وصف الوظيفة
الأدوار والمسؤوليات
انضم إلينا
في فودافون، لم نُشكل مستقبل الاتصال لمستخدمينا فحسب، بل شكلنا مستقبل الجميع الذين ينضمون إلى فريقنا. عندما تعمل معنا، تكون جزءًا من مهمة عالمية لربط الناس، وحل التحديات المعقدة، وخلق عالم أكثر استدامة وشمولية. إذا كنت ترغب في تطوير مسيرتك المهنية مع إيجاد التوازن المثالي بين العمل والحياة، فإن فودافون توفر الفرص لمساعدتك على الانتماء وإحداث تأثير حقيقي. الغرض من الدور
عن الدور، نبحث عن أخصائي ضمان الأمن السيبراني الأول للانضمام إلى فريقنا ولعب دور رئيسي في ضمان أمان بيئة فودافون الرقمية. يتولى هذا الدور مسؤولية إجراء اختبارات الاختراق، وتحليل الثغرات، وأنشطة ضمان الأمن عبر تطبيقات الويب والمنصات المحمولة والشبكات وبيئات السحابة. كأخصائي ضمان الأمن السيبراني الأول، ستتعاون بشكل وثيق مع الفرق التقنية والجهات المعنية بالأعمال لتحديد المخاطر الأمنية وتقويمها وتخفيفها مع ضمان الامتثال لسياسات ومعايير الأمن السيبراني في فودافون.
مسؤوليات العمل
- إجراء اختبارات اختراق على تطبيقات الويب والشبكات والتطبيقات المحمولة وبيئات السحابة لتحديد الثغرات ونقاط الضعف الأمنية.
- أداء تحليل الثغرات وتقديم توصيات الإصلاح لتعزيز وضع الأمن.
- ضمان القبول الآمن للعُقد والتقنيات الجديدة من خلال التحقق من الامتثال لسياسات الأمن ومعايير الصناعة في فودافون.
- أداء أنشطة ضمان الأمن بانتظام على الأنظمة والتطبيقات القائمة للحفاظ على الامتثال المستمر والحماية ضد التهديدات الناشئة.
- المشاركة في تقييمات المخاطر للمشاريع الجديدة، وتقديم منظور ضمان أمني لضمان تحديد المخاطر وتخفيفها مبكرًا في دورة التطوير.
- التعاون مع الفرق التقنية ووحدات الأعمال في فودافون لمعالجة نتائج اختبارات الاختراق والتخفيف منها بشكل فعال.
- متابعة التطورات في التهديدات الأمنية والثغرات وأفضل الممارسات في الصناعة، وتطبيقها لتحسين عمليات ضمان الأمن.
ليس المطابقة المثالية؟
هل تقلق من أنك لا تستوفي جميع المعايير المرجوة بدقة؟ في فودافون نحن شغوفون بتمكين الناس وخلق مكان عمل يمكن للجميع فيه الازدهار، مهما كان خلفهم الشخصي أو المهني. إذا كنت متحمسًا لهذا الدور لكن خبرتك لا تتوافق تمامًا مع كل جزء من الوصف الوظيفي، فنحثك على التقدم نظرًا لأنك قد تكون المرشح المناسب لهذا الدور أو لفرصة أخرى.
المهارات الأساسية والمعرفة والخبرة
الأنشطة الأساسية
- اتباع عمليات التسليم الداخلية لتنفيذ متطلبات برامج الأمن السيبراني بما يتوافق مع السياسات العالمية/المحلية.
- ضمان تسليم المشاريع في الوقت المحدد وضمن الميزانية المخصصة.
- التأكد من أن جميع المسارات تسير في الاتجاه الصحيح وتحقق أهدافها الرئيسية.
- إصدار تقارير للمسارات الجارية إلى إدارة الأمن السيبراني والتكنولوجيا.
- إدارة بناء واجهات مناسبة مع مختلف البائعين.
