Service Operations Specialist
We are seeking a highly skilled Offensive Security professional with expertise in Red Team Operations, Application Security Testing, API Security Assessment, Mobile Application Penetration Testing, and Dynamic Application Security Testing (DAST). The role involves simulating real-world cyberattacks, identifying security weaknesses across applications and infrastructure, and providing actionable remediation guidance to development and security teams.
Qualifications
Must-Have Skills:
- Offensive Security / Penetration Testing
- 5+ years of hands-on experience in Penetration Testing, Red Teaming, or Offensive Security.
- Strong understanding of adversary simulation and attack methodologies.
- Web & API Security
- Strong expertise in Web Application Security and API Security.
- OWASP Top 10 and OWASP API Top 10.
- Hands-on experience with Burp Suite, OWASP ZAP and similar tools.
- Network & Active Directory Security
- Network penetration testing and vulnerability assessment.
- Hands-on experience with Nmap, Metasploit, BloodHound, Cobalt Strike/equivalent.
- Knowledge of Active Directory attack techniques.
- Cloud & Infrastructure Security
- Hands-on security testing across Azure, AWS and/or GCP.
- Understanding of cloud attack paths, IAM, misconfigurations and cloud-native security.
- Red Team Tools, Scripting & Security Frameworks
- Strong hands-on experience with Kali Linux and offensive security tooling.
- Ability to develop attack/automation scripts using Python, PowerShell or Bash.
- Working knowledge of MITRE ATT&CK, Secure SDLC and NIST CSF.
Good-to-have skills:
- Mobile & Advanced Application Security
- Mobile penetration testing using MobSF, Frida.
- Secure code review and advanced application security testing.
- Cloud Red Teaming & Container Security
- Cloud Red Teaming across Azure/AWS/GCP.
- Kubernetes, Docker and container security experience.
- DevSecOps & CI/CD Security
- Integration of security testing into CI/CD pipelines.
- DAST, threat modeling and DevSecOps practices.
- Purple Teaming & Adversary Emulation
- Experience conducting Purple Team exercises.
- Advanced adversary emulation and MITRE ATT&CK-based assessments.
- Industry Certifications
- Preferred: OSCP, OSEP, OSWE, CRTO, CRTP, PNPT, CISSP, GWAPT, GPEN, GMOB, GXPN or AZ-500.
Responsibilities
- Conduct adversary emulation exercises and Red Team engagements.
- Execute attack simulations against enterprise environments, Active Directory, cloud infrastructure, and critical business applications.
- Perform reconnaissance, initial access, privilege escalation, persistence, lateral movement, and data exfiltration simulations.
- Assess effectiveness of SOC, SIEM, EDR, XDR, MDR, and Incident Response capabilities.
- Develop custom attack scenarios based on MITRE ATT&CK framework.
- Deliver executive and technical reports with attack paths, impact analysis, and remediation recommendations.
- Perform manual and automated security assessments of web applications.
- Identify and exploit vulnerabilities including:
- SQL Injection
- Cross-Site Scripting (XSS)
- CSRF
- SSRF
- Broken Authentication
- Authorization Bypass
- Business Logic Flaws
- File Upload Vulnerabilities
- Perform REST, SOAP, GraphQL, and Microservices API security assessments.
- Evaluate APIs against OWASP API Security Top 10.
- Identify vulnerabilities such as:
- Broken Object Level Authorization (BOLA)
- Conduct Android and iOS application security assessments.
- Perform static and dynamic analysis of mobile applications.
- Assess:
- Local Data Storage Security
- Configure and execute DAST scans across web applications and APIs.
- Validate and triage findings.
- Integrate DAST into CI/CD and DevSecOps pipelines.
- Assist development teams in remediation and secure coding practices.
Advancing connectivity to secure a brighter world.
Nokia is a global leader in connectivity for the AI era. With expertise across fixed, mobile and transport networks, powered by the innovation of Nokia Bell Labs, we’re advancing connectivity to secure a brighter world.
Learn more about life at Nokia.
Our recruitment process
We act inclusively and respect the uniqueness of people. Our employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law. We are committed to a culture of inclusion built upon our core value of respect.
If you’re interested in this role but don’t meet every listed requirement, we still encourage you to apply. Unique backgrounds, perspectives, and experiences enrich our teams, and you may be just the right candidate for this or another opportunity.
The length of the recruitment process may vary depending on the specific role's requirements. We strive to ensure a smooth and inclusive experience for all candidates. Discover more about the recruitment process at Nokia.

