This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a Cyber Security Assurance Tech Lead to join our team and play a key role in delivering and supporting penetration testing and security assurance activities across Vodafone’s digital environment. This role is responsible for performing penetration testing engagements, supporting security assessment activities, conducting vulnerability analysis, and ensuring the security posture of web applications, mobile platforms, networks, and cloud environments. As a Cyber Security Assurance Tech Lead, you will work closely with technical teams, vendors, and business stakeholders to identify, assess, and remediate security vulnerabilities while ensuring compliance with Vodafone’s cyber security policies, standards, and best practices.
Job Responsibility
Perform penetration testing activities on web applications, mobile applications, networks, APIs, and cloud environments to identify security vulnerabilities and weaknesses
Support penetration testing activities conducted internally or through third-party vendors, ensuring proper execution and reporting
Conduct vulnerability assessments and security analysis, providing remediation recommendations to improve the overall security posture
Validate secure implementation and acceptance of new technologies, systems, and infrastructure in alignment with Vodafone security policies and standards
Perform regular security assurance activities on existing applications and environments to ensure continuous compliance and protection against emerging threats
Participate in security risk assessments for new projects and initiatives, ensuring security risks are identified and mitigated during early project phases
Collaborate with technical teams and business stakeholders to track and remediate penetration testing findings in a timely manner
Review and validate penetration testing reports, ensuring findings are properly documented with clear remediation guidance
Stay up to date with emerging cyber threats, vulnerabilities, attack techniques, and industry best practices to continuously improve penetration testing and security assurance capabilities
Requirements
Strong knowledge of security frameworks and methodologies such as MITRE ATT&CK, NIST, OWASP, and CIS Controls
Hands-on understanding of penetration testing methodologies for web, mobile, network, API, and cloud environments
Familiarity with hardening and secure configuration practices for servers, databases, operating systems, and applications
Experience in vulnerability assessment, risk analysis, and providing security recommendations aligned with business requirements
Ability to work collaboratively with cross-functional teams to identify, prioritize, and remediate security vulnerabilities
Strong analytical, troubleshooting, and problem-solving skills with the ability to communicate technical findings to both technical and non-technical stakeholders
Nice to have
Relevant certifications are considered a plus (OSCP, eWPTX, eCPPT, CEH, PNPT, or similar)