Join us
At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.
What you’ll do
About the role
We are looking for a Cyber Security Assurance Tech Lead to join our team and play a key role in delivering and supporting penetration testing and security assurance activities across Vodafone’s digital environment. This role is responsible for performing penetration testing engagements, supporting security assessment activities, conducting vulnerability analysis, and ensuring the security posture of web applications, mobile platforms, networks, and cloud environments.
As a Cyber Security Assurance Tech Lead, you will work closely with technical teams, vendors, and business stakeholders to identify, assess, and remediate security vulnerabilities while ensuring compliance with Vodafone’s cyber security policies, standards, and best practices.
Who you are
Job responsibilities:
Perform penetration testing activities on web applications, mobile applications, networks, APIs, and cloud environments to identify security vulnerabilities and weaknesses.
Support penetration testing activities conducted internally or through third-party vendors, ensuring proper execution and reporting.
Conduct vulnerability assessments and security analysis, providing remediation recommendations to improve the overall security posture.
Validate secure implementation and acceptance of new technologies, systems, and infrastructure in alignment with Vodafone security policies and standards.
Perform regular security assurance activities on existing applications and environments to ensure continuous compliance and protection against emerging threats.
Participate in security risk assessments for new projects and initiatives, ensuring security risks are identified and mitigated during early project phases.
Collaborate with technical teams and business stakeholders to track and remediate penetration testing findings in a timely manner.
Review and validate penetration testing reports, ensuring findings are properly documented with clear remediation guidance.
Stay up to date with emerging cyber threats, vulnerabilities, attack techniques, and industry best practices to continuously improve penetration testing and security assurance capabilities.
Not a perfect fit?
Worried that you don’t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you’re excited about this role but your experience doesn’t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.
What's in it for you
Core competencies, knowledge, and experience
Strong knowledge of security frameworks and methodologies such as MITRE ATT&CK, NIST, OWASP, and CIS Controls.
Hands-on understanding of penetration testing methodologies for web, mobile, network, API, and cloud environments.
Familiarity with hardening and secure configuration practices for servers, databases, operating systems, and applications.
Experience in vulnerability assessment, risk analysis, and providing security recommendations aligned with business requirements.
Ability to work collaboratively with cross-functional teams to identify, prioritize, and remediate security vulnerabilities.
Strong analytical, troubleshooting, and problem-solving skills with the ability to communicate technical findings to both technical and non-technical stakeholders.
Relevant certifications are considered a plus (OSCP, eWPTX, eCPPT, CEH, PNPT, or similar).
Key activities
Follow internal delivery and governance processes to execute cyber security assurance and penetration testing activities in alignment with global and local security policies.
Support the delivery of cyber security projects and assessments within agreed timelines and scope.
Ensure all security assessment streams are progressing effectively and meeting their defined objectives.
Prepare and issue reports and dashboards related to penetration testing and security assurance activities to Cyber Security and Technology Management.
Coordinate and maintain effective communication with internal teams and external vendors involved in penetration testing and security assurance activities.
Ensure security assessment activities and vendor deliverables are completed on time and according to required quality standards.
Who we are
We are a leading international telco, serving millions of customers. At Vodafone, we believe that connectivity is a force for good. If we use it for the things that really matter, it can improve people's lives and the world around us. Through our technology we empower people, connecting everyone regardless of who they are or where they live and we protect the planet, whilst helping our customers do the same.
Belonging at Vodafone isn't a concept; it's lived, breathed, and cultivated through everything we do. You'll be part of a global and diverse community, with many different minds, abilities, backgrounds and cultures. We're committed to increasing diversity, ensuring equal representation, and making Vodafone a place everyone feels safe, valued and included.
انضم إلينا
في فودافون، نحن لا نشكّل مستقبل الاتصال لعملائنا فحسب، بل نشكّل المستقبل للجميع من ينضمون إلى فريقنا. عندما تعمل معنا، فأنت جزء من مهمة عالمية لربط الناس، وحل التحديات المعقدة، وخلق عالم أكثر استدامة وشمولاً. إذا كنت ترغب في تطوير مسارك المهني مع إيجاد التوازن المثالي بين العمل والحياة، فإن فودافون توفر الفرص لمساعدتك على الإحساس بالانتماء وتحقيق أثر حقيقي.
ما ستقوم به
عن الدور
نحن نبحث عن قائد تقني لضمان الأمن السيبراني للانضمام إلى فريقنا ولعب دور رئيسي في تقديم ودعم أنشطة الاختبار الاختراقي وضمان الأمن عبر بيئة فودافون الرقمية. يتحمل هذا الدور مسؤولية إجراء مهام الاختبار الاختراقي، دعم أنشطة التقييم الأمني، إجراء تحليل الثغرات، وضمان وضع أمني للتطبيقات الويب، والمنصات المحمولة، والشبكات، وبيئات السحابة.
كقائد تقني لضمان الأمن السيبراني، ستعمل عن كثب مع الفرق التقنية، البائعين، وأصحاب المصلحة التجاريين لتحديد وتقييم وتخفيف الثغرات الأمنية مع ضمان الامتثال لسياسات ومعايير وأفضل ممارسات الأمن السيبراني في فودافون.
