At a Glance
- Tasks: Join us as a DevSecOps Security Engineer to enhance security in our cloud platforms.
- Company: Tesco Mobile is the UK's largest mobile virtual network operator with over 5 million customers.
- Benefits: Enjoy perks like a 20% annual bonus, 25+ days holiday, and private medical insurance.
- Why this job: Be part of an inclusive culture that values diversity and empowers you to grow and innovate.
- Qualifications: Experience with AWS, Azure, CI/CD pipelines, and a passion for learning new skills is essential.
- Other info: Flexible working options available from day one, plus access to mental wellbeing support.
The predicted salary is between 42000 - 84000 £ per year.
About the role
As one of our DevSecOps Security Engineers, you will be helping the team manage and deploy solutions on platforms in a secure and optimised manner. This will include all aspects of security, maintaining an evolving programme of work to address prioritised concerns, helping to identify threats and risks and working to implement solutions and mitigations. You will also work with the rest of the squad to incorporate more security checks into the CI/CD pipelines. The role will include validation of planned changes to ensure that they comply with best practice and will also involve working with the Cyber Security Team.
You will be responsible for
- Be a team player – live the Tesco Mobile values.
- Implement agreed security improvements to key platforms.
- Act as the subject matter expert for infrastructure security.
- Work with the application development teams to improve application security.
- Crafting business justifications for security improvements and present these to Product Owners and other stakeholders in an eloquent manner for an audience that may not be as technically experienced in Security Engineering.
You will need
We are looking for the following skills & experience:
- Significant commercial experience with cloud and SaaS security improvement projects.
- Significant experience with cloud providers AWS and Azure.
- Experience of CI/CD pipelines and adding security tooling to these.
- Experience using SAST and other techniques to improve code security.
- Experience using AWS Security Hub, Azure Security Center, etc. to improve cloud security position.
- Willingness to learn new skills.
Nice to have:
- Source code systems and branching strategies; Github and Github Actions.
- Experience in a commercial setting using and managing Splunk including defining data streams, indices and ingests and dashboards.
- Experience maintaining and updating infrastructure using IaC tooling.
- Automation experience using a variety of tools and languages including AWS CLI, python, etc.
- Experience automating tasks using PowerShell or Azure CLI.
- Containerisation technologies; Docker and Kubernetes.
- Exposure to Continuous Integration and Continuous Deployment techniques, approaches and tools, including experience with the GitHub and GitHub Actions.
What\’s in it for you
We\’re all about the little helps. That\’s why we give our wonderful colleagues bags of benefits. Including wellbeing services, an award-winning pension scheme and much, much more, our colleague reward package keeps on giving. And helps make every day a little better for you and your family. These include but are not limited to:
- Annual bonus scheme of up to 20% of base salary
- Holiday starting at 25 days plus a personal day (plus Bank holidays)
- Buy holiday salary sacrifice scheme (for salaried roles)
- Private medical insurance
- Retirement savings plan – save between 4% and 7.5% and Tesco will match your contribution
- Life Assurance – 5 x contractual pay
- 26 weeks maternity and adoption leave (after 1 years\’ service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 4 weeks fully paid paternity leave
- The right to request flexible working from your first day with us
- Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing
- A Colleague Clubcard for you & a family member (after 3 months of service), giving you access to lots of discounts in-store & online
- Great colleague deals and discounts, saving you money on everyday purchases, eating out and utility bills for the home
- Access to our colleague networks providing a space for colleagues to come together from a range of backgrounds.
- Opportunities to get on – take advantage of our ongoing learning opportunities and award-winning training, to help you achieve the job and career you want
About us
A 50-50 joint venture between Tesco and VMO2 that was established back in 2003, Tesco Mobile has gone from strength to strength as we\’ve launched into new services and markets. With more than 5 million customers, we\’re the largest mobile virtual network operator in the UK. We\’re proud to have an inclusive culture that\’s uniquely Tesco Mobile, with a strong sense of community, plus all the benefits of working for one of the shareholders.
We care for human connection and we keep our customers at the heart of everything we do, which is why we\’ve embraced the Agile way of working. Agile is more than just a methodology – it\’s a liberating journey that puts customers and purpose first. It empowers us to self-organise, collaborate, co-create and rapidly inspect and adapt everything we do – allowing us to respond at pace to our customers\’ needs. It encourages variety of thought and enables us to thrive, both individually and collectively.
We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We\’re committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We\’re proud to have been accredited Disability Confident Leader and we\’re committed to providing a fully inclusive and accessible recruitment process. #J-18808-Ljbffr
Devsecops Security Engineer - Tesco Mobile employer: Tesco
Contact Detail:
Tesco Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Devsecops Security Engineer - Tesco Mobile
✨Tip Number 1
Familiarize yourself with the specific cloud security tools mentioned in the job description, such as AWS Security Hub and Azure Security Center. Being able to discuss your hands-on experience with these tools during the interview will demonstrate your expertise and readiness for the role.
✨Tip Number 2
Brush up on your knowledge of CI/CD pipelines and how to integrate security checks into them. Prepare examples of how you've successfully implemented security improvements in past projects, as this will show your practical understanding of the role's requirements.
✨Tip Number 3
Since communication is key in this role, practice explaining complex security concepts in simple terms. This will help you effectively present business justifications for security improvements to stakeholders who may not have a technical background.
✨Tip Number 4
Highlight your willingness to learn new skills, especially in areas like automation and containerization technologies. Be prepared to discuss any relevant courses or certifications you've pursued, as this shows your commitment to professional growth and aligns with Tesco Mobile's values.
We think you need these skills to ace Devsecops Security Engineer - Tesco Mobile
Some tips for your application 🫡
Understand the Role: Make sure to thoroughly read the job description for the DevSecOps Security Engineer position at Tesco Mobile. Understand the key responsibilities and required skills, especially around cloud security, CI/CD pipelines, and application security.
Tailor Your CV: Customize your CV to highlight relevant experience in cloud and SaaS security projects, as well as your familiarity with AWS and Azure. Be specific about your experience with CI/CD pipelines and any security tooling you've implemented.
Craft a Compelling Cover Letter: Write a cover letter that not only showcases your technical skills but also demonstrates your ability to communicate complex security concepts to non-technical stakeholders. Use examples from your past experiences to illustrate your points.
Show Enthusiasm for Learning: In your application, express your willingness to learn new skills and adapt to evolving security challenges. Highlight any recent training or certifications related to security engineering or cloud technologies.
How to prepare for a job interview at Tesco
✨Understand the Role
Make sure you have a clear understanding of the responsibilities of a DevSecOps Security Engineer. Familiarize yourself with security practices, CI/CD pipelines, and how to implement security improvements in cloud environments like AWS and Azure.
✨Showcase Your Experience
Be prepared to discuss your significant commercial experience with cloud and SaaS security improvement projects. Highlight specific examples where you've successfully implemented security measures or improved code security using SAST techniques.
✨Communicate Effectively
Since you'll be presenting business justifications for security improvements to non-technical stakeholders, practice explaining complex security concepts in simple terms. This will demonstrate your ability to bridge the gap between technical and non-technical audiences.
✨Emphasize Team Collaboration
As a team player, it's important to convey your willingness to collaborate with application development teams and the Cyber Security Team. Share examples of past experiences where teamwork led to successful security implementations or risk mitigations.