Information Security Analyst - Product Assurance
Information Security Analyst - Product Assurance

Information Security Analyst - Product Assurance

Coventry Full-Time 36000 - 60000 £ / year (est.) Home office (partial)
Go Premium
Sainsbury's

At a Glance

  • Tasks: Ensure secure product development and maintain robust security across our environment.
  • Company: Join Sainsbury's, a leading retailer committed to innovation and inclusivity.
  • Benefits: Enjoy discounts, flexible working, bonus schemes, and a supportive work-life balance.
  • Why this job: Make a real impact on data security while working with cutting-edge technologies.
  • Qualifications: Experience in information security and strong stakeholder management skills required.
  • Other info: Opportunities for growth and development in a dynamic tech environment.

The predicted salary is between 36000 - 60000 £ per year.

Overview

In a nutshell

As an Information Security Analyst in the Data Governance and Information Security Team, you will be working within the Product Assurance team who are responsible for ensuring our Engineering and Development communities are building and maintaining secure products through their entire lifecycle.

You will be continually reviewing our security posture and setting the direction on how best to make improvements in line with the evolving threat landscape and core business objectives.

What you need to do

As an Information Security Analyst, you will have good all round Infosec experience coupled with finely honed Stakeholder Management skills to ensure that robust security is maintained across our environment.

  • Work in a flexible, agile manner within Engineering Families, whilst maintaining appropriate levels of challenge and governance
  • Ensure security is built in by design, products are delivered securely with client and employee data appropriately protected
  • Define Security Non-Functional Requirements for each project and ensure that they are fulfilled prior to going into service, ensuring the relevant technology standards are applied to specific projects
  • Liaise with the Information Security Testing Team to ensure that Ethical Hacking, Code Reviews, Application Scanning, and Infrastructure Scanning is conducted
  • Provide end to end assurance of IT products across the Group, throughout its lifecycle, providing approvals where appropriate
  • Articulate risk in technical and non-technical terminology so that it can be interpreted by IT and Business individuals alike
  • Help identify, assess, and manage strategic, operational and emerging risks affecting the Cloud and Data, and articulate, quantify and monitor risks according to risk appetite
  • Build and maintain strong senior stakeholder relationships within technology and the business to understand security risk and drive robust risk-based decision making
  • Effectively articulate technical issues to business units and engineering teams
  • Liaise with third-party strategic partners and providers who support Sainsbury’s

What you need to know and show

  • Proven experience demonstrating technical understanding of security to ensure systems are designed and built securely and to help continually improve our security posture
  • Appreciation of containerisation technologies such as Docker, Kubernetes etc.
  • Fundamental knowledge of logging, monitoring, load balancing/proxies and API gateways
  • Fundamental knowledge of GitHub, Jenkins & Jira
  • Basic knowledge of the OWASP Top 10, Mitre ATT&CK, NIST frameworks, PCI-DSS and Cyber Kill Chain
  • Fundamental understanding of PAM, EDR, AV, IPS, SIEM, WAF and DLP technologies
  • The ability to verify solutions and gain assurance that they are fit for purpose through demonstrable evidence of controls and testing
  • Strong understanding of the changing threat landscape and how this may affect our systems
  • The ability to challenge concerns and report through appropriate channels
  • Self-drive, motivation and the ability to work independently to deliver expected outcomes
  • In-depth understanding of data and security risks in a large enterprise
  • Risk & Vulnerability Management experience and understanding of Risk & Vulnerability Management Frameworks
  • Strong analytical and report writing skills
  • Experience with serverless cloud technologies such as AWS storage and Lambda functions

Desirable Qualifications

You will have one (or more) of the following:

  • CompTIA Security+, Network+, Linux+, Cloud+, Data+, DataSys+
  • CSA CCSK / CCAK
  • AWS Certified Security
  • Microsoft Azure Security Engineer Associate
  • (ISC)² CISSP / CCSP / SSCP
  • ISACA CISA / CISM / CRISC / CGEIT
  • MSc. Information/Cyber Security

Benefits and work-life information

As well as lots of on-the-job training and endless opportunities, you\’ll get:

  • Colleague discount across our multi-brands – Sainsbury\’s, Argos, TU Clothing and Habitat
  • Holiday allowance
  • Bonus scheme
  • Pension plan
  • Special offers on gym memberships, restaurants, holidays, retail vouchers and more

Work-life balance is important to us, so we offer colleagues as much flexibility as possible in line with the needs of their role. We trust them to decide how, where and when they work, combining remote and collaborative working with a flexible approach to hours, giving them plenty of time and space for life outside of work whilst delivering against our business goals.

