At a Glance
- Tasks: Join our team to develop and maintain cutting-edge security tools against cyber threats.
- Company: Be part of John Lewis Partnership, a leading employee-owned business in the UK.
- Benefits: Enjoy hybrid working, a supportive on-call rota, and a focus on work-life balance.
- Why this job: Shape the future of security in a collaborative environment that values innovation and diversity.
- Qualifications: Proven expertise in Security Engineering and agile delivery; relevant certifications are a plus.
- Other info: Apply early as roles may close quickly due to high demand.
The predicted salary is between 43000 - 62000 £ per year.
Apply on JLP Jobs – the official careers website for John Lewis Partnership, John Lewis & Partners, and Waitrose & Partners.
About the role
Join the Information Security Engineering team at John Lewis Partnership to help build a secure future for an iconic brand. We work to protect our customers, Partners, and business against an ever-evolving cyber threat landscape.The John Lewis Partnership’s Information Security strategy is bold and ambitious. We provide a collection of security services, delivered via people, processes and technology. Working collaboratively, these services ensure that customers can shop with us efficiently, safely and securely, every single day.Our Threat Defence team is at the forefront of our cyber resilience, proactively monitoring threats, identifying vulnerabilities, and engineering robust security defences.As we expand our Security Engineering service, you\’ll be instrumental in developing cutting-edge capabilities and empowering our Security Operations Centre to stay ahead of the latest threats.This is a great opportunity to directly shape our security posture, getting hands-on with next-generation cyber security tools. You\’ll thrive in an agile, supportive, and highly collaborative team where innovation isn\’t just encouraged, it\’s expected.
At a Glance
-
Salary:£50,000 – £74,000 depending on experience
-
Contract type: 2 Permanent and 1 Fixed term contract (up to 12 months)
-
Hybrid Working: Based at our Bracknell Head Office with a flexible hybrid model (typically 1 day per week in the office, primarily Tuesdays, with ad-hoc visits as required by business needs), we support a healthy work-life balance
-
On-Call: Participate in a supportive on-call rota (approx. 1 week in 6), with flexibility for leave and personal commitments.
What You’ll Be Doing:
In this hands-on technical engineering role, you will:
-
Develop, deploy, and maintain our critical security operations tooling, ensuring its continuous effectiveness
-
Follow agile development practices in support of our Information Security strategy
-
Lead the delivery of new and updated security tools across key domains like Email Security, Cloud Security, SaaS Security and Internet Security
-
Contribute to the continuous improvement of existing critical security tooling, such as Google SecOps (Chronicle) and SentinelOne EDR
-
Collaborate closely with Information Security colleagues, other technology teams, and strategic security vendors to build a truly secure Partnership.
What You’ll Have (Essential Skills):
-
Extensive proven Security Engineering expertise in at least one of these core areas:
-
Email Security: e.g. Secure Email Gateways, Phishing Protection
-
Cloud Security: e.g. Cloud Access Security Broker (CASB), Cloud Security Posture Management (CSPM)
-
SaaS Security:e.g. SaaS Security Posture Management (SSPM)
-
Internet Security: e.g. Zero Trust Network Access (ZTNA), Secure Web Gateway (specific experience with zScaler would be particularly beneficial)
-
-
Proven track record of successful agile delivery (Scrum or Kanban)
-
Strong collaboration skills working with development, operations, and infrastructure teams within a security context
-
In-depth working knowledge of security best practices and frameworks (e.g. Mitre ATT&CK, NIST).
Even Better If You Have (Desirable Skills):
-
Experience with SIEM tooling and detection development (Google SecOps/Chronicle proficiency is of specific benefit)
-
Background in delivering and/or maintaining EDR tooling (specifically SentinelOne engineering experience is beneficial)
-
Experience securing Google Cloud environments, utilising tools such as Google Security Command Center
-
Relevant Information Security certifications (e.g. CISSP) or a related degree.
Ready to Apply?
-
Simply upload your CV and complete our application questions.
We advise saving the application questions to a separate document before entering on Workday for future reference.