من أنت
المسؤوليات الوظيفية:
إجراء أنشطة الاختبار الاختراقي على تطبيقات الويب، والتطبيقات المحمولة، والشبكات، وواجهات برمجة التطبيقات، وبيئات السحابة لتحديد الثغرات ونقاط الضعف الأمنية.
دعم أنشطة الاختبار الاختراقي التي تُنفّذ داخلياً أو من خلال بائعين طرف ثالث، لضمان التنفيذ والتقارير بشكل صحيح.
إجراء تقييمات الثغرات وتحليل أمني وتقديم توصيات التخفيف لتحسين الوضع الأمني العام.
التحقق من التنفيذ الآمن وقبول التكنولوجيا الجديدة والأنظمة والبنية التحتية بما يتوافق مع سياسات ومعايير أمان فودافون.
إجراء أنشطة ضمان الأمن المنتظمة على التطبيقات والبيئات القائمة لضمان الامتثال المستمر والحماية من التهديدات الناشئة.
المشاركة في تقييمات مخاطر الأمن للمشاريع والمبادرات الجديدة، لضمان تحديد مخاطر الأمن وتخفيفها في المراحل المبكرة من المشروع.
التعاون مع الفرق التقنية وأصحاب المصلحة التجاريين لتعقب ومعالجة نتائج الاختبار الاختراقي بشكل فوري.
مراجعة وتوثيق تقارير الاختبار الاختراقي والتأكد من توثيق النتائج مع إرشادات التخفيف الواضحة.
البقاء على اطلاع بالتهديدات السيبرانية الناشئة والثغرات وتقنيات الهجوم وأفضل الممارسات الصناعية لتحسين قدرات الاختبار الاختراقي وضمان الأمن بشكل مستمر.
ليس التطابق المثالي؟
قلق من أنك لا تستوفي جميع المعايير المرغوبة بدقة؟ في فودافون نحن شغوفون بتمكين الناس وخلق مكان عمل يزدهر فيه الجميع، بغض النظر عن خلفيتهم الشخصية أو المهنية. إذا كان لديك حماس لهذا الدور لكن خبرتك لا تتوافق تماماً مع كل جزء من وصف الوظيفة، فنحن نشجعك على التقديم فقد تكون أنت المرشح المناسب لهذا الدور أو لفرصة أخرى.
ما المزايا التي تأتيك
المهارات الأساسية، والمعرفة، والخبرة
معرفة قوية بإطارات العمل الأمني ومنهجياتها مثل MITRE ATT&CK، NIST، OWASP، و CIS Controls.
فهم عملي لمنهجيات الاختبار الاختراقي لبيئات الويب، والماليات، والشبكات، وواجهات برمجة التطبيقات، والسحابة.
الإلمام بممارسات التشدد والتكوين الآمن للخوادم وقواعد البيانات وأنظمة التشغيل والتطبيقات.
خبرة في تقييم الثغرات وتحليل المخاطر وتقديم توصيات أمنية متوافقة مع متطلبات العمل.
القدرة على العمل بشكل تعاوني مع فرق متعددة الاختصاصات لتحديد الأولويات ومعالجة الثغرات الأمنية.
مهارات تحليلية قوية ومهارات حل المشكلات والقدرة على شرح النتائج الفنية لأصحاب المصلحة الفنيين وغير الفنيين.
الشهادات ذات الصلة تعتبر ميزة (OSCP، eWPTX، eCPPT، CEH، PNPT، أو ما يماثلها).
أنشطة رئيسية
اتباع عمليات التقديم والحوكمة الداخلية لتنفيذ أنشطة ضمان الأمن السيبراني والاختبار الاختراقي بما يتماشى مع السياسات الأمنية العالمية والمحلية.
دعم تقديم مشاريع الأمن السيبراني والتقييمات ضمن الجداول والحدود المتفق عليها.
ضمان تقدم جميع مسارات التقييم الأمني بفعالية وتحقيق أهدافها المحددة.
إعداد وإصدار تقارير ولوحات معلومات متعلقة بأنشطة الاختبار الاختراقي وضمان الأمن إلى إدارة الأمن السيبراني والتقنية.
تنسيق والحفاظ على اتصال فعال مع الفرق الداخلية والبائعين الخارجيين المشاركين في أنشطة الاختبار الاختراقي وضمان الأمن.
التأكد من اكتمال أنشطة التقييم الأمني وتسليمات البائعين في الوقت المحدد وبالجودة المطلوبة.
من نحن
نحن شركة اتصالات دولية رائدة، نخدم ملايين العملاء. في فودافون، نؤمن بأن الاتصال قوة للخير. إذا استخدمناه للأشياء التي تهم حقاً، يمكنه تحسين حياة الناس والعالم من حولنا. من خلال تقنيتنا نمكّن الناس، نوصل الجميع بغض النظر عمن هم أو أين يعيشون ونحمي الكوكب، في حين نساعد عملائنا على القيام بالمثل.
الانتماء في فودافون ليس مفهوماً فحسب؛ بل هو حي ومتنفس ومُ cultivates من خلال كل ما نقوم به. ستكون جزءاً من مجتمع عالمي ومتعدد يعج بعقول ومواهب وخلفيات وثقافات مختلفة. نحن ملتزمون بزيادة التنوع وضمان التمثيل المتساوي وجعل فودافون مكاناً يشعر فيه الجميع بالأمان والقيمة والشمول.