At a Glance
- Tasks: Join our team to enhance security and protect our customers at Tesco Bank.
- Company: Be part of Tesco Bank, a leader in financial services with a commitment to inclusivity.
- Benefits: Enjoy competitive salary, performance bonuses, generous holidays, and a fantastic pension scheme.
- Why this job: Make a real impact in cybersecurity while developing your skills in a supportive environment.
- Qualifications: Technical understanding of vulnerabilities and strong communication skills are essential.
- Other info: Hybrid work model with opportunities for career growth and ongoing learning.
The predicted salary is between 36000 - 60000 ÂŁ per year.
Serving our customers, communities, and planet a little better every day.
Salary – Between £, - £, + annual bonus & benefits
Location – Edinburgh, Permanent
Office Attendance – Our roles are hybrid; however, you should be able to travel to our Edinburgh office 2 days per week for this position.
A chance to thrive
We’re looking for a Security Engineering Analyst to join our Vulnerability Management and Assurance team at Tesco Bank, part of Barclays Bank UK Plc. The Vulnerability Management and Assurance team are the technical experts in technical vulnerabilities and weaknesses – senior stakeholders rely on our ability to understand deeply technical topics and interpret the situation at the business level. Our team is responsible for detecting, tracking, and advising on vulnerabilities to protect the Bank and our customers.
What you’ll be doing:
- Supporting holistic improvements to our security posture – this is a broad “stem cell” role with many directions to specialise in down the line.
- Scoping and arranging pragmatic assessments and penetration tests – supporting Project assurance and Annual testing cycle alongside Consultancy and Assurance team.
- Vulnerability Scanning & Compliance Benchmarking of all our assets – working alongside our Vulnerability Management experts.
- Managing vulnerability and non-compliance data, driving improvements across the bank - liaising with teams across the bank and gaining broad exposure to various systems.
- Advising system owners, risk teams, and senior stakeholders – reporting key metrics.
We need you to have:
- Technical understanding of vulnerabilities and a familiarity with the attacker mindset.
- Familiarity with a range of security assessment types and ambition to decide, scope, and arrange pragmatic security tests to be carried out by our panel of security vendors.
- Strong understanding of security best practices and anti-patterns.
- Great communication abilities with technical and non-technical colleagues across the bank to build working relationships with other teams, spread awareness of security, and help the bank achieve required levels of protection and governance.
And if you have any of these, even better:
- Understanding of Agile practices and effectively employing the principles in a real-life workplace to improve the team’s service.
- Experience in offensive IT Security tooling and practices experience in pentesting, HackTheBox, TryHackMe).
- Understanding of current and past OWASP Top s (web / API / mobile), CVSSv2 and CVSSv3, MITRE ATT&CK, and NIST Framework.
- IT Security related achievements, publications, certifications, and other credentials.
We don’t expect you to tick every box, and if you feel you hit most of the brief, it’s worth exploring to further develop your career here with us.
What’s in it for you:
- Prepare for your retirement with our colleague pension scheme.
- Virtual GP Service days a year.
- Performance related annual bonus.
- Indulge in a generous holiday allowance with a minimum of weeks, with the opportunity to buy more.
- Embrace the benefits of our Colleague Clubcard, enjoy a % discount that increase to % every payday (worth up to 2K). As an added perk, we’ll give you a second card to share with someone else.
- Benefit from our family-oriented initiatives, encompassing enhanced maternity leave pay, a shared parental leave policy, and a generous paid paternity leave.
- A place to get on - take advantage of our ongoing learning opportunities and training, to help you achieve the job and career you want.
Everyone’s welcome
We want all our colleagues to always feel welcome and be themselves at Tesco Bank, part of Barclays Bank UK Plc. We’re committed to building a more inclusive workplace and celebrating everything that makes colleagues unique, and value the richness and diversity this brings to our business. A more diverse business helps us deliver on our purpose to serve our customers, communities, and planet a little better every day.
Security Engineering Analyst employer: Tesco Bank
Contact Detail:
Tesco Bank Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Engineering Analyst
✨Network Like a Pro
Get out there and connect with people in the industry! Attend meetups, webinars, or even local events. The more you engage with others, the better your chances of landing that Security Engineering Analyst role.
✨Show Off Your Skills
Don’t just talk about your experience; demonstrate it! Create a portfolio showcasing your projects, especially any vulnerability assessments or penetration tests you've conducted. This will make you stand out to potential employers.
✨Tailor Your Approach
When reaching out to companies, including Tesco Bank, make sure to tailor your message. Highlight how your skills align with their needs, especially in vulnerability management and assurance. Personal touches can go a long way!
✨Apply Through Our Website
We encourage you to apply directly through our website for the best chance at landing the job. It shows you're genuinely interested and gives you access to all the latest opportunities in our team!
We think you need these skills to ace Security Engineering Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV speaks directly to the role of Security Engineering Analyst. Highlight your technical understanding of vulnerabilities and any relevant experience you have with security assessments. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security and how you can contribute to our Vulnerability Management and Assurance team. Be sure to mention any specific experiences that relate to the job description.
Show Off Your Communication Skills: Since you'll be liaising with both technical and non-technical colleagues, it's important to demonstrate your communication abilities in your application. Use clear and concise language to convey your ideas and experiences, making it easy for us to understand your background.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super straightforward, and you’ll be able to keep track of your application status easily. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at Tesco Bank
✨Know Your Vulnerabilities
Make sure you brush up on your understanding of technical vulnerabilities and the attacker mindset. Be ready to discuss specific examples of vulnerabilities you've encountered and how you approached them. This will show that you not only understand the theory but can apply it in real-world scenarios.
✨Communicate Clearly
Since you'll be liaising with both technical and non-technical colleagues, practice explaining complex security concepts in simple terms. Think about how you would explain a vulnerability to someone without a technical background. This skill is crucial for building relationships and spreading security awareness across the bank.
✨Familiarise Yourself with Security Frameworks
Get to grips with frameworks like OWASP, CVSS, and MITRE ATT&CK. Be prepared to discuss how these frameworks influence your approach to vulnerability management and compliance. Showing familiarity with these standards will demonstrate your commitment to best practices in security.
✨Show Your Passion for Continuous Learning
Highlight any relevant certifications or training you've completed, and express your enthusiasm for ongoing learning opportunities. Mention any platforms like HackTheBox or TryHackMe that you've used to hone your skills. This will reflect your proactive attitude towards personal and professional development in the field of security.