IT Policy and Controls Manager

Vodafone

Greater London

Hybrid

GBP 90,000 - 120,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Yearly bonus 10%
28 days annual leave
Private pension with 2:1 match
Private medical & dental

Job summary

Vodafone seeks an IT Policy & Controls Manager to develop and govern our IT security controls framework, aligning risk management with corporate strategy. You will partner with Cyber Security, Privacy, and Audit to strengthen control effectiveness across markets.

You will lead the design, documentation and continuous improvement of the control framework, driving governance and measurable risk reduction in a global, dynamic environment.

Qualifications

  • 10+ years of technical experience in complex IT environments.
  • Familiarity with security risks and controls to mitigate these risks.
  • Knowledge of ITIL and ISO 27001 processes and controls.
  • Attention to detail and strong analytical skills.
  • Excellent written and verbal communication abilities.
  • Experience managing stakeholders up to senior management.
  • Comfortable working in a global, diverse environment.

Responsibilities

  • Develop and document the IT control framework and methodology.
  • Update and enhance the control framework in line with strategies.
  • Define criteria for control effectiveness and measurement.
  • Establish governance clarifying ownership, scope, and dependencies.
  • Collaborate with risk management, assurance and audit functions.
  • Maintain CHARM framework and drive improvement initiatives.

Skills

IT security controls
Risk management
Stakeholder management
Strong communication
Analytical skills
Security frameworks
ITIL knowledge
ISO 27001
Complex IT environments
Self-starter
Team player

Education

University degree
Technology/business studies
ISO 27001 certification

Tools

SAP
Cloud
Databases
Operating systems

Job description

Select how often (in days) to receive an alert:

At Vodafone, we’re working hard to build a better future. A more connected, inclusive and sustainable world. As a dynamic global community, it's our human spirit, together with technology, that empowers us to achieve this.

We challenge and innovate in order to connect people, businesses, and communities across the world. Delighting our customers and earning their loyalty drive us, and we experiment, learn fast and get it done, together.

With us, you can be truly be yourself and belong, share inspiration, embrace new opportunities, thrive, and make a real difference.

Join Us

At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.

What you’ll do

The IT Policy & Controls Manager is responsible for developing the methodology and framework for managing IT security controls to reduce risk in line with Vodafone’s tolerance. They will also oversee programmes to implement and improve these controls as part of the IT control framework, or other related programmes as required. The outcome is that the organisation is more effective t reducing risk in an agile and dynamic way.

The role holder will also support the process of wider cyber & IT controls testing for Vodafone Group Technology as part of Vodafone’s Cyber Health & Adaptive Risk Method (CHARM). This involves the alignment of controls and scope between Vodafone Group and Local Markets and managing control effectiveness throughout the year alongside continuous improvement of controls design.

  • They will be required to influence and guide colleagues from Cyber Security, wider Technology and in all markets and functions as well as collaborating with other functions including Privacy and Corporate Security.
  • They will have the primary responsibility to develop, document, and set up processes to update and enhance the IT control framework in line with our Cyber and Technology strategies. They will define criteria for control effectiveness and measurement as well as advising on tools to support the methodology.
  • Help establishing a governance model, which clarifies control ownership, scope and dependencies between Vodafone entities.
  • Work closely with risk management and assurance teams and ensure that the methodology properly supports the integration of risks, controls and assurance in order to deliver true risk reduction value.
  • Support security improvement initiatives and projects and help prioritising and delivering capabilities, which meet or surpass the requirements defined in the control framework.
  • Expected to have a strong knowledge of security risks, controls, processes / technologies / tools to mitigate these risks and Information Security Management Systems.


Key accountabilities and decision ownership:

  • Maintain and develop a control framework which is fit for purpose to address the changing IT Security risk landscape.
  • Maintain the formal documentation of the methodology
  • Provide guidance to other staff on the methodology, control implementation and best practice. Identify best practice / improvement opportunities and share with control owners to improve the efficiency and effectiveness of their controls
  • Lead the implementation of the methodology and operation activities performed across Vodafone and provide a consolidated status view to management
  • Obtain and implement input from subject matter experts and operational teams for developing continuous improvement of control framework and KPIs /KRIs.
  • Work with stakeholders from other compliance and audit functions to streamline and align methodologies used and lead on audit actions.
  • Assess the effectiveness of IT Controls owned by Vodafone Technology and manage the risk of control deficiencies affecting supported business controls
  • Contribute to the maintenance of the CHARM framework.
Who you are

Core competencies, knowledge and experience:

