Vodafone
IT Policy and Controls Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Join Us
At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.
What you’ll do
The IT Policy & Controls Manager is responsible for developing the methodology and framework for managing IT security controls to reduce risk in line with Vodafone’s tolerance. They will also oversee programmes to implement and improve these controls as part of the IT control framework, or other related programmes as required. The outcome is that the organisation is more effective at reducing risk in an agile and dynamic way.
The role holder will also support the process of wider cyber & IT controls testing for Vodafone Group Technology as part of Vodafone’s Cyber Health & Adaptive Risk Method (CHARM). This involves the alignment of controls and scope between Vodafone Group and Local Markets and managing control effectiveness throughout the year alongside continuous improvement of controls design.
They will be required to influence and guide colleagues from Cyber Security, wider Technology and in all markets and functions as well as collaborating with other functions including Privacy and Corporate Security.
They will have the primary responsibility to develop, document, and set up processes to update and enhance the IT control framework in line with our Cyber and Technology strategies. They will define criteria for control effectiveness and measurement as well as advising on tools to support the methodology.
- Help establishing a governance model, which clarifies control ownership, scope and dependencies between Vodafone entities.
- Work closely with risk management and assurance teams and ensure that the methodology properly supports the integration of risks, controls and assurance in order to deliver true risk reduction value.
- Support security improvement initiatives and projects and help prioritising and delivering capabilities, which meet or surpass the requirements defined in the control framework.
Expected to have a strong knowledge of security risks, controls, processes / technologies / tools to mitigate these risks and Information Security Management Systems.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Key accountabilities and decision ownership:
- Maintain and develop a control framework which is fit for purpose to address the changing IT Security risk landscape.
- Maintain the formal documentation of the methodology.
- Provide guidance to other staff on the methodology, control implementation and best practice. Identify best practice / improvement opportunities and share with control owners to improve the efficiency and effectiveness of their controls.
- Lead the implementation of the methodology and operation activities performed across Vodafone and provide a consolidated status view to management.
- Obtain and implement input from subject matter experts and operational teams for developing continuous improvement of control framework and KPIs /KRIs.
- Work with stakeholders from other compliance and audit functions to streamline and align methodologies used and lead on audit actions.
- Assess the effectiveness of IT Controls owned by Vodafone Technology and manage the risk of control deficiencies affecting supported business controls.
- Contribute to the maintenance of the CHARM framework.
Who you are
Core competencies, knowledge and experience:
- 10+ years technical experience in complex IT environments.
- Familiarity with security risks and controls (processes, technologies, tools) to mitigate these risks as well as hands-on experience with the design, implementation and operation of a methodology to manage the controls.
- Preferably knowledge of ITIL and ISO 27001 processes and controls.
- Attention to detail, strong analytical skills, efficient problem-solving capability.
- Strong oral and written communication skills including the ability to communicate complex matters in simple terms.
- Experienced in managing stakeholders at different levels up to senior management.
- A self-starter and good team player, used to work in a global environment and ability to adapt style to different cultures and audiences, well organised with a high degree of flexibility.
- Fluent English language skills.
Must have technical / professional qualifications:
- University graduate or equivalent in business/technology studies.
- Knowledge and experience of different technologies (web applications, infrastructure, operating systems, databases, SAP and Cloud).
- A grounding in security, risk or compliance, ideally backed up with relevant certification or qualifications, experience in working with security frameworks such as ISO 27001, ideally audit experience.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Not a perfect fit?
Worried that you don’t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you’re excited about this role but your experience doesn’t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.
What's in it for you
- Yearly bonus: 10%
- Annual leave: 28 days + bank holidays
- Charity days: 5 days/year
- Maternity leave: 52 weeks: the first 13 weeks are fully paid, followed by 26 weeks of half pay
- Private pension: You can contribute up to 5% of your basic pay with 2:1 matching from Vodafone up to 10%.
- Access to: private medical, private dental, free health assessments, share save scheme
- Additional discounts: Vodafone retail, gym, cinema, cycle to work, season ticket loan
Who we are
We are a leading international Telco, serving millions of customers. At Vodafone, we believe that connectivity is a force for good. If we use it for the things that really matter, it can improve people's lives and the world around us. Through our technology we empower people, connecting everyone regardless of who they are or where they live and we protect the planet, whilst helping our customers do the same.
Belonging at Vodafone isn't a concept; it's lived, breathed, and cultivated through everything we do. You'll be part of a global and diverse community, with many different minds, abilities, backgrounds and cultures. We're committed to increase diversity, ensure equal representation, and make Vodafone a place everyone feels safe, valued and included.
If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, please refer to https://careers.vodafone.com/application-adjustments/ for guidance.
Together we can.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location