At a Glance
- Tasks: Lead cyber threat intelligence efforts to enhance our security programme and protect our customers.
- Company: Join Tesco, a leading retailer committed to sustainability and inclusivity.
- Benefits: Enjoy a competitive salary, annual bonus, generous holiday, and private medical insurance.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
- Qualifications: 3-5 years in cybersecurity with strong skills in scripting and threat intelligence.
- Other info: Flexible working patterns and a culture that celebrates diversity and inclusion.
The predicted salary is between 36000 - 60000 £ per year.
To build and mature a cyber threat intelligence capability that serves as the predictive and proactive heart of our security programme. You will act as the technical authority for collecting, processing, and analysing intelligence, ensuring it enables a truly threat-informed defence. By converging intelligence tradecraft with engineering principles, you will drive the "Intelligence-to-Action" cycle and ruthlessly prioritise the efforts of our detection and response functions.
Benefits
- Annual bonus scheme of up to 20% of base salary
- Holiday starting at 25 days plus a personal day (plus Bank holidays)
- Private medical insurance
- 26 weeks maternity and adoption leave (after 1 years' service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 6 weeks fully paid paternity leave
- Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing
Responsibilities
- Intelligence-to-Action Engineering: Operationalise the "Intelligence-to-Action Cycle," prioritising security engineering efforts based on business risk and validated threats. Define and manage intelligence requirements to guide collection and ensure resources focus on the most relevant risks. Design "Threat Intelligence-as-Code" workflows that automatically trigger hunting packages or detection stubs in our data platform when CTI outputs are available.
- Maintenance of CTI Systems: Implement, manage and optimise the Threat Intelligence Platform (TIP) and analytical tools to automate across the intelligence cycle. Drive technical initiatives to reduce technical debt and ensure tools scale to meet the organisation's evolving needs. Ensure seamless integration between CTI systems, SIEMs, SOAR, and endpoint detection platforms to correlate threats against internal telemetry and take suitable action.
- Detection & Hunt Support: Translate unstructured intelligence into actionable detection suggestions, collaborating with engineers to address coverage gaps for high-priority adversary behaviours. Support proactive threat hunting by defining process and systems which enable hypothesis-driven hunts based on adversary TTPs and specific business risks.
- Automation & Force Multipliers: Champion "Automation-First" principles, using scripting (Python, PowerShell) to automate repetitive data collection and enrichment tasks. Leverage AI and machine learning as "Force Multipliers" to summarise complex threat reports and accelerate code generation and deployment. Develop advanced workflows that integrate intelligence feeds directly into defensive controls for real-time blocking.
- Strategic & Tactical Reporting: Support the production of tiered intelligence products, from strategic executive briefings to operational reports on specific adversary campaigns. Disseminate machine-readable indicators (IOCs) to enable immediate detection and response actions.
- Partnership & Sharing: Act as the technical intelligence partner to Detection Engineering, Security Operations and Incident Response, ensuring a seamless flow of actionable data. Establish and mature intelligence-sharing partnerships with industry peers and intelligence-sharing communities to strengthen collective defence.
Qualifications
- Experience: 3-5+ years in cybersecurity, specifically in Security Engineering, Threat Intelligence, Security Operations (SOC), Incident Response.
- Tradecraft: Advanced understanding of frameworks relating to threat modelling, threat intelligence, threat hunting and detection engineering (ATT&CK, D3FEND, Kill Chain, Attack Flow, STRIDE, DREAD, etc).
- Technical Skills: Proficiency in scripting languages (e.g., Python, PowerShell) for analysis, automation, and workflow improvement.
- Tooling: Hands-on experience with Threat Intelligence Platforms (TIPs) (MISP, ThreatConnect, etc) and SIEM technologies (Splunk, Sentinel, etc).
- Communication: Strong ability to translate complex threat data into actionable insights for both technical and executive audiences.
Our vision at Tesco is to become every customer's favourite way to shop, whether they are at home or out on the move. Our core purpose is 'Serving our customers, communities and planet a little better every day'. Serving means more than a transactional relationship with our customers. It means acting as a responsible and sustainable business for all stakeholders, for the communities we are part of and for the planet. We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We're committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We're proud to have been accredited Disability Confident Leader and we're committed to providing a fully inclusive and accessible recruitment process. For further information on the accessibility support we can offer, please click here. We're a big business and we can offer a range of diverse full-time & part-time working patterns across our many business areas, which means that we can find something that works for you. We work in a more blended pattern - combining office and remote working. Our offices will continue to be where we connect, collaborate and innovate. If you are applying internally, please speak to the Hiring Manager about how this can work for you - Everyone is welcome at Tesco.
Senior Security Engineer in Welwyn Garden City employer: Tesco
Contact Detail:
Tesco Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer in Welwyn Garden City
✨Tip Number 1
Network like a pro! Reach out to folks in the cybersecurity field, especially those at Tesco. A friendly chat can open doors and give you insider info on what they're really looking for.
✨Tip Number 2
Show off your skills! Prepare a portfolio or a GitHub repository showcasing your projects, especially those involving threat intelligence and automation. This gives you a chance to demonstrate your expertise beyond just words.
✨Tip Number 3
Ace the interview by being ready to discuss real-world scenarios. Think about how you've tackled security challenges in the past and be prepared to share your thought process. Tesco loves proactive problem solvers!
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're genuinely interested in joining the Tesco team.
We think you need these skills to ace Senior Security Engineer in Welwyn Garden City
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Security Engineer role. Highlight your experience in cybersecurity, especially in areas like threat intelligence and security engineering. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about this role and how you can contribute to our mission at Tesco. Keep it engaging and relevant to the job description.
Showcase Your Technical Skills: Don’t forget to mention your proficiency in scripting languages like Python and PowerShell. We’re looking for someone who can automate processes and improve workflows, so make sure to highlight any relevant projects or experiences.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It’s the best way for us to receive your application and ensure it gets the attention it deserves. Good luck!
How to prepare for a job interview at Tesco
✨Know Your Threat Intelligence
Make sure you brush up on your knowledge of threat intelligence frameworks like ATT&CK and D3FEND. Be ready to discuss how you've applied these in past roles, especially in relation to operationalising the 'Intelligence-to-Action Cycle'.
✨Showcase Your Scripting Skills
Since scripting is key for this role, prepare to demonstrate your proficiency in Python or PowerShell. Bring examples of how you've automated tasks or improved workflows in previous positions, as this will show your hands-on experience.
✨Communicate Clearly
You’ll need to translate complex data into actionable insights, so practice explaining technical concepts in simple terms. Think about how you would present your findings to both technical teams and executive audiences.
✨Prepare for Collaboration Questions
This role involves working closely with various teams, so be ready to discuss your experience in cross-functional collaboration. Have examples ready that highlight how you've partnered with detection engineering or incident response teams to enhance security measures.