At a Glance
- Tasks: Lead security initiatives and partner with teams to enhance security maturity.
- Company: Join Tesco, a leading retailer committed to serving customers and communities sustainably.
- Benefits: Enjoy flexible working patterns, remote options, and a diverse, inclusive culture.
- Why this job: Be part of a dynamic team that empowers innovation while prioritising security.
- Qualifications: Experience in web technologies, cloud services, and application security is essential.
- Other info: Embrace a culture of collaboration and continuous learning in a rapidly evolving tech landscape.
The predicted salary is between 48000 - 84000 £ per year.
As a Cyber Security Partner; you will transform the security maturity of key product areas and teams. You will be the face of security group for them. Everything you do is in the context of the product; roadmap; its risk acceptance level; the technology stack; and its architecture. You build a comprehensive understanding of the threat landscape and its potential risks to the business. Through effective partnership, you engage the leadership to make well-informed decisions about security and privacy. About our Security Partnering team: We are a team of 15+ individuals and continuing to grow. Our team aids Tesco technology and software development teams with groundbreaking technologies across cloud and other innovative platforms at scale. We have a new role to lead security partnerships to drive and be responsible for security initiatives for an engineering domain. Tesco technology comprises of several domains and over 120 teams developing software who are responsible for their own security, so we act differently than a traditional security team. We’re team of security partners, not security police. We go as far as calling ourselves as Security Partners, not Security Architects or Consultants. Security Partnering team is part of Security & Capability group that offers the enterprise with various security solutions and capabilities. Our software engineering teams have tremendous freedom in their work and the corresponding responsibility to do the right thing for our customers. Instead of controlling our engineering teams with process and security gates, we enable them to innovate by providing security mentorship to make right decisions for Tesco. The good news is that our engineering teams are (usually) willing partners in doing better security, more efficiently and earlier in the process. We want you to help us scale out and represent ourselves for the wider engineering domain. Tesco has fully embraced DevOps and agile methodologies to develop our enterprise APIs, services and cloud capabilities. Our 100+ delivery teams have loads of Docker, Kubernetes and microservices galore across Azure and AWS, so our security approach must work with elastic, here today, gone tomorrow infrastructure. Our security approaches should be event-driven, real-time and effective. Weekly scans are so 2010. Build a good understanding of the aligned verticals, the technology architecture, the criteria and constraints, the security posture and technical debts. Understand the threat landscape and take a risk-based approach on security. Drive security initiatives such as developing security requirements, threat modelling, strengthening application security, vulnerability reduction, etc., across that product areas. Review architecture and design for security problems, indulge in enabling software development teams to use security capabilities and tooling provided by Tesco. Be ready to review critical code, build pipelines, deployment methods, etc and assist teams in doing better security overall. Apply security and privacy principles in your daily job. Facilitate risk remediation but also challenge decisions and status-quo. Facilitate in assurance activities like penetration testing, purple testing, app assurance. Develop quarterly/monthly plans for security activities and collaborate on them with team members. Be an evangelist for security, take part in strengthening Tesco\’s internal policies and standards. Strong written and verbal communication skills. Strong problem solving, analysis and computational skills. Drive tactical vs. strategic decision making. Be an advocate for change. Work experience in customer-facing solutions, web technologies, payment systems, content delivery networks, REST APIs, micro services, modern application development. Understand every-growing threat landscape and identify business risks. Good understanding of public cloud services and various architecture patterns. Good understanding of software, network and infrastructure security. Deeper understanding of application security and DevSecOps (the shift-left culture) General security principles, privacy principles, industry standards such as NIST, ISO27001, CIS, MITRE framework. Preferred Azure or AWS cloud security certifications What’s in it for you Package Description Our vision at Tesco is to become every customer\’s favourite way to shop, whether they are at home or out on the move. Our core purpose is ‘Serving our customers, communities and planet a little better every day’. Serving means more than a transactional relationship with our customers. It means acting as a responsible and sustainable business for all stakeholders, for the communities we are part of and for the planet. We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We\’re committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We’re proud to have been accredited Disability Confident Leader and we’re committed to providing a fully inclusive and accessible recruitment process. For further information on the accessibility support we can offer, please click here. We’re a big business and we can offer a range of diverse full-time & part-time working patterns across our many business areas, which means that we can find something that works for you. We work in a more blended pattern – combining office and remote working. Our offices will continue to be where we connect, collaborate and innovate. If you are applying internally, please speak to the Hiring Manager about how this can work for you – Everyone is welcome at Tesco. #J-18808-Ljbffr
Cyber Security Partner (II) employer: Tesco
Contact Detail:
Tesco Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Partner (II)
✨Tip Number 1
Familiarise yourself with Tesco's technology stack and the specific tools they use, such as Docker, Kubernetes, and cloud services like Azure and AWS. Understanding these technologies will help you engage effectively with the engineering teams and demonstrate your capability to drive security initiatives.
✨Tip Number 2
Network with current employees in the Security Partnering team or related departments. Engaging with them on platforms like LinkedIn can provide insights into the team culture and expectations, which can be invaluable during interviews.
✨Tip Number 3
Stay updated on the latest trends in cybersecurity, especially regarding DevSecOps and risk management. Being able to discuss recent developments or case studies during your conversations will showcase your passion and knowledge in the field.
✨Tip Number 4
Prepare to discuss how you would approach building security partnerships within a DevOps environment. Think about examples from your past experiences where you successfully collaborated with teams to enhance security without hindering innovation.
We think you need these skills to ace Cyber Security Partner (II)
Some tips for your application 🫡
Understand the Role: Before you start writing your application, make sure you fully understand the responsibilities and requirements of the Cyber Security Partner role. Familiarise yourself with Tesco's approach to security and how it integrates with their technology and product development.
Tailor Your CV: Highlight relevant experience in cyber security, particularly in areas like risk management, threat modelling, and application security. Use specific examples from your past roles that demonstrate your ability to partner with engineering teams and drive security initiatives.
Craft a Compelling Cover Letter: In your cover letter, express your passion for security and your understanding of the evolving threat landscape. Discuss how your skills align with Tesco's values and how you can contribute to their mission of enabling innovation while ensuring security.
Showcase Communication Skills: Since strong written and verbal communication skills are essential for this role, ensure your application is clear, concise, and free of jargon. Use straightforward language to convey your ideas and experiences, demonstrating your ability to communicate effectively with both technical and non-technical stakeholders.
How to prepare for a job interview at Tesco
✨Understand the Role and Responsibilities
Before the interview, make sure you have a solid grasp of what being a Cyber Security Partner entails. Familiarise yourself with Tesco's security initiatives, the technology stack they use, and how your role will impact their product areas. This knowledge will help you articulate how your skills align with their needs.
✨Showcase Your Communication Skills
As a Cyber Security Partner, you'll need to engage with various teams and leadership. Prepare examples that demonstrate your strong written and verbal communication skills. Be ready to discuss how you've effectively communicated complex security concepts to non-technical stakeholders in the past.
✨Demonstrate Your Problem-Solving Abilities
Expect questions that assess your analytical and problem-solving skills. Prepare to discuss specific challenges you've faced in previous roles, particularly in relation to security issues, and how you approached them. Highlight your ability to drive tactical versus strategic decision-making.
✨Be Ready to Discuss Current Threat Landscapes
Stay updated on the latest trends and threats in cyber security. Be prepared to discuss how these threats could impact Tesco and how you would approach risk management. Showing that you understand the evolving threat landscape will demonstrate your commitment to proactive security measures.