Security Risk Management Coordinator

NokiaApplyPublished 5 hours agoFirst seen 4 hours ago
Apply

Security Risk Management team focuses on security risk oversight and reporting:

  • manages and monitors security risks;
  • maintains security risk management framework;
  • hosts risk governance and management meetings with business stakeholders;
  • supports customer and certification audits.
     

Qualifications


  • Cross organisatonal impact by supporting risk-based decision making process in scope of information security.I
  • Individual Contributor: Operates autonomously in own subject area. Can analyze, develop and implement concepts and solutions as a subject matter expert. Increased awareness of and involvement outside of own subject area. Distills big picture. Makes decisions about and prioritizes own work. Managerial/Supervisory: Clear managerial responsibilities for people. Typically first level of solid line management. Interprets policies. Ensures existing plans are put into operation. Executes and/or oversees processes to meet stakeholders´needs. Responsible for analysis, design & development of policies, plans, programs in scope of Security Risk and Compliance Managmenet.
  • Carries out specialised activities/projects according to general direction. Influences others to support decisions. Works mostly independently. Analyze situations or data that requires review of relevant factors. Solutions can often be checked and proved. Demonstrates success in multiple roles and is adaptable to manage complex changing business environments.
  • Communicates with parties within and outside of own job function and teams at all organizational levels. Works to influence others to accept job function’s view/practices and agree/accept new concepts, practices, and approaches. Has cross-cultural knowledge and global mindset. Requires ability to communicate with executive leadership regarding matters of significant importance to the organisation. May conduct briefings with senior leaders within the job function and negotiate regarding operational issues.
  • Management Experience / Achieved well-advanced skills in Information Security Management with focus on Security Risk and Compliance in a global technological organizations, combining deep knowledge of theory and organisational practice or expertise.

     

Responsibilities

• Assesses the compliance, identifies deficiencies, determines risk level, recommends solutions and give guidance and support to ensure Nokia information is protected in line with the Nokia Information Security Policy, done in a cost effective and innovative way bringing value, through simplification, standardisation and homogenisation.

• Engages with stakeholders and shares knowledge and expertise on the information security risk management and related security management perspectives across the organisation to ensure information security management is adequately represented on relevant business and governance forums and is known, well-integrated, and well-respected across the enterprise. 

• Supports business stakeholders to improve their security posture by defining the present risk level, setting the standard which risk is acceptable and defining remediation actions.

• Drives a cultural change around Information Security Risk Management process, identifying needs of the security and business stakeholders, making suggestions for improvement and preparing the necessary steps so that these needs can be timely addressed. 

• Develops and implements standards for security risk and compliance management, clearly defining functional requirements for Security GRC tool implementation.

• Coordinates operational and transformational activities of Security Risk Management team and reports to Security GRC Transformation Program about status, dependencies and challenges.

• Contributes to projects in accordance to our corporate processes.