not limited to:

  • Ensuring security governance is established within assigned BS/BFs, including defining, proposing, and maintaining appropriate governance structures and operating models.
  • Ensuring all Information Security related roles and responsibilities are defined, communicated, and formally nominated within the business.
  • Establishing and facilitating regular interworking channels, governance forums, and interlock meetings between Information Security and BS/BF leadership teams to drive security risk reduction and strategic alignment.
  • Creating awareness within BS/BFs regarding security risks, emerging threats, required security measures, and the evolving threat landscape.
  • Providing regular updates to BS/BF management on relevant incidents, cyber threats, security posture, and key security developments.
  • Assessing BS/BF priorities, concerns, and business objectives, and aligning them with Nokia's Information Security priorities, programs, and initiatives.
  • Communicating Nokia's security strategy and roadmap to BS/BF stakeholders.
  • Monitoring, tracking, and co-steering the implementation of agreed security roadmaps, initiatives, controls, and remediation programs within assigned BS/BFs.
  • Providing regular executive-level reporting on key security risks, security posture, metrics, and KPIs across all relevant security domains.
  • Communicating within Information Security the status, progress, dependencies, and challenges of BS/BF-specific security projects and initiatives.
  • Escalating significant security risks, compliance concerns, or control deficiencies to key business stakeholders and leadership teams when appropriate.
  • Proactively communicating BS/BF concerns regarding Information Security initiatives, services, investment priorities, budget requirements, resource needs, and support levels.
  • Supporting BS/BFs in identifying, assessing, managing, and mitigating security risks related to critical information protection (CIP), third-party engagements, cloud environments, and other critical business ecosystems.
  • Guiding solution owners and technology stakeholders on security compliance requirements for applications, databases, servers, cloud services, and other technology platforms.
  • Preparing for internal and external audits in cooperation with relevant teams and communicating potential weaknesses, control gaps, and improvement opportunities to management.
  • Comparing audit findings with previously identified risks and weaknesses, driving sustainable remediation plans and continuous improvement initiatives.
  • Monitoring training completion metrics, communicating training status to stakeholders, and driving compliance with mandatory security training requirements.
  • Acting as the trusted security advisor to business leadership by translating security risks, requirements, and opportunities into actionable business outcomes.

Promoting a strong security culture across the organization by embedding security considerations into business planning, decision-making, and operational processes.