## Join Us
At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.
Global Cyber Security’s role is to inspire trust and confidence in our customers by enabling secure connectivity. Our purpose is to proactively protect Vodafone & its customers by reducing the risks posed by security threats to Vodafone’s global technology infrastructure and the sensitive data it holds.
Responsible for leading the design, integration, and optimization of enterprise DevSecOps capabilities with a primary focus on Vulnerability Management (VM), Application Security (AppSec), and Cloud-Native Application Protection Platforms (CNAPP). This role serves as a technical leader and strategic advisor driving secure-by-design practices across CI/CD pipelines and application ecosystems.
Partners closely with application engineering, cloud, and platform teams to embed security controls into development workflows, enabling scalable and automated security outcomes across hybrid and multi-cloud environments.
## What you’ll do
* Lead the design and implementation of DevSecOps frameworks integrating security into CI/CD pipelines;
* Act as a trusted advisor to application and platform teams, influencing secure coding, build, and deployment practices;
* Define and drive security guardrails, standards, and patterns for cloud-native and application environments;
* Serve as the primary technical owner for CNAPP platforms, including onboarding, configuration, policy management, and optimization;
* Integrate CNAPP insights into engineering workflows, ticketing systems, and reporting dashboards;
* Drive enterprise VM strategy for cloud, container, and application layers;
* Advance risk-based prioritization and remediation workflows integrated into CI/CD and developer tools;
* Partner with engineering teams to reduce mean time to remediation (MTTR) and improve vulnerability posture;
* Oversee integration and tuning of SAST, DAST, SCA, and container scanning tools within pipelines;
* Architect and implement security tooling integrations into CI/CD pipelines, ensuring minimal developer friction;
* Enable shift-left security practices with automated checks, policy enforcement, and feedback loops;
* Collaborate with DevOps teams to standardize pipeline security templates and reusable modules;
* Work closely with cloud engineering, SRE, infrastructure, and application teams to align on security priorities;
* Influence vendor strategy and tool selection for DevSecOps and CNAPP capabilities;
* Represent security in architecture reviews, change control boards, and major transformation initiatives;
* Define and track KPIs such as vulnerability aging, pipeline coverage, and policy compliance;
* Lead continuous improvement initiatives to enhance automation, scalability, and developer experience.
## Who you are
* BA/BS in Information Systems, Computer Science, or related field;
* Strong knowledge across multiple domains, including: Cloud Security (AWS, Azure, GCP), Application Security (SAST, DAST, SCA, IaC), Secrets Scanning, API Security, Cloud Security, Container & Kubernetes Security, Vulnerability Management & Risk Prioritization and Security Architecture & Design;
* Experience with infrastructure-as-code (IaC) security, API integrations, and automation scripting;
* Demonstrated ability to partner with engineering teams and influence security adoption without direct authority;
* Experience driving enterprise-wide security initiatives and standards;
* Knowledge of Wiz, Prisma Cloud, ICS (Rapid7) (CNAPP), Qualys, MEND, SonarQube (AppSec);
*...
Want jobs like this matched to you?
SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.