This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
A Senior Leader role responsible for defining and executing a risk‑based IT control testing programme to assess the design and operating effectiveness of technology controls across IT infrastructure, applications and cloud environments. The role provides end‑to‑end accountability for the testing methodology, rolling plan, standards & reporting and acts as the design owner for the testing approach and control test packs used across the in‑scope technology estate. As a Senior Leader the role leads and influences stakeholders across Technology, Operations, Risk and Audit—translating complex technical findings into clear risk insights, prioritised remediation actions and measurable improvements in control maturity. Applicants should bring deep hands‑on expertise in IT security and control testing, strong analytical judgement, and the leadership capability to set direction, coach others and drive consistent outcomes at scale.
Job Responsibility
Develop and own the IT security control testing strategy, methodology and rolling out plan
Perform operational and technical control testing across IT systems and infrastructure
Identify and report security gaps and control deficiencies including actionable remediation recommendations and collaborate with cross‑functional teams to drive timely closure
Enhance KRI reporting by defining and delivering accurate data‑driven insights that reflect the health and maturity of IT security controls, including where KRIs currently do not exist
Strengthen Vodafone’s overall IT systems & infrastructure security through structured control testing, expert technical guidance and continuous improvement aligned to industry best practices
Requirements
Strong practitioner knowledge of IT security controls, with proven ability to apply and influence their adoption across complex, large‑scale IT and cloud environments
Proven experience in designing and executing security control testing including assessment of control design and effectiveness, supported by clearly defined metrics, KRIs and testing methodologies
Ability to identify security gaps and control deficiencies, translate findings into clear and actionable remediation guidance and work with stakeholders to drive timely closure
Experience in defining, measuring and reporting IT security KPIs and KRIs with the ability to provide accurate, data‑driven insights that demonstrate control health, effectiveness and maturity to senior stakeholders
Strong ability to collaborate with cross‑functional teams across technology, operations and risk functions, effectively communicating technical security topics to both technical and non‑technical audiences
Experience in IT control testing, audit or assurance roles
Relevant industry security certifications such as CISSP, CCSP, CISM, cloud or vendor‑specific are desired but not a mandatory
Nice to have
Relevant industry security certifications such as CISSP, CCSP, CISM, cloud or vendor‑specific are desired but not a mandatory
What we offer
Yearly bonus: 10%
Annual leave: 28 days + bank holidays + the opportunity to buy/sell/carry over 5 days/year
Charity days: 5 days/year
Maternity leave: 52 weeks: the first 13 weeks are fully paid, followed by 26 weeks of half pay
Private pension: You can contribute up to 5% of your basic pay with 2:1 matching from Vodafone up to 10%
Access to: private medical, private dental, free health assessments, share save scheme
Additional discounts: Vodafone retail, gym, cinema, cycle to work, season ticket loan