- ضمان تسليم المشاريع والأنشطة مع البائعين في الوقت المناسب وضمن الميزانية المخصصة.
معرفة قوية بأطر الأمن مثل MITRE ATT&CK وNIST وCIS.
الإلمام بإعدادات تقوية التكوينات للبيئات المختلفة (الخوادم، قواعد البيانات، التطبيقات، إلخ).
الخبرة في تقييم المخاطر وتقديم توصيات أمنية بما يتماشى مع متطلبات الأعمال.
القدرة على العمل بشكل تعاوني مع فرق متعددة الوظائف لمعالجة وتخفيف الثغرات الأمنيّة.
مهارات تحليلية قوية وحل المشكلات، مع القدرة على شرح قضايا الأمن المعقدة لأصحاب المصلحة الفنيين وغير الفنيين.
الشهادات ذات الصلة تعتبر إضافة (OSCP، eWPTX، eCPPT، أو ما يماثلها).
المرشح المثالي
- إجراء اختبارات اختراق على تطبيقات الويب والشبكات والتطبيقات المحمولة وبيئات السحابة لتحديد الثغرات ونقاط الضعف الأمنية.
- أداء تحليل الثغرات وتقديم توصيات الإصلاح لتعزيز وضع الأمن.
- ضمان القبول الآمن للعُقد والتقنيات الجديدة من خلال التحقق من الامتثال لسياسات الأمن ومعايير الصناعة في فودافون.
- أداء أنشطة ضمان الأمن بانتظام على الأنظمة والتطبيقات القائمة للحفاظ على الامتثال المستمر والحماية ضد التهديدات الناشئة.
- المشاركة في تقييمات المخاطر للمشاريع الجديدة، وتقديم منظور ضمان أمني لضمان تحديد المخاطر وتخفيفها مبكرًا في دورة التطوير.
- التعاون مع الفرق التقنية ووحدات الأعمال في فودافون لمعالجة نتائج اختبارات الاختراق والتخفيف منها بشكل فعال.
- متابعة التطورات في التهديدات الأمنية والثغرات وأفضل الممارسات في الصناعة، وتطبيقها لتحسين عمليات ضمان الأمن.
- اتباع عمليات التسليم الداخلية لتنفيذ متطلبات برامج الأمن السيبراني بما يتوافق مع السياسات العالمية/المحلية.
- ضمان تسليم المشاريع في الوقت المحدد وضمن الميزانية المخصصة.
- التأكد من أن جميع المسارات تسير في الاتجاه الصحيح وتحقق أهدافها الرئيسية.
- إصدار تقارير للمسارات الجارية إلى إدارة الأمن السيبراني والتكنولوجيا.
- إدارة بناء واجهات مناسبة مع مختلف البائعين.
- ضمان تسليم المشاريع والأنشطة مع البائعين في الوقت المناسب وضمن الميزانية المخصصة
- معرفة قوية بأطر الأمن مثل MITRE ATT&CK وNIST وCIS.
- الإلمام بإعدادات تقوية التكوينات للبيئات المختلفة (الخوادم، قواعد البيانات، التطبيقات، إلخ).
- الخبرة في تقييم المخاطر وتقديم توصيات أمنية بما يتماشى مع متطلبات الأعمال.
- القدرة على العمل بشكل تعاوني مع فرق متعددة الوظائف لمعالجة وتخفيف الثغرات الأمنيّة.
- مهارات تحليلية قوية وحل المشكلات، مع القدرة على شرح قضايا الأمن المعقدة لأصحاب المصلحة الفنيين وغير الفنيين.
- الشهادات ذات الصلة تعتبر إضافة (OSCP، eWPTX، eCPPT، أو ما يماثلها).
