At a Glance
- Tasks: Lead vendor security reviews and enhance security practices in a dynamic tech environment.
- Company: Join Just Eat Takeaway.com, a global leader in online food delivery.
- Benefits: Competitive salary, inclusive culture, and opportunities for personal growth.
- Other info: Be part of a diverse team that values growth and collaboration.
- Why this job: Make a real impact on security in a fast-paced, innovative company.
- Qualifications: Experience in security assessments and strong communication skills are essential.
The predicted salary is between 60000 - 80000 £ per year.
Ready for a challenge? Just Eat Takeaway.com might be the place for you. We’re a leading global online delivery platform, and our vision is to empower everyday convenience. Whether it’s a Friday-night feast, a post-gym poke bowl, or grabbing some groceries, our tech platform connects tens of millions of customers with hundreds of thousands of restaurant, grocery and convenience partners across the globe.
About this role
The InfoSec team at JET is scaling its security partnership and vendor assurance capability across a complex, cloud-native environment spanning multiple markets. As Security Business Partner, you will own the day-to-day delivery of vendor security reviews and shift-left security practices within engineering and product teams. You will work closely with the Security Business Partner function to embed security thinking early and give JET confidence in its third-party supply chain. Based in the UK, this is a hands-on, high-impact individual role.
These are some of the key components to the position:
- Execute vendor security assessments by collecting, analysing, and documenting supplier control evidence, audit reports, and risk findings against defined frameworks including ISO 27001 and NIST CSF.
- Identify and document third-party security risks, recommending proportionate risk treatment options aligned to JET's risk appetite.
- Support threat modelling, secure design reviews, risk remediation recommendations and early-stage risk assessments alongside engineering teams as part of the secure development lifecycle.
- Translate security findings into clear, business-aligned risk language for product and stakeholders, reducing reliance on technical jargon.
- Maintain accurate risk registers, vendor assessment records, and reporting inputs that feed into executive-level risk dashboards.
- Build working relationships with business and technology teams across multiple markets, acting as a visible and trusted point of contact for security guidance.
What will you bring to the team?
- Demonstrated ability to execute security risk assessments and vendor reviews end-to-end, including evidence collection, gap analysis, and documented findings.
- Working knowledge of security frameworks such as NIST CSF, ISO 27001, or CIS Controls applied in a product or engineering context.
- Ability to communicate security risk clearly to both technical and non-technical audiences, without defaulting to jargon or compliance-speak.
- Familiarity with GRC concepts including risk management, controls design, and third-party assurance, gained through hands-on practice rather than solely policy work.
- Comfort working across multiple teams and geographies in a fast-moving environment, managing competing priorities without losing accuracy or rigour.
- Relevant certifications (such as CISA, CRISC, or equivalent) are a plus, but not a barrier to applying if you can demonstrate the capability.
At JET, this is how we play
Our teams forge connections internally and work with some of the best-known brands on the planet, giving us truly international impact in a dynamic environment. Being the best at what we do isn’t just about delivering on our strategy. It's a competition for something incredibly valuable – our customers' choice. Every time a customer decides where to order, they're picking a side. At the heart of the JET Customer League are our values and behaviours. They guide every interaction, every decision, every innovation. These are the actions we need to perform consistently and brilliantly, to surpass the competition and earn our customers’ loyalty, again and again.
Fun, fast-paced and supportive, the JET culture is about movement, growth, helping one another to succeed and celebrating wins. By truly living our values and embodying our behaviours, we’re building a customer-first culture which enables us to stay one step ahead of the competition.
Inclusion, Diversity & Belonging
No matter who you are, what you look like, who you love, or where you are from, you can find your place at Just Eat Takeaway.com. We’re committed to creating an inclusive culture, encouraging diversity of people and thinking, in which all employees feel they truly belong and can bring their most colourful selves to work every day.
What else are we delivering?
Want to know more about our JETers, culture or company? Have a look at our career site where you can find people's stories, blogs, podcasts and more JET journeys.
Are you ready to join the team? Apply now!
Senior Business Information Security Specialist employer: Just Eat
Just Eat Takeaway.com is an exceptional employer, offering a dynamic and inclusive work culture that prioritises employee growth and collaboration. As a Senior Business Information Security Specialist, you will thrive in a fast-paced environment where your contributions directly impact our global operations, all while enjoying the benefits of a supportive team that celebrates diversity and innovation.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Business Information Security Specialist
✨Tip Number 1
Network like a pro! Reach out to current or former employees at Just Eat Takeaway.com on LinkedIn. A friendly chat can give you insider info and maybe even a referral, which can really boost your chances.
✨Tip Number 2
Prepare for the interview by diving deep into their security practices. Familiarise yourself with ISO 27001 and NIST CSF, and think about how you can apply your knowledge to their specific challenges. Show them you mean business!
✨Tip Number 3
Practice your communication skills! You’ll need to explain complex security risks in simple terms. Try explaining your past experiences to a friend who isn’t in the field – if they get it, you’re golden!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, you can tailor your application to highlight how you fit into the JET culture and values.
We think you need these skills to ace Senior Business Information Security Specialist
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the Senior Business Information Security Specialist role. Highlight your experience with security frameworks like ISO 27001 and NIST CSF, and show how your skills align with what we’re looking for at Just Eat Takeaway.com.
Showcase Your Communication Skills:Since you'll need to translate complex security findings into clear language, give examples in your application of how you've successfully communicated technical information to non-technical audiences. We love candidates who can bridge that gap!
Be Specific About Your Experience:When detailing your past roles, focus on specific projects or tasks where you executed security risk assessments or vendor reviews. Use metrics or outcomes to demonstrate your impact, as this will resonate well with us.
Apply Through Our Website:We encourage you to apply directly through our career site. It’s the best way for us to see your application and get you into the process. Plus, you’ll find loads of resources about our culture and values there!
How to prepare for a job interview at Just Eat
✨Know Your Security Frameworks
Make sure you brush up on your knowledge of security frameworks like ISO 27001 and NIST CSF. Be ready to discuss how you've applied these in past roles, especially in vendor assessments and risk management.
✨Speak Their Language
Practice translating technical security findings into clear, business-friendly language. This role requires you to communicate effectively with both technical and non-technical audiences, so think about examples where you've done this successfully.
✨Showcase Your Hands-On Experience
Prepare to share specific examples of your hands-on experience with security risk assessments and vendor reviews. Highlight your ability to collect evidence, perform gap analyses, and document findings clearly.
✨Build Relationships
Think about how you've built working relationships across teams in previous roles. Be ready to discuss your approach to collaboration and how you can act as a trusted point of contact for security guidance within the organisation.