Telecom
Developing frameworks, processes and tools to manage supplier security risks.
Building and maintaining relationships with internal stakeholders such as Legal and Procurement, and with suppliers to ensure that client’s suppliers are assessed, on-boarded, monitored and off-boarded with appropriate due diligence related to security issues.
Monitoring ongoing compliance of suppliers depending on the risk profile of the supplier.
Carrying out security assurance activities for Vodafone’s critical and high risk suppliers.
Overseeing all supporting activities, including KPI and MI reporting, flagging risks and
issue remediation.
With these activities you will have a great impact on our business:
Operate as a key subject matter expert on all supplier security assurance activities
including due diligence testing, supplier assurance assessments and security schedule contract negotiation.
Provide high-quality professional advice to business units and contract leads in areas of Corporate Security and supplier security assurance, articulating the practical risks and business impact, and agreeing solutions.
Support the ongoing identification and implementation of improvements to the Supplier Security Assurance framework to reflect the changing threat environment and best practice assurance approaches
Perform security assessments of suppliers based on their criticality, recording results accurately and initiating appropriate assurance response.
Produce high quality, informative and accurate reports in respect of supplier security assurance assessments.
Significant experience of providing security supplier assurance in a complex global organisation.
In-depth knowledge of ISO standards in relation to security and business continuity.
Excellent stakeholder management, communication and influencing skills.
Thorough understanding of supplier governance, understanding of security management processes, practices and technical countermeasures.
Ability to analyse complex information and identify key and relevant points, including communicating in a relevant and easy to understand manner.
Professional qualifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor, ISO 22301 Lead Auditor by a recognised professional body.