At a Glance
- Tasks: Ensure secure product development and improve security posture in a dynamic environment.
- Company: Join Sainsbury’s, a leading retailer committed to innovation and inclusivity.
- Benefits: Enjoy discounts, flexible working, holiday allowance, and a performance-related bonus.
- Other info: Opportunities for continuous learning and career growth in a collaborative culture.
- Why this job: Make a real impact on cybersecurity while developing your skills in a supportive team.
- Qualifications: 6+ years in InfoSec, strong technical knowledge, and excellent stakeholder management skills.
The predicted salary is between 55000 - 65000 £ per year.
As a Senior Information Security Analyst in the Data Governance and Information Security Team, you will be working within the Product Assurance team who are responsible for ensuring our Engineering and Development communities are building and maintaining secure products through their entire lifecycle. You will be continually reviewing our security posture and setting the direction on how best to make improvements in line with the evolving threat landscape and core business objectives.
The ideal candidate will have significant (6+ years) experience working within Information or Cyber Security and be passionate about continuous professional development. You will be asked to provide recent, industry-respect certificates if successful at interview to demonstrate your ongoing education.
Whilst this role isn’t ‘hands-on’ candidates are expected to have an in-depth knowledge of security technologies and how these are integrated in monolithic and microservice architectures.
What you need to do:
- Provide technical, procedural and policy advice to business stakeholders and Engineers with sufficient detail.
- Review requests to ensure they comply with company policy and best security practice prior to approval.
- Conduct in-depth risk assessments and threat modelling alongside producing detailed documentation.
- Present findings to management alongside recommendations on how to secure our systems.
- Advocate for innovative security solutions through persuasive quantitative evidence and presentation.
- Mentor, engage and help educate junior colleagues across the InfoSec family.
- Support strategic initiatives to ensure cybersecurity is integrated at all phases across the business.
- Ensure that risks have been raised and being able to comprehensively explain the issues.
- Provide subject matter expertise on the InfoSec domain that the candidate is expert at.
- Evaluate requests from our suppliers to ensure they are fit for purpose.
- Deliver weekly reporting to management and other stakeholders.
- Co-ordinate complex incident response and recovery, working closely with Engineers and SOC colleagues.
- Provide support to the Information Security Manager.
What you need to know and show:
- A strong technical understanding of security to ensure systems are designed and built securely and to help continually improve our security posture.
- Familiarity with common Mobile Device and Endpoint Management solutions.
- An understanding of the Microsoft Defender suite of products.
- Awareness of Email & Web Security Gateway technologies.
- Ability to understand the operation of corporate networks and firewall solutions, including Wide Area Network considerations for multi-site deployments (inc. international).
- Consideration on how to assess the security of purchased Software-as-a-Service products.
- Familiarity with AI tooling such as Microsoft 365 / Security / GitHub Copilot.
- Experience with other common productivity & collaboration tools, such as Confluence, Miro, Adobe Cloud Suite.
- Ability to understand and assess integrations between systems through methods such as APIs, Process Automation or Batch processing.
- Nice to have knowledge of AWS, Azure, Oracle, GCP and SAP Clouds.
- Risk Management experience and understanding of Risk Management Frameworks.
- Strong analytical and report writing skills.
- Appreciation of containerisation technologies such as Docker, Kubernetes etc.
- Experience with logging, monitoring, load balancing/proxies and API gateways.
- Working knowledge of GitHub, Jenkins, Ansible, Chef and Puppet.
- In-depth knowledge of the OWASP Top 10, Mitre ATT&CK, NIST frameworks, PCI-DSS and Cyber Kill Chain.
- Familiarity with PAM, EDR, AV, IPS, SIEM, WAF and DLP technologies.
- The ability to verify solutions and gain assurance that they are fit for purpose through demonstrable evidence of controls and testing.
- Strong understanding of the changing threat landscape and how this may affect our systems.
