Ericsson
Ericsson
New

SW Production Security Champion

Brak informacji o wynagrodzeniu
SeniorFull-time
#371673·Dodano wczoraj·0
Źródło: nofluffjobs.com
Aplikuj teraz

Tech Stack / Keywords

RANSecuritySoftware Securityrisk assesmentAudits

Firma i stanowisko

Ericsson is hiring a Production Security Champion/Security Specialist to join the RAN Performance team. The role focuses on securing production and production-adjacent environments such as CI/CD pipelines, build and test infrastructure, and performance labs, ensuring compliance with Ericsson security expectations and external regulations.

Wymagania

  • Hands-on experience with RAN Performance, TPS, or similar production, lab, CI/CD, build, and test environments.
  • Strong understanding of security frameworks, secure SDLC/SSDF, and CI/CD architectures.
  • Solid knowledge of security concepts including vulnerability management, secure configuration, identity and access management, and Ericsson's SRM framework.
  • Experience with security activities such as risk assessments, security reviews, audits, or customer security questionnaires.
  • Good understanding of regulatory expectations for R&D/production environments (NIST SSDF, EU CRA, NIS2).
  • Proven ability to lead cross-functional initiatives and drive change through influence rather than formal authority.

Nice to have:

  • Experience with risk assessment.
  • Experience with audits.

Obowiązki

  • Interpret and translate NIST SSDF, NCSC, EU CRA, and related frameworks into concrete security controls for build/test tools, CI/CD pipelines, SBOM tracking, access control, and logging.
  • Ensure audit-ready evidence is available for self-attestations, customer requests, and regulatory reviews.
  • Turn secure development principles into practical guidelines for production tooling and automation, including secure scripting, CI/CD patterns, and secrets/credentials handling.
  • Drive security awareness and training for engineers and operations teams.
  • Define and maintain reusable security ways of working for RAN Performance production, including access request flows, security review checkpoints, logging and retention requirements, and incident handling routines.
  • Build clear documentation, templates, and checklists for onboarding new tools or making environment changes.
  • Maintain an aggregated risk view for production environments, coordinating vulnerability management and periodic access reviews.
  • Drive structured handling of vulnerabilities, hardening, privileged access, and exceptions through to closure.
  • Lead a chapter of Security Masters and Principal Security Masters across production and production-like environments, ensuring synchronization with leadership and security programs.

Benefity

  • Sport subscription
  • Training budget
  • Private healthcare
  • Lunch card
  • International projects
  • Free coffee
  • Canteen
  • Bike parking
  • Playroom
  • In-house trainings
  • Free parking
  • Mobile phone
  • Modern office
  • No dress code
Karta sportowa
Dofinansowanie szkoleń
Opieka zdrowotna
Firmowa stołówka
Parking dla rowerów
Szkolenia wewnętrzne
Napoje w biurze
Darmowe przekąski
Telefon
Ericsson

Ericsson

8 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz