This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
In this role you will provide Security Architectural support to projects that have engaged with Secure by Design, providing guidance to projects and BAU activities across the following UK business functions. The purpose of the role is to: Ensure Security is embedded in IT and Digital Systems including planning, designing, and building phase; Define technical security controls for efficient implementation; Ensure compliance with Legal and Regulatory requirements; Fulfil Key Customers obligations and Stakeholders expectation; Ensure security architecture activity is timely delivered to support other technology and business functions; Contribute to, define and assess complex design proposal.
Job Responsibility:
Provide Security Architectural support to projects that have engaged with Secure by Design, providing guidance to projects and BAU activities
Ensure Security is embedded in IT and Digital Systems including planning, designing, and building phase
Define technical security controls for efficient implementation
Ensure compliance with Legal and Regulatory requirements
Fulfil Key Customers obligations and Stakeholders expectation
Ensure security architecture activity is timely delivered to support other technology and business functions
Contribute to, define and assess complex design proposal
Develop and document end-to-end architecture that will protect the IT and Digital Systems from the significant and persistent cyber security threat
Ensure system architecture is developed adequately to protect the availability, confidentiality and integrity of IT Systems
Develop architecture in conjunction with Group and European region technical architects and influence them to support the UK position
Engage with the business functions to understand their future roadmaps and ensure that appropriate Cyber Security engagement takes place to support these roadmaps
Provide technical leadership and task direction to other Secure by Design managers, Specialists as well as Cyber Security Champions across Technology and other business functions
Work with project teams to produce solutions that comply with internal security policies, standards and the security architecture
Embed effective security practices into IT & Digital processes (Agile, DevSecOps, CI/CD etc)
Provide Cyber Security guidance, design input and design review/assessment
Review and approve end to end connectivity across Vodafone networks
Specify security testing and ensure that identified vulnerabilities are remediated
Identify Cyber Security risks and ensure that these are managed effectively
Lead relevant Regulatory and Compliance initiatives for Secure by Design
Review telecoms project designs and architectures against the company’s cyber security policies and communicate this to project teams
Assess project designs against requirements, including the UK Telecommunications Security Act (TSA)
Guide and embed effective security controls into Network architectures
Provide Cyber Security guidance, design input and design review/assessment of complex changes
Specify and scope security penetration testing of complex designs, and ensure that identified vulnerabilities are remediated
Assist members of the Secure by Design Networks team with understanding of designs
Provide leadership, updates and guidance for cyber control implementation and their ongoing assessment and improvement
Requirements:
Educated to degree level and/or relevant technical experience (preferably 7+ years) with a proven track record of delivering complex cross-domain IT/IS solutions architectures/designs in the telecommunications industry
Minimum of 5+ years of experience in a Security role
Knowledge of common information technology management / compliance frameworks such as ISO/IEC 27001, SOC 2, SOX, ITIL, COBIT, and NIST
Knowledge of legal, regulatory and privacy requirements, such as Personally Identifiable Information (PII) Protection and Payment Card Industry (PCI)/Data Security Standard
An ability to think strategically and drive change
A deep understanding of Security risks and mitigating solutions
A diverse security background with knowledge in several areas including DNS, routing, authentication, VPN, proxy services and DDOS mitigation technologies
Knowledge in Windows, UNIX and Linux operating systems
Practices and methods of enterprise architecture and security architecture
IT security architecture development and definition
Web Security & Encryption
Strong organizational skills
Ability to work under time and resource pressure
An ability and desire to communicate and work with a broad set of stakeholders
A customer-focused, responsive, and transparent attitude
Competent in understanding solution designs and equipment configurations used to deliver a wide range of IT and telecommunications solutions
Competent in applying security policies and principles defined in security architecture to real world scenarios
Understands and applies risk management principles
Effective communication skills to influence stakeholders and explain complex security requirements in simple terms
Establishing and maintaining single point of contact relationship with key project manager(s)
An industry security certification. CISSP is strongly preferred