This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a Secure by Design – Artificial Intelligence professional to ensure that Vodafone’s products, platforms, services, and AI-driven solutions are developed with robust security and privacy controls from the outset. The individual will guide teams through the SPDA (Security, Privacy & Design Assessment) process, review solution documentation, strengthen risk management, and support compliance with global security frameworks, particularly in AI environments. This role supports security validation across environments, assesses risks for AI/GenAI use cases, and collaborates closely with privacy, cyber, and engineering teams to embed secure-by-design principles across the organisation.
Job Responsibility:
Oversee the Group SPDA assessment process from initiation to sign‑off and guide product teams throughout
Review HLDs, BSRs, risk items, and penetration test findings to identify necessary security and privacy controls
Collaborate with Local Privacy, Corporate Security, and Secure by Design teams to ensure complete SPDA coverage
Ensure SPDA outcomes are reflected in Risk Registers and Personal Data Processing Registers
Support and coordinate the penetration testing lifecycle—from onboarding to final reporting
Maintain awareness of the AIB Platform architecture, capabilities, and existing security controls to align AI use cases
Apply knowledge of AI/GenAI methods such as RAG pipelines, LLM‑enabled automation, and AI agents within SPDA considerations
Track mitigation plans through to closure or escalate them to cyber risk governance where required
Provide security validation across environments (lab to pre‑prod to prod)
Ensure ongoing alignment of SPDA activities with GDPR requirements and Vodafone security policies
Work collaboratively with architecture, engineering, risk, corporate security, and ethical hacking teams to support secure delivery
Engage suppliers and partners to ensure alignment with Vodafone’s security expectations
Requirements:
Experienced IT and cyber security professional with deep expertise in securing Office IT products and services
Strong understanding of AI governance, AI security frameworks, Microsoft Copilot, LLM risk management, prompt security, and AI lifecycle governance
Proficient in agile working methods and knowledgeable across endpoint, cloud, and modern collaboration ecosystems
Skilled in secure identity management and familiar with Office IT‑driven technology environments
Able to communicate complex security concepts clearly to technical and non‑technical stakeholders
Holds a university degree in Information Security or equivalent
Possesses one or more relevant certifications: CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor, GIAC, TOGAF, SABSA or equivalent
Brings 5+ years of cyber security experience and 10+ years of experience with Microsoft Office 365, Microsoft Security services, and associated technologies
Has 5+ years of cloud security experience
What we offer:
Exposure to cutting‑edge AI security practices and enterprise‑scale secure‑by‑design frameworks
Opportunity to influence security strategy for high‑impact global products and AI platforms
Cross‑functional collaboration with cyber security, architecture, privacy, ethical hacking, and product teams
Development within a global organisation committed to innovation and secure digital transformation