Cyber Incident Manager (CIM)

Tesco UK

Greater London

Hybrid

GBP 90,000 - 120,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Tesco UK in London is seeking a Cyber Incident Manager to lead coordinated response to cyber incidents, protecting the integrity of Tesco's digital platforms and the retail ecosystem serving millions of customers daily.

You will act as central orchestrator, ensuring swift, structured resolution and embedding continuous improvement across the cyber defence lifecycle, with emphasis on automation, cross-functional collaboration and clear communication to stakeholders including senior leadership.

Qualifications

  • Experience in cyber incident management and incident response, with ability to coordinate high-pressure situations.
  • Strong analytical, risk assessment and prioritisation skills under time pressure.
  • Proven communication skills to inform diverse stakeholders, including senior leadership.
  • Hands-on exposure to incident management platforms such as Zendesk and xMatters in cyber/operational contexts.
  • Foundational understanding of AI and automation applied to cyber defence.
  • Broad knowledge of enterprise technology environments and business impact of incidents.

Responsibilities

  • Lead end-to-end cyber incident management activities and coordinate cross-functional teams for containment, eradication and recovery.
  • Act as central point of coordination during incidents, providing timely updates to technical and non-technical stakeholders.
  • Leverage automation to improve incident triage, prioritisation, and decision-making.
  • Utilise tools like Zendesk and xMatters to manage incidents and streamline workflows.
  • Translate lessons learned into improvements across detection, response, and prevention capabilities.
  • Collaborate with Security Operations, Threat Intelligence, Detection Engineering and Technology teams.
  • Promote modern, agile ways of working and a culture of inclusion and continuous improvement.

Skills

Incident leadership
Critical thinking & decision-making
Communication & influencing
Operational tooling
Applied automation in cyber defence
Technology awareness
Strategic thinking
Change leadership
Collaboration & inclusion

Tools

Zendesk
xMatters
SIEM
EDR
Jira

Job description

As a Cyber Incident Manager at Tesco, you will lead the coordinated response to cyber incidents, protecting the integrity of the retail ecosystem that serves millions of customers every day.

Acting as a central orchestrator, you will ensure swift, structured, and effective incident resolution, minimising operational disruption and customer impact.

This role is critical to maintaining trust in Tesco’s digital platforms by driving proactive, intelligence-led response and embedding continuous improvement across the cyber defence lifecycle.

You will operate at the intersection of technology, business impact, and customer outcomes, championing innovation and resilience.

  • Lead Incident Orchestration: Direct end-to-end cyber incident management activities, coordinating cross-functional technical teams to ensure rapid containment, eradication, and recovery.
  • Drive Effective Communication: Act as the central point of coordination during incidents, providing clear, concise, and timely updates to technical and non-technical stakeholders, including senior leadership.
  • Enable Automated Response: Leverage Applied Artificial Intelligence (AI) and automation to enhance incident triage, prioritisation, and decision-making at pace.
  • Optimise Operational Tooling: Utilise platforms such as Zendesk and xMatters to manage incidents, streamline workflows, and ensure high-quality service delivery.
  • Embed Continuous Improvement: Translate lessons learned from incidents into actionable improvements across detection, response, and prevention capabilities.
  • Collaborate Across Domains: Work closely with Security Operations, Threat Intelligence, Detection Engineering, and Technology teams to deliver a unified, customer-first cyber defence posture.
  • Lead Through Change: Champion modern, agile ways of working, fostering innovation, resilience, and a culture of inclusion and continuous improvement within the incident response community.
Essential:
  • Incident Leadership: Demonstrable understanding of cyber incident management and incident response processes, with the ability to coordinate complex, high-pressure situations effectively.
  • Critical Thinking & Decision-Making: Strong analytical and problem-solving capability, with the ability to assess risk, prioritise actions, and make sound decisions under pressure.
  • Communication & Influencing: Proven ability to communicate complex technical issues clearly and influence stakeholders across a diverse organisational landscape.
  • Operational Tooling Expertise: Hands-on experience or exposure to incident management platforms such as Zendesk and xMatters in a cyber or operational environment.
  • Applied Automation in Cyber Defence: Foundational understanding of how AI and automation can be applied to enhance cyber defence outcomes, particularly in incident detection and response.
  • Technology Awareness: Broad exposure to core enterprise technology environments, with an understanding of how cyber incidents impact business-critical systems.
  • Strategic Thinking: Ability to connect tactical incident response with broader strategic outcomes, driving improvements that enhance long-term resilience.
  • Change Leadership: Experience in embracing and enabling change, promoting modern engineering and operational practices across teams.
  • Collaboration & Inclusion: Demonstrable commitment to fostering inclusive, high-performing teams, working collaboratively across diverse technical and business functions.
Desirable:
  • Exposure to digital forensics techniques and investigative practices.
  • Familiarity with tools such as Jira for workflow and task management.
  • Understanding of cloud and container security principles.
  • Awareness of core cyber defence technologies (e.g., Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR)).
  • Interest in data analytics and the use of insights to improve incident outcomes.
  • Knowledge of development lifecycles and product-based delivery models.
  • Awareness of retail technology environments and associated risks.
  • Evidence of continuous learning, curiosity, and contribution to the wider cybersecurity profession.

