At a Glance
- Tasks: Lead penetration testing and enhance security for a historic retail giant.
- Company: Join Sainsbury's Tech, a forward-thinking team in a 150-year-old retail chain.
- Benefits: Enjoy discounts, flexible working, holiday allowance, and a bonus scheme.
- Other info: Be part of a diverse culture that values curiosity and continuous improvement.
- Why this job: Make a real impact on security while learning from industry experts.
- Qualifications: Extensive experience in penetration testing and strong technical writing skills.
The predicted salary is between 55000 - 65000 £ per year.
The big question: why on earth should a Tech professional like you work for a 150-year-old retail chain? Because we’re on a journey. Changing the way we operate. Learning to think nimble. Giving our teams the time and freedom they need to push boundaries. To create amazing systems and technologies. To give our colleagues and our customers even more incredible experiences. There are thousands of experts to talk to and learn from. We’ve got data from billions of transactions for our teams to play with. Things get built here. They get made here. They hit customers and colleagues quickly. Welcome to the home of Sainsbury's Tech.
About the Team
Our Data Governance & Information Security team is at the heart of protecting the organisation’s systems, data, and people. We work across all areas of the business to identify risks, strengthen defences, and ensure compliance with industry standards and regulations. We value accountability, curiosity, and continuous improvement, and we’re passionate about building a culture where security is second nature. Joining us means being part of a team that tackles evolving threats, drives awareness, and helps the organisation remain resilient and trusted.
More about the role
The Senior Information Security Tester will be engaged in delivering Penetration Testing & related services and will:
- Scope penetration testing for both internal and external facing systems
- Take ownership and perform a wide range of penetration tests in line with internal standards and SLAs, including detailed and actionable reporting through our reporting platform
- Provide expert feedback in several forums related to technical vulnerabilities and processes within and outside of the security testing team
- Perform Quality Assurance on in-house reports, vulnerability database write-ups, and any related documentation related to the security testing team’s function
- Improve internal vulnerability database write-ups to increase overall quality of all reports
- Assist other teams in understanding security vulnerabilities and implications through constructive conversations & meetings when engaged through security testing, or as part of the wider conversation
- Periodically review external penetration tests as part of ongoing vendor evaluation, along with providing formal feedback for any issues and participating in resolution meetings
- Provide mentorship to others within the team, along with assisting to fill in any knowledge gaps when identified
- Perform Purple Team activities as required, with Red Team capabilities a large advantage
- Participate in reviewing bug bounty findings and providing feedback for issues which are of high severity, complexity, and exceeding a reward threshold
- Provide advice and guidance associated with the planning, design, implementation and improvement of system security taking account of current best practice, legislation and regulation when necessary
- Help shape the security testing process by providing feedback highlighting opportunities for improvement in efficiency and ways of working
Essential
- Extensive experience performing Web Application penetration tests
- Extensive knowledge of OWASP vulnerabilities, tools and methodologies
- Strong experience performing Infrastructure penetration tests against Windows & Linux environments
- Strong experience performing build reviews against Windows & Linux hosts, MacOS a bonus
- Strong technical writing ability to write penetration test reports for technical and non-technical audiences
- Strong reporting Quality Assurance skills
- Ability to work on their own with minimal supervision and deliver on time to budget
- Demonstrates extensive knowledge of good security practice covering the physical and logical aspects of information products, systems integrity and confidentiality
- At least one of the following information security testing certifications OSWE, OSCP, GIAC or CREST (CRT or CCT)
- Ability to think methodically and logically through situations, problem solve and communicate well using both spoken and written word
- Remains visible to customers as the face of Security Testing to listen to their concerns and share these with others
- Ability to translate complex/technical issues clearly to meet the needs of the audience outside of a written report
- Ability to take responsibility, own the issue, resolve it (get the required result) and recognise how individual contributions impact team delivery
- Experience performing Purple Team activities
Advantageous
- Experience with AI & LLM penetration testing
- Experience performing Mobile penetration testing
- Experience performing Red Team activities such as phishing, social engineering, malware development and other offensive tooling development, along with knowledge of relevant frameworks
- Experience with AV & EDR Evasion
- Experience with scripting and programming languages such as C, CPP, C#, Python
- Extensive knowledge of PCI, ASV and SSDL
- Holds industry respected certifications for any penetration testing or related functions for web applications, infrastructure, mobile, AI/LLM, Red Team, etc
- Expertise in defensive tools or systems which provide access security control (i.e. prevents unauthorised system access)
- Current Information Security qualifications/certifications e.g. CISSP, CISM, CRISC, CEH etc desirable but not essential
- Experience of using Static Application Security Testing (SAST) analysis tools such as HP Fortify, Veracode, Checkmarx
- Has expert awareness of problem-solving procedures used for business-critical IT incidents, and a good awareness of their implications for a retail business
- Ability to balance the benefits of optimised security with the cost of providing it, to promote the best overall interests of the business
- Mentoring experience assisting others in the team to improve their skills
In return you’ll get
- Colleague discount across the multi-brands – Sainsbury’s, Argos and Habitat
- Holiday allowance
- Bonus scheme
- Pension plan
- Special offers on gym memberships, restaurants, holidays, retail vouchers and more
- Flexible working and job share conversations are encouraged.
Across our multi-brands, we’re proud to be an equal opportunities employer that champions a diverse and inclusive culture. If you’re reading this, even if you’re not 100% sure you’re there with your experience, we’d still love to hear from you. If you’d like to find out more head to Sainsbury's Tech.
Senior IS Tester employer: Sainsbury's
At Sainsbury's Tech, we are not just a 150-year-old retail chain; we are a forward-thinking employer committed to innovation and continuous improvement. Our vibrant work culture fosters accountability and curiosity, providing ample opportunities for professional growth through mentorship and collaboration with industry experts. With a focus on employee well-being, we offer competitive benefits including discounts across our brands, flexible working arrangements, and a commitment to diversity and inclusion, making us an exceptional place for tech professionals to thrive.
StudySmarter Expert Advice🤫
We think this is how you could land Senior IS Tester
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Sainsbury's, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Sainsbury's
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Sainsbury's. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior IS Tester
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Sainsbury's insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Sainsbury's that you’re committed to staying ahead in the game.
How to prepare for a job interview at Sainsbury's
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Sainsbury's to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Sainsbury's.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.