  • 10+ years technical experience in complex IT environments
  • Familiarity with security risks and controls (processes, technologies, tools) to mitigate these risks as well as hands-on experience with the design, implementation and operation of a methodology to manage the controls
  • Preferably knowledge of ITIL and ISO 27001 processes and controls
  • Attention to detail, strong analytical skills, efficient problem-solving capability
  • Strong oral and written communication skills including the ability to communicate complex matters in simple terms
  • Experienced in managing stakeholders at different levels up to senior management
  • A self-starter and good team player, used to work in a global environment and ability to adapt style to different cultures and audiences, well organised with a high degree of flexibility

Must have technical / professional qualifications:

  • University graduate or equivalent in business/technology studies
  • Knowledge and experience of different technologies (web applications, infrastructure, operating systems, databases, SAP and Cloud)
  • A grounding in security, risk or compliance, ideally backed up with relevant certification or qualifications, experience in working with security frameworks such as ISO 27001, ideally audit experience
Not a perfect fit?

Worried that you don’t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you’re excited about this role but your experience doesn’t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.

What's in it for you
  • Yearly bonus: 10%
  • Annual leave: 28 days + bank holidays
  • Charity days: 5 days/year
  • Maternity leave: 52 weeks: the first 13 weeks are fully paid, followed by 26 weeks of half pay
  • Private pension: You can contribute up to 5% of your basic pay with 2:1 matching from Vodafone up to 10%.
  • Access to: private medical, private dental, free health assessments, share save scheme
  • Additional discounts: Vodafone retail, gym, cinema, cycle to work, season ticket loan
Who we are

We are a leading international Telco, serving millions of customers. At Vodafone, we believe that connectivity is a force for good. If we use it for the things that really matter, it can improve people's lives and the world around us. Through our technology we empower people, connecting everyone regardless of who they are or where they live and we protect the planet, whilst helping our customers do the same.

Belonging at Vodafone isn't a concept; it's lived, breathed, and cultivated through everything we do. You'll be part of a global and diverse community, with many different minds, abilities, backgrounds and cultures. ;We're committed to increase diversity, ensure equal representation, and make Vodafone a place everyone feels safe, valued and included.

Vodafone is committed to attracting, developing and retaining the very best people by offering a motivating and inclusive workplace in which talent is truly recognised and rewarded. We are committed to promoting Inclusion for All with the belief that diversity plays an important role in the success of our business. We actively encourage everyone to consider becoming a part of our journey.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Policy and Controls Manager
IT Policy and Controls Manager

Vodafone Group Plc • Greater London

On-site
GBP 90,000 - 130,000
Yearly bonus 10%
28 days leave + bank holidays
Private pension with employer match
+2
IT Policy and Controls Manager London, United Kingdom Cyber Policy & Controls Posted 5 hours ago
IT Policy and Controls Manager London, United Kingdom Cyber Policy & Controls Posted 5 hours ago

Vodafone Group Plc • Greater London

On-site
GBP 90,000 - 120,000
Yearly bonus 10%
28 days annual leave
Private pension
Security Architect
Security Architect

Vodafone Group Plc • Newbury

On-site
GBP 90,000 - 120,000
Discretionary 10% yearly bonus
28 days annual leave + bank holidays
Private pension with Vodafone match
+1
Senior Manager Investment Governance
Senior Manager Investment Governance

Vodafone • Greater London

Hybrid
GBP 90,000 - 130,000
Discretionary yearly bonus
Company car
Private medical
+2
Operational & Technical Testing Lead-NW
Operational & Technical Testing Lead-NW

Vodafone • Newbury

On-site
GBP 70,000 - 90,000
Yearly bonus
Annual leave 28 days
Charity days
+4
Investments Risk & Assurance Manager London, United Kingdom Vodafone Partners
Investments Risk & Assurance Manager London, United Kingdom Vodafone Partners

Vodafone Group Plc • Greater London

On-site
GBP 85,000 - 110,000
Discretionary bonus
28 days annual leave
Private pension
+4
Exposure Management Specialist
Exposure Management Specialist

Vodafone • Newbury

On-site
GBP 60,000 - 90,000
Yearly bonus: 10%
Annual leave: 28 days + bank holidays
Charity days: 5 days/year
+8
Security Regulations Manager
Security Regulations Manager

Vodafone • Newbury

On-site
GBP 50,000 - 65,000
Yearly bonus: 10%
Annual leave: 28 days + bank holidays
Private medical and dental
+2
Interim Senior Legal Counsel
Interim Senior Legal Counsel

Vodafone • Greater London

Hybrid
GBP 90,000 - 130,000
Yearly bonus: 20%
Company car: £580 per month + private燃
Private pension: 2:1 matching up to 10
Digital Transformation Tech Authority
Digital Transformation Tech Authority

Vodafone • Greater London

On-site
GBP 90,000 - 120,000
Yearly bonus: 10%
28 days annual leave + bank holidays +
Buy/sell/carry over 5 days/year
+4