You might know us as a supermarket, technology company or even for our award-winning mobile network. Truth is, we’re all of those things, and much more. Our colleagues work with one goal in mind, helping to make every day a little better for our customers, colleagues and communities all over the world. No two customers are the same, neither are our colleagues.

At Tesco, we champion a balance that lets you thrive both in and out of work. Spend 60% of your week collaborating with colleagues at our office locations or local sites and the rest remotely. Whether you're just kicking off your career, juggling passions, or navigating big life events, we're here to support you. We always welcome a conversation about flexible working, so talk to us throughout your application about how we can support.

We're proud to be an accredited Disability Confident Leader, where everyone’s welcome. That’s why we commit to providing a fully inclusive and accessible recruitment process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Incident Manager (CIM)
Cyber Incident Manager (CIM)

Tesco • Welwyn Garden City

On-site
GBP 85,000 - 110,000
Cyber Incident Manager (CIM)
Cyber Incident Manager (CIM)

TESCO UK • Welwyn Garden City

Hybrid
GBP 90,000 - 125,000
Cyber Incident Manager (CIM)
Cyber Incident Manager (CIM)

Tesco Technology • Welwyn Garden City

Hybrid
GBP 90,000 - 130,000
Annual bonus up to 20%
25 days holiday + personal day
Private medical insurance
+2
Security Engineer III
Security Engineer III

Tesco UK • Digswell

Hybrid
GBP 90,000 - 140,000
Security Engineer III
Security Engineer III

Tesco Technology • Welwyn Garden City

Hybrid
GBP 70,000 - 110,000
Annual bonus up to 20%
Private medical insurance
Paternity leave (6 weeks paid)
+1
Senior Security Engineer - Detection Engineering
Senior Security Engineer - Detection Engineering

Tesco UK • Digswell

Hybrid
GBP 80,000 - 120,000
Security Engineer - Detection Engineering
Security Engineer - Detection Engineering

Tesco Technology • Welwyn Garden City

Hybrid
GBP 65,000 - 100,000
Annual bonus up to 20%
25 days holiday + personal day
Private medical insurance
+2
Senior Incident Responder (DFIR)
Senior Incident Responder (DFIR)

Tesco Technology • Welwyn Garden City

Hybrid
GBP 70,000 - 110,000
Annual bonus up to 20% of base salary
Holiday 25 days + personal day
Private medical insurance
+2
Security Analyst III - SOC
Security Analyst III - SOC

Tesco Technology • Welwyn Garden City

Hybrid
GBP 70,000 - 90,000
Annual bonus up to 20%
Private medical insurance
Maternity/adoption leave
+2
Senior Incident Responder (DFIR)
Senior Incident Responder (DFIR)

TESCO UK • Welwyn Garden City

Hybrid
GBP 80,000 - 110,000