Additional information

We are committed to being a truly inclusive retailer, so you’ll be welcomed whoever you are and wherever you work. Around here, there’s always the chance to try something new – whether that’s as part of an evolving team or somewhere else across the business – and we take development seriously and promise to support you. When you join our team, we’ll also offer you an amazing range of benefits. Here are some of them:

  • Starting off with colleague discount, you\’ll be able to get 10% off at Sainsbury\’s, Argos, TU and Habitat after 4 weeks. This increases to 15% off at Sainsbury’s every Friday and Saturday and 15% off at Argos every pay day
  • Pensions scheme and life cover
  • Opportunity for a performance-related bonus of up to 10% of salary, depending on performance
  • Annual holiday allowance and options to buy additional holiday
  • Other money-saving benefits such as season ticket loans, cycle to work scheme, health cash plans, pay advance, discounts from retailers
  • Employee assistance programme

Moments that matter are as important to us as they are to you which is why we give up to 26 weeks’ pay for maternity or adoption leave and up to 4 weeks’ pay for paternity leave.

Please see www.sainsburys.jobs for a range of our benefits (note, length of service and eligibility criteria may apply).

Responsibilities

We’d all like amazing work to do, and real work-life balance. That\’s waiting for you at Sainsbury’s. Think about the scale it takes for us to feed the nation. The level of data, transactions and variety it involves. Then you’ll realise that ours is a modern software engineering environment because it has to be. We’ve made serious investment into a Tech Academy and into setting standards and principles. We iterate, learn, experiment and push ways of working such as Agile, Scrum and XP. So you can look forward to awesome opportunities in everything from AI to reusable tech.

#J-18808-Ljbffr

Information Security Analyst - Product Assurance employer: Sainsbury's

Sainsbury's is an exceptional employer that prioritises employee growth and work-life balance, offering a flexible working environment that allows you to thrive both personally and professionally. With a commitment to inclusivity and continuous development, you'll have access to extensive training opportunities and a range of benefits including generous discounts, a performance-related bonus scheme, and comprehensive support for your well-being. Join us in a dynamic team where your contributions directly impact the security of our innovative products and services.
Sainsbury's

Contact Detail:

Sainsbury's Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Security Analyst - Product Assurance

✨Tip Number 1

Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just grab a coffee with someone who works in InfoSec. You never know who might have the inside scoop on job openings!

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to security. This gives potential employers a tangible look at what you can do and sets you apart from the crowd.

✨Tip Number 3

Prepare for interviews by brushing up on both technical and non-technical aspects of InfoSec. Be ready to discuss how you would articulate risks and solutions to different stakeholders. Practice makes perfect, so consider mock interviews with friends or mentors.

✨Tip Number 4

Don’t forget to apply through our website! We’ve got loads of opportunities waiting for you, and applying directly shows your enthusiasm for joining our team. Plus, it’s super easy to keep track of your applications that way!

We think you need these skills to ace Information Security Analyst - Product Assurance

Information Security
Stakeholder Management
Security Non-Functional Requirements
Ethical Hacking
Application Scanning
Infrastructure Scanning
Risk Assessment
Cloud Technologies
Containerisation (Docker, Kubernetes)
Logging and Monitoring
API Gateways
OWASP Top 10
NIST Frameworks
Risk & Vulnerability Management
Analytical Skills

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Information Security Analyst role. Highlight your relevant experience, especially in security frameworks and stakeholder management. We want to see how your skills align with our needs!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how you can contribute to our Product Assurance team. Keep it engaging and personal – we love a good story!

Showcase Your Technical Skills: Don’t forget to mention your technical know-how! Whether it's your experience with containerisation technologies or your understanding of the OWASP Top 10, make sure we see your expertise clearly. We’re looking for someone who can hit the ground running!

Apply Through Our Website: We encourage you to apply through our website for a smoother process. It’s the best way for us to receive your application and keep track of it. Plus, you’ll find all the details you need about the role there!

How to prepare for a job interview at Sainsbury's

✨Know Your Stuff

Make sure you brush up on your technical knowledge, especially around security frameworks like OWASP Top 10 and NIST. Be ready to discuss how these apply to the role and how you've used them in past experiences.

✨Speak Their Language

Practice articulating complex security concepts in simple terms. This will help you connect with both technical and non-technical stakeholders during the interview, showcasing your ability to bridge the gap between IT and business.

✨Showcase Your Experience

Prepare specific examples from your previous roles that demonstrate your understanding of risk management and vulnerability assessments. Highlight any experience with tools like GitHub, Jenkins, or cloud technologies, as these are key for the position.

✨Ask Smart Questions

Come prepared with insightful questions about the company's security posture and how they handle emerging threats. This shows your genuine interest in the role and helps you assess if the company aligns with your career goals.

Information Security Analyst - Product Assurance
Sainsbury's
Location: Coventry
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>