Job Description
Roles & Responsibilities
Join Us
At Vodafone, we re not just shaping the future of connectivity for our customers we re shaping the future for everyone who joins our team. When you work with us, you re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact. Role Purpose
About the Role We are looking for a Cyber Security Assurance Senior Specialist to join our team and play a key role in ensuring the security of Vodafone s digital environment. This role is responsible for conducting penetration testing, vulnerability analysis, and security assurance activities across web applications, mobile platforms, networks, and cloud environments. As a Cyber Security Assurance Senior Specialist, you will work closely with technical teams and business stakeholders to identify, assess, and mitigate security risks while ensuring compliance with Vodafone s cyber security policies and standards.
Job Responsibilities
- Conduct penetration testing on web applications, networks, mobile applications, and cloud environments to identify vulnerabilities and security weaknesses.
- Perform vulnerability analysis and provide remediation recommendations to enhance security posture.
- Ensure secure acceptance of new nodes and technologies by validating compliance with Vodafone s security policies and industry standards.
- Perform regular security assurance activities on existing systems and applications to maintain continuous compliance and protection against emerging threats.
- Participate in risk assessments for new projects, providing a security assurance perspective to ensure risks are identified and mitigated early in the development cycle.
- Collaborate with Vodafone technical teams and business units to address and remediate penetration testing findings effectively.
- Stay up to date with emerging security threats, vulnerabilities, and industry best practices, applying them to improve security assurance processes.
Not a perfect fit?
Worried that you don t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you re excited about this role but your experience doesn t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.
Core competencies, knowledge, and experience
Key activities
- Follow internal delivery processes to deliver cyber security programs requirements in alignment with global/local policies.
- Ensure delivery of projects on time and within allocated budget.
- Ensure that all streams running on the right track and fulfilling their main objectives.
- Issue reports for running streams to Cyber Security and Technology Management
- Manages building proper interface with different vendors.
- Ensure projects and activities delivery with vendors on time and within allocated budget
Strong knowledge of security frameworks such as MITRE ATT&CK , NIST and CIS.
Familiarity with hardening configurations for different environments (servers, databases, applications, etc.).
Experience in risk assessment and providing security recommendations in line with business requirements.
Ability to work collaboratively with cross-functional teams to address and mitigate security vulnerabilities.
Strong analytical and problem-solving skills, with the ability to communicate complex security issues to technical and non-technical stakeholders.
Relevant certifications are a plus ( OSCP, eWPTX, eCPPT, or similar ).
Desired Candidate Profile
- Conduct penetration testing on web applications, networks, mobile applications, and cloud environments to identify vulnerabilities and security weaknesses.
- Perform vulnerability analysis and provide remediation recommendations to enhance security posture.
- Ensure secure acceptance of new nodes and technologies by validating compliance with Vodafone s security policies and industry standards.
- Perform regular security assurance activities on existing systems and applications to maintain continuous compliance and protection against emerging threats.
- Participate in risk assessments for new projects, providing a security assurance perspective to ensure risks are identified and mitigated early in the development cycle.
- Collaborate with Vodafone technical teams and business units to address and remediate penetration testing findings effectively.
- Stay up to date with emerging security threats, vulnerabilities, and industry best practices, applying them to improve security assurance processes.
- Follow internal delivery processes to deliver cyber security programs requirements in alignment with global/local policies.
- Ensure delivery of projects on time and within allocated budget.
- Ensure that all streams running on the right track and fulfilling their main objectives.
- Issue reports for running streams to Cyber Security and Technology Management
- Manages building proper interface with different vendors.
- Ensure projects and activities delivery with vendors on time and within allocated budget
- Strong knowledge of security frameworks such as MITRE ATT&CK , NIST and CIS.
- Familiarity with hardening configurations for different environments (servers, databases, applications, etc.).
- Experience in risk assessment and providing security recommendations in line with business requirements.
- Ability to work collaboratively with cross-functional teams to address and mitigate security vulnerabilities.
- Strong analytical and problem-solving skills, with the ability to communicate complex security issues to technical and non-technical stakeholders.
- Relevant certifications are a plus ( OSCP, eWPTX, eCPPT, or similar ).