## Join Us
At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.
The Security Engineer (GRC) processes all assigned security analyses and completes all specific activities in the area of Governance, Risk and Compliance in the field of Cybersecurity, following local and global procedures, with the aim of protecting customer and employee data and maintaining the integrity of the company's IT infrastructure.
Creates and maintains updated procedures necessary to resolve team-specific activities, provides support and guidance to team colleagues and maintains good collaboration with all departments within the company, both local and global.
## What you’ll do
Main Responsibilities:
• Collaborates with various teams in the organization to manage cybersecurity risks, including suppliers
• Responsible for the end-to-end coordination of penetration tests for Vodafone assets, ensuring planning, defining the scope, organizing and facilitating their execution in collaboration with various stakeholders
• Manages the relationship with the teams involved, provides operational support during testing, distributes results to relevant parties and monitors the remediation of identified vulnerabilities.
• Ensures the escalation and recording of cyber risks in cases where remediation exceeds the agreed deadlines, contributing to effective risk management and compliance with security requirements.
• Knows and proposes updates for cybersecurity policies, control objectives, risk management processes and standards to align with regulations, best practices and local and group information security frameworks
• Oversees and leads cybersecurity risk management processes, including cybersecurity, controls the tracking and management of supplier risks
• Provides assistance to internal and external audits in the area of Cybersecurity and follows up on the closure of associated findings on time, such as ISO27001, etc.
• Maintains updated and ensures risk reporting in dedicated IT systems such as RiskConnect or similar
• Processes risk sheets identified through Trust by Design and Prevention and Detection processes, Shadow IT
• Updates action plans in the centralized system with those responsible for closing the agreed measures and monitors monthly the actions that are about to expire to obtain an up-to-date status from them
• Ensures the representation of the Cyber team in local or group sessions for the continuous review of the risk management framework: CHARM or equivalent
• Analyzes the specific technologies of the communications industry, applicable regulatory requirements, global trends and methodologies for the development of information security solutions, to determine their impact on the governance framework of security risks
• Knows the applicable Security requirements in the essential security areas, user management, logging and monitoring, API Security, Cloud Security, VOIP Security, Mobile Application Security and Web Security, Network and Telco Equipment Security from the perspective of associated risks
• Responsible for reviewing the security requirements within the contracts signed by the organization with third parties to minimize information security risks in accordance with applicable procedures
• Monitors the implementation of procedures in the area of Shadow IT, Trust by Design, Cyber Defence and Prevent to ensure complete and correct registration of information security risks
• Manages the implementation of risk management projects following the cybersecurity strategy communicated by the team global...
Want jobs like this matched to you?
Swoopd scores fresh postings against your résumé so you only see the matches that matter.