Assistant Product Security Manager

EricssonGurugram, HaryanaOn-siteFull-timeSenior, 5–8 yearsListed 2 hours ago

Apply now

About this role

Join our Team

About the role

As an Assistant Product Security Manager / Security Master at Ericsson, you will work with the E5GC (Enterprise 5G Connect) Product Security Manager (PSM) to support the E5GC development organization in India. You will help embed security and privacy throughout the product lifecycle, from solution design and development through testing, vulnerability handling, compliance, delivery, and support.

The role is suited to a proactive, self-starting security professional who combines technical expertise, practical judgment, clear communication, and creative problem-solving.

Key responsibilities

- Support the E5GC PSM in implementing product-security processes across the India development organization and integrating security into development and delivery practices.
- Monitor and coordinate responses to PSIRT alerts, vulnerabilities, and security incidents, including triage, CVSS-based risk assessment, remediation tracking, verification, and escalation.
- Coordinate penetration testing and vulnerability assessments, including scope definition, findings analysis, remediation follow-up, and closure.
- Support the selection, implementation, and effective use of security tools, automation, and responsible AI-enabled capabilities.
- Provide security and privacy input to solution design, including applicable security and privacy GPRs, threat modeling, secure design, and personal-data protection requirements.
- Assist with security and privacy Statements of Compliance, audits, risk assessments, evidence preparation, and other governance activities.
- Prepare and maintain security documentation, including security assessments, test reports, and vulnerability records.
- Advise and collaborate with developers, architects, product managers, privacy specialists, and other stakeholders on secure implementation, risk reduction, and continuous improvement.

Required qualifications and experience

- Bachelor’s degree or equivalent experience in cybersecurity, information security, computer science, software engineering, or a related field.
- 5+ years of relevant experience in product security, application security, cybersecurity, vulnerability management, penetration testing, or a related area.
- Practical experience with CVSS, vulnerability testing and handling, penetration-testing findings, remediation coordination, and risk-based prioritization.
- Experience responding to security advisories, PSIRT alerts, vulnerability disclosures, or security incidents.
- Experience implementing or operationalizing security tools in a software-development environment.
- Knowledge of secure software development, security architecture, threat modeling, security-by-design, and personal-data protection.
- Knowledge of ISO/IEC 27001 and information-security management practices.
- Familiarity with security and privacy compliance, Statements of Compliance, audits, and evidence preparation.
- Familiarity with vulnerability scanners, software-composition analysis, static and dynamic analysis, container security, or cloud-security tools.
- Experience using scripting, automation, data analysis, or AI to improve security workflows.
- Strong written and verbal English communication skills, with the ability to collaborate across cultures and functions.

Personal competencies

- Proactive, self-motivated, and comfortable taking ownership from identification through resolution.
- An out-of-the-box thinker who can develop practical solutions to security and privacy challenges.
- Analytical, structured, detail-oriented, and able to make sound risk-based decisions.
- Collaborative, adaptable, curious, and confident raising security and privacy concerns constructively.
- Able to balance delivery needs with security, privacy, compliance, and customer expectations.

Success in this role

Success means providing timely and practical security guidance to the India development organization, ensuring PSIRT alerts and vulnerabilities are handled effectively, and strengthening the E5GC security and privacy posture through better design, testing, tools, documentation, and collaboration.

“All academic credentials must be from recognized and accredited institutions and are further subject to verification.”

Why join Ericsson? At Ericsson, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build solutions never seen before to some of the world’s toughest problems. You´ll be challenged, but you won’t be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.

What happens once you apply? Click Here to find all you need to know about what our typical hiring process looks like.Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer.  learn more.

Primary country and city: India (IN) || Kolkata

Req ID:  791433