- The ability to challenge concerns and report through appropriate channels.
- Self-drive, motivation and the ability to work independently to deliver expected outcomes.
- Excellent teamwork and problem-solving skills by blending technical knowledge with business requirements.
- In-depth understanding of data and security risks in a large enterprise.
Desirable Qualifications:
- You will have two (or more) of the following:
- CompTIA CASP+, Cloud+, Security+, Network+, Linux+
- CSA CCSK / CCAK
- (ISC)² CISSP / CCSP / SSCP
- ISACA CISA / CISM / CRISC / CGEIT
- AWS Certified Security or Certified Solutions Architect
- GCP Professional Cloud Security Engineer
- GIAC Cloud Security Automation
- Microsoft Certified Azure Solutions Architect Expert
- Microsoft Certified Cybersecurity Architect Expert
- MSc. Information/Cyber Security (not essential)
As well as lots of on-the-job training and endless opportunities, you'll get: Colleague discount across our multi-brands - Sainsbury's, Argos, TU Clothing and Habitat, holiday allowance, bonus scheme, pension plan, special offers on gym memberships, restaurants, holidays, retail vouchers and more.
Work-life balance is important to us, so we offer our colleagues as much flexibility as possible in line with the needs of their role. We trust them to decide how, where and when they work, combining remote and collaborative working with a flexible approach to hours, giving them plenty of time and space for life outside of work whilst delivering against our business goals.
Senior Information Security Analyst - Product Assurance in Coventry employer: Sainsbury's
Sainsbury's is an exceptional employer that prioritises employee growth and well-being, offering a flexible work environment across Holborn, Coventry, and Manchester. With a strong commitment to professional development, competitive benefits including generous discounts, a robust pension plan, and a focus on work-life balance, Sainsbury's fosters a collaborative culture where innovation thrives and every team member is valued. Join us to be part of a forward-thinking team dedicated to securing the future of our products and services.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Information Security Analyst - Product Assurance in Coventry
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at local meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Prepare for those interviews! Research the company and its security practices. Be ready to discuss how your experience aligns with their needs, especially around risk management and security technologies.
✨Tip Number 3
Show off your skills! Bring examples of your work or projects that demonstrate your expertise in InfoSec. This could be anything from risk assessments to innovative security solutions you've implemented.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace Senior Information Security Analyst - Product Assurance in Coventry
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Senior Information Security Analyst role. Highlight your relevant experience in InfoSec, especially any work with security technologies and risk management frameworks. We want to see how your skills align with what we're looking for!
Showcase Your Passion:In your cover letter, let us know why you're passionate about cybersecurity and continuous professional development. Share any recent certifications or training you've completed that relate to the role. We love seeing candidates who are eager to learn and grow!
Be Clear and Concise:When writing your application, keep it clear and concise. Use bullet points where possible to make it easy for us to read. We appreciate straightforward communication, especially when it comes to complex topics like security!
Apply Through Our Website:Don't forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about our company culture and values.
How to prepare for a job interview at Sainsbury's
✨Know Your Stuff
Make sure you brush up on your technical knowledge, especially around security technologies and frameworks like OWASP Top 10 and NIST. Be ready to discuss how these apply to both monolithic and microservice architectures, as this will show your depth of understanding.
✨Showcase Your Experience
Prepare to share specific examples from your 6+ years in the field. Highlight your experience with risk assessments, threat modelling, and how you've successfully communicated complex security concepts to stakeholders. This will demonstrate your ability to provide valuable insights.
✨Be a Team Player
Since mentoring junior colleagues is part of the role, think of ways you've supported others in your previous positions. Share stories that illustrate your teamwork and problem-solving skills, as well as how you’ve advocated for innovative security solutions.
✨Stay Current
The threat landscape is always changing, so be prepared to discuss recent trends and how they might impact the company’s security posture. Mention any ongoing education or certifications you’re pursuing, as this shows your commitment to continuous professional development.