-
Internal applicants – Please click here to view the Job outline – Job Outline – SENIOR INFORMATION SECURITY ANALYST.pdf
#LI-HEADOFFICE
#LI-Hybrid
#LI-LS1
35
The partnership
We’re the largest employee owned business in the UK and home of our cherished brands, John Lewis and Waitrose. We’re not just employees, we’re Partners, driven by our purpose to build a happier world. As we look to our future, there’s never been a more exciting time to join us.
We’re ruthlessly focused on being brilliant at retail. We continue to innovate, adapt and diversify. Never Knowingly Undersold on price, quality and service in John Lewis and passionately serving food-lovers in Waitrose.
As Partners we all share the responsibility of ownership and in its rewards. We use our voices to contribute to our success, working together through the good and challenging times, holding true to our behaviours and treating everyone with kindness and respect.
We all own making the Partnership somewhere we belong. Embracing our differences and creating an environment where we’re free to be ourselves and can THRIVE. Growing ourselves individually, and as a collective.
As Partners, we make all the difference. And, we all own it.
Important points to note:
It’s important to note that some of our roles are subject to pre-employment vetting (which may include DBS checks for successful candidates). If required, you’ll be informed and provided with information about vetting during the recruitment process and we encourage you to complete any vetting documents quickly to avoid delays. Any DBS checks required will be carried out by a third-party registered body and financial probity checks may also be required for some of our roles.
We also recommend that you apply as soon as possible as vacancies can close early if we see a high number of applicants.
We want all of our Partners to have a good work-life balance and we support flexible working. This might mean flexible or compressed hours, job sharing or shorter hour contracts, where possible. Please discuss this further with the hiring manager during your interview.
#J-18808-Ljbffr
Senior Information Security Engineer employer: John Lewis Partnership
Contact Detail:
John Lewis Partnership Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Information Security Engineer
✨Tip Number 1
Familiarise yourself with the specific security tools mentioned in the job description, such as Google SecOps and SentinelOne. Having hands-on experience or knowledge about these tools will give you an edge during discussions with the hiring team.
✨Tip Number 2
Showcase your collaboration skills by preparing examples of how you've worked with cross-functional teams in previous roles. The ability to work well with development, operations, and infrastructure teams is crucial for this position.
✨Tip Number 3
Stay updated on the latest trends and threats in cybersecurity. Being knowledgeable about current events in the cyber threat landscape will demonstrate your passion and commitment to the field during interviews.
✨Tip Number 4
Prepare to discuss your experience with agile methodologies, particularly Scrum or Kanban. Highlighting your successful delivery of projects using these frameworks will align well with the expectations of the role.
We think you need these skills to ace Senior Information Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your extensive Security Engineering expertise, particularly in areas like Email Security, Cloud Security, and SaaS Security. Use specific examples from your experience that align with the job description.
Craft a Strong Cover Letter: Write a cover letter that showcases your passion for information security and your understanding of John Lewis Partnership's mission. Mention how your skills can contribute to their ambitious Information Security strategy.
Prepare for Application Questions: Before applying, save the application questions to a separate document. This will allow you to draft thoughtful responses that reflect your experience and knowledge in security best practices and frameworks.
Highlight Collaboration Skills: In your application, emphasise your strong collaboration skills. Provide examples of how you've worked with development, operations, and infrastructure teams in a security context, as this is crucial for the role.
How to prepare for a job interview at John Lewis Partnership
✨Showcase Your Technical Expertise
Be prepared to discuss your extensive experience in Security Engineering, particularly in areas like Email Security, Cloud Security, and SaaS Security. Highlight specific projects or tools you've worked with, such as Secure Email Gateways or Cloud Access Security Brokers, to demonstrate your hands-on knowledge.
✨Emphasise Agile Methodologies
Since the role involves agile development practices, be ready to share examples of how you've successfully delivered projects using Scrum or Kanban. Discuss your role in these processes and how you collaborated with cross-functional teams to achieve security objectives.
✨Familiarise Yourself with Security Frameworks
Make sure you have a solid understanding of security best practices and frameworks like Mitre ATT&CK and NIST. Be prepared to discuss how you've applied these frameworks in your previous roles to enhance security measures and mitigate risks.
✨Prepare Questions About Collaboration
The job requires close collaboration with various teams. Prepare insightful questions about how the Information Security team interacts with other departments and vendors. This shows your interest in teamwork and helps you understand the collaborative culture at John Lewis Partnership.