Key Responsibilities
This function will be responsible for the full lifecycle management of policy content, which includes the following responsibilities:
- Lead the creation, review, approval, and continuous improvement of information security policies, standards, guidelines, and procedures.
- Develop, implement, and effectively manage changes to policy content as a Subject Matter Expert (SME)
- Stay informed on (emerging) information security trends, threats, and regulatory changes, and adjust policy content accordingly.
- Respond to the need to develop and implement changes and improvements.
- Conduct research and analyze complex technical and security information by using various sources, such as: publications available on the Internet
- Consult GS security-related service SMEs to assess current and emerging threats.
- Collaborate with other SME stakeholders (within Group Security and other Nokia teams) to develop and review new policy content.
- Work closely with cross-functional teams (including IT, privacy, compliance, legal, corporate functions, and other business groups) to ensure a unified approach to Nokia’s security policy.
- Ensure that security policy is consistent with the overall Nokia Strategy & Technology strategy, and that policy content helps implementing security strategies addressing the evolving threat landscape.
- Conduct the annual review of policy content to address new technology, legal, privacy, and organizational requirements.
Key Tasks for Policy Management
This role oversees the full management lifecycle of Information Security policies:
- Act as a primary point of contact for inquiries related to security policies and procedures.
- Lead Group Security’s Policy Review Governance Meetings, schedule regular meetings, review changes under consideration.
- Manage multiple projects and priorities effectively and manage the approval process.
- Communicate policy changes to the Nokia organization, using internal web postings, Nokia’s enterprise social networking platform, and targeted emails.
- Conduct annual review of policy content (to support ISO 27001).
- Conduct life-cycle management of related documentation, policy website, and policy tools.
Key Tasks for developing policy content as a Subject Matter Expert (SME)
- Develop strong understanding of security frameworks (CIS Controls, CMMC, COBIT, ISO 27001, ITIL, NIST,…) and regulatory requirements (GDPR, SOX,…).
- Stay current on cybersecurity trends and the evolving threat landscape.
- Stay up to date with regulatory changes affecting security policy (EU AI Act, NIS2, CRA,,…).
- Analyze, develop, and implement concepts and solutions as a subject matter expert in cybersecurity and information technology.