VULNERABILITY MANAGEMENT & SECURITY ASSESSMENT SPECIALIST
Who we are
VOIS (Vodafone Intelligent Solutions) is a strategic arm of Vodafone Group Plc, creating value for customers by delivering intelligent solutions through Talent, Technology & Transformation.
As the largest shared services organisation in the global telco industry with 30,000 FTE, our portfolio of next-generation solutions and services are designed in partnership with customers across Vodafone Group, local markets, and partner markets to simplify and drive growth. With our strategic partner Accenture, we work alongside our Vodafone customers, other Telco and tech companies to drive transformation, meet the challenges of our industry and ensure we stay relevant and resilient. This partnership is a unique, industry-first model which brings together the best of in-house and 3rd party capability.
We work with customers across 28 countries from 10 VOIS locations: Albania, Egypt, Hungary, India, Romania, Spain, Turkey, UK, Germany, Ireland, and with a network of teams in Czech Republic, Italy, Greece, and Portugal.
#VOIS #BeUnrivalled #CreateTheFuture
About this Role
We are seeking a Vulnerability Management & Security Assessment Specialist to operate and continuously enhance Vodafone’s vulnerability assessment services. This role is responsible for managing vulnerability scanning platforms, identifying and assessing security risks across infrastructure, applications and services, driving remediation activities, and ensuring vulnerability management processes are effective and aligned with organisational security requirements. The role combines technical expertise with stakeholder engagement to provide clear security insights and improve Vodafone’s overall cyber security posture.
What you’ll do
- Execute vulnerability assessments and security scanning activities across Vodafone infrastructure, services and applications.
- Manage and maintain vulnerability scanning platforms to ensure effective identification of security weaknesses.
- Perform technical security assessments and clearly articulate business risks arising from identified vulnerabilities.
- Manage and coordinate Responsible Disclosure (RD) activities, including vulnerability triage, validation, stakeholder engagement, and remediation tracking.
- Perform basic penetration testing and security assessments to identify, validate, and report security vulnerabilities across web applications and infrastructure.
- Define and support vulnerability scanning scope, scanner onboarding and assessment coverage improvements.
- Act as a technical subject matter expert for vulnerability scanning technologies and assessment methodologies.
- Proactively identify vulnerabilities and ensure timely remediation actions are tracked and implemented.
- Monitor security advisories, zero-day vulnerabilities and exploitation techniques, ensuring scanning coverage is continuously updated.
- Coordinate with infrastructure, application and security stakeholders to ensure remediation actions are completed within agreed SLAs.
- Support security hot-fix activities in collaboration with technology and application teams.
- Assist cyber incident response teams with vulnerability identification and assessment activities during security incidents.
- Develop and enhance vulnerability management processes, procedures, SOPs and reporting capabilities.
- Conduct manual security testing and basic penetration testing to validate vulnerabilities identified by automated scanners, improve finding accuracy, and reduce false positives.
- Integrate findings from multiple sources to provide a consolidated view of security posture and asset risk.
Who you are
- 7+ years of experience in vulnerability assessment, vulnerability scanner administration and security operations.
- Strong hands-on experience with Qualys VMDR, Web Application Scanning (WAS), cloud scanning and vulnerability management platforms.
- Knowledge of security testing and assessment tools including Nmap, Metasploit and related technologies.
- Strong understanding of web application security concepts, OWASP Top 10 vulnerabilities, common attack techniques, and secure coding best practices.
- Strong understanding of Windows, Linux, web applications, virtualisation technologies and infrastructure security.
- Good knowledge of network security concepts and security assessment methodologies.
- Understanding of OWASP, CVE management, SSL/PKI, IAM, two-factor authentication, perimeter security and SIEM technologies.
- Exposure to penetration testing concepts and methodologies is advantageous.
- Strong analytical, problem-solving and stakeholder communication skills.
- Experience working with global stakeholders and distributed teams.
- CEH (Certified Ethical Hacker) certification or equivalent industry-recognised security certification is preferred.
Not a perfect fit?
Concerned you may not meet every requirement? Vodafone is committed to creating an inclusive workplace where everyone can thrive. If you are excited about this role but your experience does not align exactly with every aspect of the job description, you are encouraged to apply. You may be the right candidate for this or another opportunity, and the recruitment team will support you in exploring where your skills fit best.
What's in it for you
- Opportunity to work within a global cyber security function protecting enterprise-scale infrastructure and services.
- Exposure to leading vulnerability management technologies and security assessment practices.
- Experience supporting security operations, incident response and proactive risk reduction initiatives.
- Collaboration with security, infrastructure and application teams across a global technology environment.
- Continuous learning opportunities across vulnerability management, threat research and cyber defence disciplines.
What skills you will learn
- Advanced vulnerability assessment, vulnerability research and risk prioritisation techniques.
- Enterprise-scale vulnerability management and scanner administration capabilities.
- Deeper expertise in infrastructure, cloud and application security assessment methodologies.
- Enhanced cyber security reporting, remediation governance and stakeholder management skills.
- Practical understanding of emerging threats, zero-day vulnerabilities and exploitation techniques.
VOIS Equal Opportunity Employer Commitment
Vodafone recognizes and celebrates the value of diversity in building a workforce that reflects the customers and communities it serves. No form of discrimination is tolerated. This includes, but is not limited to, discrimination based on race, colour, age, veteran status, gender identity, gender expression, sexual orientation, pregnancy, maternity or parental status, ethnicity, disability, religion or belief, political affiliation, trade union membership, nationality, citizenship, indigenous status, medical condition, HIV status, neurodiversity, social origin, cultural background, marital or civil partnership status, or socio-economic background.
Join Us
At Vodafone, we’re working hard to build a better future. A more connected, inclusive and sustainable world. As a dynamic global community, it's our human spirit, together with technology, that empowers us to achieve this.
We challenge and innovate in order to connect people, businesses, and communities across the world. Delighting our customers and earning their loyalty drive us, and we experiment, learn fast and get it done, together.
With us, you can truly be yourself and belong, share inspiration, embrace new opportunities, thrive, and make a real difference.
Alert
Apply for Vodafone jobs only through the official Vodafone Careers website to avoid job scams and fraud.” #JDEnhancedByTARA
Follow us on social media
- LinkedIn: https://www.linkedin.com/company/vois/
- Facebook: https://www.facebook.com/voisglobal
- Instagram: https://www.instagram.com/voisglobal/
- You can also chat with our employees to learn more about our projects: https://lnkd.in/dpkrcvR2