This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a Cloud Security Compliance Engineer to define, build and operate a continuous cloud compliance capability across Vodafone’s global multi‑cloud environments. This role sits within the Cyber Prevent function and focuses on reducing cyber risk through secure-by-design cloud operations, strong compliance controls, and DevSecOps-aligned practices across AWS, Azure, GCP and OCI platforms.
Job Responsibility:
Define, implement and operate a continuous cloud compliance service using in‑house, commercial and open‑source tools
Manage the service roadmap from minimum viable capability to mature operations, including automated remediation
Maintain and evolve minimum configuration standards for IaaS and PaaS environments aligned to industry benchmarks and internal policies
Partner closely with cloud account owners to reduce security risk and improve compliance outcomes across platforms
Design and manage identity and access controls for cloud compliance tooling
Integrate cloud compliance services with wider security capabilities such as vulnerability management, threat intelligence and incident response
Tune compliance policies to reflect global standards, regulatory expectations and evolving risk profiles
Support operational activities including reporting, incident escalation, remediation tracking and management dashboards
Develop reusable templates, patterns and guidance to support local markets and group entities
Extend cloud security operations into adjacent areas such as automated remediation, workload protection, DevSecOps tooling, container security and perimeter controls
Requirements:
An experienced cloud security practitioner with hands‑on knowledge of AWS, Azure, GCP and OCI environments
Skilled in cloud security principles, configuration standards and industry benchmarks
Comfortable working in DevOps or DevSecOps environments with strong automation and scripting capability
Confident in engaging with technical and non‑technical stakeholders, including presenting risk and compliance insights at management level
Experienced with operating systems, networking, cloud-native security services and third‑party compliance or workload protection tools