812,029open jobs
52,282companies
130,514added this week
Browse all
Salary
≈ $39k – $101k per year (Estimated)
Location
Hybrid (Lisbon, Portugal)

Confirmed on the employer's own hiring board on Sep 25, 2026. First seen by Alion on Sep 18, 2026.

Overview
Company
Impact
Profile match
Vodacom Moçambique is a telecommunications operator and mobile financial services provider. The company offers prepaid and postpaid mobile voice and data connectivity, broadband services, enterprise IT and telecom solutions, and the M-Pesa mobile money platform for digital payments, transfers, and financial inclusion services. Headquartered in Maputo, Mozambique, the enterprise serves individual consumers, small businesses, and corporate clients across the country.

Join Us

At Vodafone, we’re not just shaping the future of connectivity for our customers - we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.

Cyber Defence Operations (CDO) is Vodafone Group’s Cyber Defence Operations Centre of Excellence. CDO’s mission is to protect Vodafone customers against global cyber risk. CDO is specifically accountable for delivering:

  • Cyber Defence operational leadership across Vodafone.
  • Cyber Defence operational capabilities to Vodafone Group, the Local Market Operating Companies, and Partner Markets to enhance Vodafone’s global cyber defence posture and reduce its cyber risk.

The purpose of this role is to own the end-to-end strategy and operational assurance of threat relevant telemetry and adversary coverage to strengthen detection effectiveness across the CSOC. The role ensures that security telemetry is strategically onboarded, normalised, enriched and governed to support effective, scalable, adversary aligned detection and response across Vodafone’s environments. It strengthens CSOC maturity through a consistent, threat-led approach to telemetry strategy, coverage visibility and ingestion assurance. The role works closely with CSOC, Cyber Prevent platform teams and Local Markets to align data strategy, coverage intent, and operational outcomes, providing a strong foundation for detection engineering, threat hunting, and response.

The Detection Engineer works within the Cyber Security Operations team and operates at the intersection of threat modelling, telemetry strategy, and detection coverage.

This role is accountable for:

  • Defining what telemetry is required to detect adversary behaviour across Vodafone environments
  • Ensuring that ingested data is complete, timely, well-structured, and fit for behavioural detection use cases
  • Providing transparent, ATT&CK-aligned visibility of coverage gaps and data-driven risk

The role operates with minimal supervision and requires strong collaboration across Vodafone’s global cyber security community.

What you’ll do

  • Own the threat-led strategy for onboarding and prioritising security telemetry, ensuring data sources are aligned to MITRE ATT&CK coverage, threat modelling outputs and adversary behaviour relevant to Vodafone;
  • Own the definition of minimum viable logging requirements for CSOC, ensuring each critical platform (endpoint, identity, network, cloud, SaaS) provides the logs required to reliably observe adversary behaviour aligned to current threat models;
  • Determine which log sources are security-critical versus informational, ensuring CSOC ingestion is intentional and prioritised based on detection value rather than volume;
  • Define and govern acceptance criteria for telemetry consumed by CSOC, including data quality, enrichment, completeness, and timeliness, ensuring logs are fit for adversary aligned detection;
  • Maintain ATT&CK-aligned coverage views that demonstrate how telemetry sources map to adversary techniques, highlighting coverage gaps and their impact across platforms, environments, and Local Markets;
  • Provide clear, actionable insight into how telemetry quality and availability affect detection effectiveness, enabling Detection Engineering teams to build scalable behavioural detections;
  • Produce and maintain assurance artefacts (e.g. ATT&CK overlays, dashboards, runbooks) that demonstrate logging and monitoring effectiveness to Cyber Defence leadership, audit, and Local Market stakeholders;
  • Act as the named authority for visibility and telemetry-related risk, including documenting coverage gaps, authorising risk acceptance where required, and tracking remediation;
  • Partner with Cyber Prevent and platform teams to ensure telemetry ingestion, performance, and cost are balanced against detection and response value;
  • Influence and align Detection Engineering, Threat Intelligence, Incident Response, and Local Market SOCs on coverage priorities, standards, and ways of working;
  • Maintain operational runbooks for source onboarding/validation and hand-offs to CSOC operations and local market SOCs.

