
Telecom Security Risk Consultant
Posted Jul 15

Posted Jul 15
This is a fully remote position, open to applicants in France.
• Lead and execute comprehensive telecom security risk assessments and provide security consulting services for operators, vendors, and critical infrastructure programs (including Security Architecture Reviews, RAN & OSS Risk Assessment, MOCN Risk Assessment, IMS Cloud Risk Assessment, and 5G Core Risk Assessment).
• Establish the assessment scope, develop the threat model, and define the risk methodology; convert technical findings into clear, actionable risk statements along with remediation roadmaps.
• Conduct architecture and design evaluations across 2G/3G/4G/5G, IMS, EPC/5GC, RAN/OpenRAN, OSS/BSS, interconnect, roaming, cloud-native telecom platforms (Kubernetes/OpenStack), and various OT and IT infrastructures.
• Evaluate security controls and ensure compliance alignment (e.g., GSMA, 3GPP, NIST/ISO principles) covering aspects such as identity management, key management, cryptographic choices, secure boot, supply chain security, and operational security.
• Analyze protocol and interface vulnerabilities (SS7, Diameter, GTP, SIP/IMS, SIGTRAN, HTTP APIs) to identify misuse cases, misconfigurations, and inherent weaknesses.
• Assess cloud and platform security for telecom workloads (multi-tenancy, network segmentation, service mesh, IAM, secrets management, CI/CD, container hardening).
• Perform evidence-based testing and validation when necessary (configuration review, log analysis, traffic evaluation, fuzzing/abuse-case testing) and collaborate with P1 Labs R&D on advanced topics.
• Deliver high-quality outputs: executive summaries, technical annexes, risk registers, reports, and presentations; ensure consistency and repeatability throughout all engagements.
• Assist in pre-sales activities and customer workshops: clarify requirements, estimate efforts, contribute to proposals, and effectively communicate scope and value.
• Mentor team members and enhance the internal knowledge repository, assessment playbooks, and reusable tools.
• Over 5 years of experience in telecom security, network security, or risk assessment/consulting for telecom operators, infrastructure providers, or security vendors.
• Proven experience in consulting and/or client-facing roles, emphasizing clear communication and stakeholder management.
• Demonstrated capability to conduct security architecture reviews, translating intricate technical issues into prioritized, business-centric risks and mitigations.
• Practical security expertise in at least two of the following areas: protocol security, cloud/Kubernetes security, Linux hardening, IAM/PKI/key management, vulnerability research, incident response, or SOC/monitoring.
• Awareness of telecom and security standards and guidelines (e.g., 3GPP security, GSMA FS/NG, NIST, ISO 27001/27002).
• Relevant certifications are advantageous but not mandatory.
• Experience with AI-assisted delivery while considering privacy (e.g., LLM tools) and possessing strong judgment to assess AI applicability, as well as the ability to review, validate, and challenge AI-generated content to ensure its accuracy, completeness, and confidentiality.
• Comfortable working with technical documents: network diagrams, HLD/LLD, configuration baselines, cloud manifests, logs, PCAPs; capable of validating evidence and questioning assumptions.
• Excellent written and verbal communication skills; adept at composing structured reports and presenting to both technical and executive audiences.
• Ability to work independently in a client-facing setting, prioritize tasks, and deliver on schedule across multiple projects.
• Flexible remote work arrangements with occasional meetups for collaboration and team bonding.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.