Role Purpose
The purpose of the Supplier Cyber Security Team is to measure, manage and reduce the Cyber Security risks posed by our suppliers to Vodafone. Supplier risk is recognised as one of the main sources of Cyber risk; the effectiveness of supplier controls is critical to protect Vodafone and our customer data.
This role is responsible for the cyber security risk management of the end to end lifecycle of Vodafone suppliers from contracts and onboarding to end of life including information security reviews across Vodafone UK, encompassing internal reviews and inspections of critical suppliers to ensure compliance with our security and data protection policy. The role is key in managing and reducing the Cyber Security risks posed by our suppliers across all Vodafone using tools and associated processes, covering different controls throughout the supplier lifecycle
We are in the process of delivering against our 2025 vison with the first stage being centralisation of local market supplier activities into the global team. The role supports the globalisation programme and local markets as they go through the migration to create a single worldwide capability as well as support to strategic programmes to ensure that information security obligations are met and to help develop and embed a culture of security awareness and control.
Role responsibilities include
Owning the relationship with key suppliers to implement, monitor and track the key controls needed to minimise Vodafone risk;- Tracking and reporting supplier security operational activities;
- Building a Supplier Community by owning the relationship with local markets to build expertise and drive the implementation of supplier cyber security capabilities across Vodafone markets;
- Working closely with the rest of Cyber Security, as well Vodafone Procurement Company, Group Privacy and Group Corporate Security teams to support overall supplier management and governance;
- Developing a strategy and plan to ensure that Vodafone UK customer touch points (third party call centres) are provided with appropriate security, guidance and conduct periodic security inspections to assess the effectiveness of controls.
- Providing support to the business to facilitate out-source/off-shoring strategies by conducting a risk assessment and security audit of the parties concerned where required.
- Identifying areas of continuous improvement in our tools and processes, both within the SCS team, but also with the stakeholders we impact. Taking team responsibility to project manage prioritised initiative that will deliver an improved outcome for Vodafone, our suppliers and our customers.