Who you are

  • Bachelor/Master's Degree in related field;
  • 4+ years in detection content, threat intelligence, hunting or offensive security;
  • Expert with MITRE ATT&CK (enterprise/cloud), ATT&CK Navigator, and threat-led control validation;
  • Hands-on with KQL/SPL/Sigma/YARA, Microsoft Defender (EDR/Identity), Sentinel, Splunk, QRadar SOAR, scripting (Python/PowerShell);
  • Adversary emulation/simulation certifications (e.g., OSCP/OSEP, GXPN/GPEN or equivalent) to design and execute controlled emulation of attacker TTPs for validation, prior ownership of simulation labs;
  • Microsoft: SC-200 (Security Operations Analyst) , Google Cloud Security certifications;
  • MITRE ATT&CK Defender training/badges (analyst, threat intel, detection mapping) or equivalent ATT&CK-focused courses;
  • Training in threat intel tradecraft (CTI lifecycle, STIX/TAXII, actor TTP analysis);
  • AI/ML in SOC (model assurance, prompt engineering for LLM-assisted triage);
  • GCTI (Threat Intel), GCDA/GCED/GCIA (defence/monitoring/intrusion analysis);
  • Strong analytical thinking and problem-solving skills, with the ability to think like an adversary and understand how threat actors operate across complex enterprise environments;
  • Deep expertise in MITRE ATT&CK (Enterprise and Cloud), with the ability to reason at technique and sub-technique level from a coverage and visibility perspective;
  • Proven ability to translate adversary behaviour into clear telemetry and logging requirements, enabling scalable, behaviour-driven detection;
  • Strong understanding of end-to-end security telemetry and logging architectures, from log generation through ingestion, enrichment, and analytic consumption;
  • Ability to identify, articulate, and prioritise visibility and detection coverage gaps as data-driven risk;
  • Experience enabling Detection Engineering teams by ensuring access to high-quality, well-structured, and consistently enriched data;
  • Confidence working across multiple security domains (endpoint, identity, network, cloud, SaaS) to assess coverage posture and response readiness;
  • Excellent communication and collaboration skills, with the ability to align Detection Engineering, Threat Intelligence, Incident Response, platform teams, and Local Market SOCs around shared outcomes;
  • Strong attention to detail when assessing telemetry quality, consistency, and completeness;
  • Fluency in English.

Not a perfect fit?

Worried that you don’t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you’re excited about this role but your experience doesn’t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.

What's in it for you

  • Hybrid Work Model - Flexible hybrid work model with 8-10 in-office days per month, managed by team leaders;
  • Vodafone Products and Services - Employees get a mobile phone, free communication plan, data card, and various discounts on services and products;
  • Recognition - Recognition programs for innovative, creative, high-potential employees and exemplary behaviors;
  • Health and Well-being - Well-being Program offers nutrition and psychological consultations, webinars, workshops, and discounts on various services and products;
  • Learning - Access to Communities of Practice and a customizable digital training platform with high-quality content (namely Harvard Business Publishing, Skillsoft and Speexx);
  • Local and International Mobility - Internal recruitment with local and international rotation opportunities across departments and roles.

Who we are

We are a leading international Telco, serving millions of customers. At Vodafone, we believe that connectivity is a force for good. If we use it for the things that really matter, it can improve people's lives and the world around us. Through our technology we empower people, connecting everyone regardless of who they are or where they live and we protect the planet, whilst helping our customers do the same.

Belonging at Vodafone isn't a concept; it's lived, breathed, and cultivated through everything we do. You'll be part of a global and diverse community, with many different minds, abilities, backgrounds and cultures. ;We're committed to increase diversity, ensure equal representation, and make Vodafone a place everyone feels safe, valued and included.

If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, please refer to https://careers.vodafone.com/application-adjustments/ for guidance.

