At a Glance
- Tasks: Join our team to uncover vulnerabilities and enhance cyber security across Tesco.
- Company: Tesco, a leading retailer committed to innovation and inclusivity.
- Benefits: Enjoy competitive salary, annual bonus, generous holiday, and private medical insurance.
- Why this job: Make a real impact in cyber security while developing your skills in a supportive environment.
- Qualifications: Experience in penetration testing and a passion for offensive security.
- Other info: Flexible hybrid working model with opportunities for career growth and continuous learning.
The predicted salary is between 50000 - 65000 £ per year.
We are passionate about step changing our cyber security capability to better protect customers and colleagues across our global business, and we're building an internal penetration testing function to complement and help further mature our defensive security capabilities. This new role challenges you to use your offensive skills to discover and demonstrate vulnerabilities and weaknesses in our systems.
Tesco Technology has hundreds of software and infrastructure engineers deploying solutions at scale using many different technology stacks, from traditional on-premise infrastructure to cloud-centric containerised deployments. Working collaboratively with our developers is key to us identifying and addressing these findings, efficiently and at scale across Tesco. You will have the opportunity to help application teams remediate issues, to help infrastructure teams to build better supporting functions and to help improve our detection and response teams by proposing new detection ideas or providing your offensive security knowledge to aid in incident response.
We believe that skilled and hard-working people are our greatest asset in reducing cyber risk to our business and customers. We encourage and support continual development and recognise the importance of keeping up with the latest technology (as well as all the older stuff) and an evolving threat landscape. Are you up for this challenge?
What is in it for you
- Annual bonus scheme of up to 20% of base salary
- Holiday starting at 25 days plus a personal day (plus Bank holidays)
- Private medical insurance
- 26 weeks maternity and adoption leave (after 1 years' service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 4 weeks fully paid paternity leave
- Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing
You will be responsible for
You'll be working in an offensively trained and defensively focused security team. Your primary responsibility will be to deliver high-quality security assessments in a variety of areas including web application, API, mobile, and infrastructure. But, unlike in a typical consultancy role, you'll also have the advantage of being able to use internal knowledge, data sources and tools to help identify attack vectors and be able to test out your hypotheses.
There will be other opportunities to stretch your skills:
- You could work with our security engineers to refine and develop our detections
- Participate in purple teaming exercises carrying out wider assessments of our security posture
- Help triage and validate findings from our bug bounty program
- Triage and validate Tesco's risk posture for newly released CVEs as part of vulnerability management
We support our colleagues on their career development and provide time and opportunities throughout the year to carry out research, as well as training supported by us to ensure you continue to develop and innovate in offensive security.
You will need
- Penetration testing experience performing authorised tests on computer systems, exposing weaknesses in security that potentially could be exploited.
- GPEN, CREST, OSCP, OSEP or other industry relevant certifications are helpful but not crucial.
- An understanding of operating system and networking fundamentals, and underlying principles
- Knowledge of preventative and detective controls (EDR, firewalls, IDS, IPS, anti-virus, etc)
- Analytical and critical thinking skills, willingness to challenge status quo
- Good written and oral communication skills
- To be comfortable working both independently, and collaboratively in a diverse team
About us
Our vision at Tesco is to become every customer's favourite way to shop, whether they are at home or out on the move. Our core purpose is 'Serving our customers, communities and planet a little better every day'. Serving means more than a transactional relationship with our customers. It means acting as a responsible and sustainable business for all stakeholders, for the communities we are part of and for the planet.
We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We're committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We're proud to have been accredited Disability Confident Leader and we're committed to providing a fully inclusive and accessible recruitment process.
We're a big business and we can offer a range of diverse full-time & part-time working patterns across our many business areas, which means that we can find something that works for you. We work in a more blended pattern - combining office and remote working. Our offices will continue to be where we connect, collaborate and innovate.
Penetration Tester - Hybrid Offensive Security in Welwyn Garden City employer: Tesco - Corporate
Contact Detail:
Tesco - Corporate Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Penetration Tester - Hybrid Offensive Security in Welwyn Garden City
✨Tip Number 1
Network like a pro! Reach out to current Tesco employees on LinkedIn or at industry events. A friendly chat can give you insider info and maybe even a referral, which can really boost your chances.
✨Tip Number 2
Prepare for the interview by brushing up on your technical skills and understanding Tesco's tech stack. Be ready to discuss how your offensive security skills can help them improve their systems.
✨Tip Number 3
Show off your passion for continuous learning! Mention any recent courses or certifications you've completed that relate to penetration testing. It shows you're committed to staying ahead in the game.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining the Tesco team.
We think you need these skills to ace Penetration Tester - Hybrid Offensive Security in Welwyn Garden City
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Penetration Tester role. Highlight your relevant experience, especially in offensive security and penetration testing. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how you can contribute to our team. Be genuine and let your personality come through – we love that!
Showcase Your Skills: Don’t just list your qualifications; demonstrate your skills! Include specific examples of past projects or challenges you've tackled in penetration testing. We’re keen to see how you’ve applied your knowledge in real-world scenarios.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our team at Tesco!
How to prepare for a job interview at Tesco - Corporate
✨Know Your Stuff
Make sure you brush up on your penetration testing skills and the latest security trends. Familiarise yourself with common vulnerabilities and how to exploit them, as well as the tools you’ll be using. Being able to discuss specific examples from your experience will show that you’re not just knowledgeable but also practical.
✨Understand Tesco's Environment
Research Tesco’s technology stack and their approach to cyber security. Knowing about their systems, such as web applications, APIs, and infrastructure, will help you tailor your answers and demonstrate that you’re genuinely interested in the role and the company.
✨Show Your Team Spirit
Since collaboration is key at Tesco, be prepared to discuss how you’ve worked with developers and other teams in the past. Share examples of how you’ve helped remediate issues or improved security measures through teamwork. This will highlight your ability to work well in a diverse team.
✨Ask Smart Questions
Prepare thoughtful questions to ask your interviewers. Inquire about their current security challenges, the tools they use, or how they measure success in their penetration testing efforts. This shows that you’re engaged and eager to contribute to their goals.