← Back to list
Job

Secure by Design Manager

Other • On-site • Full-time • Portugal Lisbon, Portugal

In Vodafone's global Cyber VF Investments / M&A team you carry out technical security assessments, set security requirements for new products and services, and assess compliance and risk. You also act as a security design advisor and cyber coach to agile teams.

Responsibilities

  • ▹Carry out technically oriented security assessments and set security requirements for new or changed products and services requested by VF Partners, assessing compliance and risk
  • ▹Take part in technical due diligence during mergers and acquisitions, assessing compliance and risk prior to transaction completion
  • ▹Provide security design and architecture guidance and general security consultancy to the business
  • ▹Act as cyber coach to agile project and programme teams so that future infrastructures and products are secure globally
  • ▹Serve as cyber security subject matter expert, working closely with solution architects, designers and developers
  • ▹Cover the cyber aspects of the Security and Privacy by Design and Assurance process, with a focus on VF Partners and M&A projects
  • ▹Scope and coordinate security penetration testing prior to product launch
  • ▹Ensure that all global products, services and infrastructure are secure by design and that risks are mitigated to an acceptable level
  • ▹Advise internal and external customers on security matters; define, communicate and ensure supplier and third-party compliance with Vodafone's security standards
  • ▹Work closely with business and technology architecture, design and operations teams and other security teams (Risk and Compliance, Ethical Hacking, Security Operations, Corporate Security)
  • ▹Manage external resources and coach Security Champions in the agile teams
  • ▹Communicate security requirements and risks to all levels of the business and give clear guidance for implementing security controls in complex environments

Requirements

  • ▹University degree in Information Security or equivalent
  • ▹One or more of the following: CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor, GIAC, TOGAF, SABSA or equivalent
  • ▹3-5 years of work experience in cyber security
  • ▹Professional experience in information technology and cyber security, including security in agile ways of working and DevSecOps
  • ▹Good knowledge/experience in securing cloud environments, web services, CI/CD pipelines, container security, connectivity, user access management and networks
  • ▹Fluency in English

Nice to have

  • ▹Penetration testing experience

Soft skills

Communicating to technical and non-technical executivesLeadership and teamworkProactivityCoaching

What we offer

  • ▹Flexible hybrid work model with 8-10 in-office days per month, managed by team leaders
  • ▹Vodafone products and services: mobile phone, free communication plan, data card and discounts
  • ▹Recognition programs for innovative, creative, high-potential employees and exemplary behaviors
  • ▹Well-being program: nutrition and psychological consultations, webinars, workshops and discounts
  • ▹Learning: access to Communities of Practice and a customizable digital training platform (Harvard Business Publishing, Skillsoft, Speexx)
  • ▹Local and international mobility: internal recruitment with rotation opportunities across departments and roles

About the company

Vodafone is a leading international telco serving millions of customers. It believes connectivity is a force for good and uses its technology to connect people while protecting the planet.

Languages: Angol: folyékony
Education: Információbiztonsági egyetemi diploma (vagy egyenértékű)

Similar jobs