Together we can.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
812,029 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Lisbon
≈ $69k – $181k per year (Estimated) • Hybrid • Full-Time • Lisbon
DevOps
Incident Management
Cybersecurity
ISO 27001
PCI DSS
Management
ServiceNow
ITIL
Apply
≈ $69k – $181k per year (Estimated) • Hybrid • Full-Time • Lisbon
Cybersecurity
Qualys Cloud Platform
ISO 27001
PCI DSS
Apply
$12k – $27k per year (gross) • Hybrid • Full-Time • Bangkok
Python
PowerShell
DevOps
Terraform
Ansible
CI/CD
Jenkins
AWS
Apply
≈ $18k – $43k per year (Estimated) • In office • Full-Time • Pluak Daeng
DevOps
Windows
TCP/IP
Apply
Hybrid • 5+ years exp
DevOps
IAM
Cybersecurity
NIST CSF
IoT
OPC UA
Apply
In office • TS/SCI • 5+ years exp
Python
Java
C++
DevOps
Splunk
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
IAM
Linux
Unix
TCP/IP
DNS
Cybersecurity
Microsoft Sentinel
NIST 800-53
FedRAMP
Zero Trust
SIEM
Apply
Remote (Greece) • Part-Time • Athens
Python
JavaScript
SQL
Python
Django
Databases
PostgreSQL
DevOps
GCP
DigitalOcean
Heroku
Azure
AWS
Apply
In office • 2+ years exp
Java
DevOps
Splunk
GCP
Azure
AWS
Docker
Kubernetes
IAM
Linux
Unix
TCP/IP
DNS
Cybersecurity
Microsoft Sentinel
Zero Trust
SIEM
Apply
≈ $90k – $200k per year (Estimated) • Remote (United States, Canada, ET hours) • 8+ years exp
Python
Bash
Databases
MySQL
Cassandra
Apache Kafka
AI/ML
Cursor
Claude
DevOps
Terraform
Ansible
GCP
New Relic
OpenTelemetry
Datadog
Prometheus
Azure
CI/CD
AWS
Docker
Linux
IoT
MQTT
Apply
In office • 7+ years exp • Bachelor's Degree • Bengaluru
Python
Perl
DevOps
RTOS
CI/CD
Linux
TCP/IP
Wi-Fi
IoT
MQTT
Zigbee
Management
Agile
Apply
≈ $54k – $127k per year (Estimated) • Hybrid • Master's Degree • Lisbon
Analytics
Microsoft Excel
Management
ITIL
Apply
≈ $39k – $101k per year (Estimated) • Hybrid • Lisbon
Cybersecurity
ISO 27001
Apply
≈ $29k – $65k per year (Estimated) • In office • 10+ years exp • Bachelor's Degree • Pune
Java
SQL
Databases
Oracle
DevOps
Rest API
Splunk
Zabbix
Kibana
Datadog
Dynatrace
AppDynamics
IAM
Linux
Unix
SOAP
Management
ITIL
Apply
≈ $17k – $42k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Pune
SQL
Databases
Oracle
AI/ML
Anomaly Detection
DevOps
Rest API
Splunk
Zabbix
Kibana
Datadog
Dynatrace
AppDynamics
AIOps
SLI/SLO/SLA
IAM
Linux
Unix
SOAP
Cybersecurity
Active Directory
LDAP
Management
ITIL
Apply
≈ $21k – $51k per year (Estimated) • In office • 4+ years exp • Bachelor's Degree • Pune
SQL
Databases
Oracle
AI/ML
Anomaly Detection
DevOps
Rest API
Splunk
Zabbix
Kibana
Datadog
Dynatrace
AppDynamics
AIOps
SLI/SLO/SLA
IAM
Linux
Unix
SOAP
Cybersecurity
Active Directory
LDAP
Management
ITIL
Apply
≈ $48k – $120k per year (Estimated) • Hybrid • Lisbon
Python
Ruby
Scala
AI/ML
LLM
Frontend
GraphQL
DevOps
Rest API
CI/CD
Shift-Left
Cybersecurity
OWASP Top 10
Shift-Left Security
Threat Modeling
Apply
≈ $48k – $120k per year (Estimated) • Hybrid • 6+ years exp • Lisbon
DevOps
Terraform
GCP
AWS CDK
CloudFormation
Azure
AWS
Shift-Left
IAM
Amazon CloudWatch
Cybersecurity
Okta
Wiz
Zero Trust
Shift-Left Security
Apply
Solutions Architect 2 days ago
≈ $48k – $116k per year (Estimated) • Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Lisbon
DevOps
Azure
Apply
≈ $25k – $68k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Athens • Lisbon
Apply
In office • Part-Time • Lisbon
Apply
See all jobs
This is one of many
812,029 more open roles from verified company boards, updated every day.