Job Search and Career Advice Platform

Enable job alerts via email!

Cyber Security Partner (II)

Tesco UK

Welwyn Garden City

Hybrid

GBP 65,000 - 85,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A major retail company in Welwyn Garden City is seeking a Security Partner to influence security practices within product areas. This role involves engaging with teams to enhance security maturity throughout the SDLC. Candidates should possess hands-on product security experience, knowledge of OWASP standards, and be familiar with cloud environments such as Azure or AWS. This position supports a collaborative and innovative environment, offering both office and remote working opportunities.

Benefits

Diverse working patterns
Inclusive culture
Collaboration opportunities

Qualifications

  • Experience in product security, including architecture review and design principles.
  • Experience in securing pipelines and infrastructure.
  • Hands-on experience in code review for vulnerabilities.
  • Understanding of OWASP ASVS and compliance regulations is advantageous.

Responsibilities

  • Engage deeply within product areas to influence security delivery.
  • Empower teams with security maturity throughout the SDLC.
  • Review architecture and apply design principles.

Skills

Hands-on product security experience
Experience in leading security initiatives
Experience in threat modelling
Application security expertise
Experience with SAST, DAST, SCA tools
Understanding of web applications
Cloud native architecture experience
Good communication skills

Education

Degree in computer science or equivalent

Tools

SAST
DAST
SCA
Kubernetes
Job description
About the Security Partners team

We are the trusted security advisors for Tesco Technology. Our purpose is to collaborate seamlessly with the product and engineering stakeholders, leveraging our deep expertise in cyber security to design and implement robust, resilient solutions that protect our business and customers from cyber threats. We are a dynamic and expanding global team of 15+ experts, serving as the strategic link between the wider security group and software engineering teams that develop cutting‑edge services at scale to support the retail business. Tesco Technology comprises several technology domains with over 100+ teams, each entrusted with their own security. These teams enjoy significant autonomy, balanced by the responsibility to make customer‑centric decisions and security. Rather than imposing controls through rigid processes and security gates, we empower these engineering teams to innovate by providing security guidance that helps them make informed decisions for Tesco. Encouragingly, these teams are enthusiastic partners in enhancing security, working more efficiently, and integrating security into every aspect of their ways of working. This collaborative approach sets us apart from traditional security teams. We proudly identify ourselves as Security Partners, not security police, emphasizing our role as the “trusted advisors” rather than enforcers. Partners engage key people in engineering to make security contextual and frictionless. After all, security is a journey and there is no one‑size‑fits‑all. Join the team and be part of this exciting journey!

The Role

As a Security Partner, you will deeply engage within product areas and influence the way security is delivered by them. You will be supported by experts in the team, nonetheless. To achieve this, you are good at secure design principles, cloud security, secure development practices and patterns, application security, secure pipelines, open‑source security and related. And not to mention, you are versatile to learn anything that comes along your way.

Being the trusted advisor

As enterprise applications become more distributed, adaptive to technological advancements, and run from hybrid infrastructure, teams need to navigate through different complexities and make key security decisions along the way. A trusted security advisor empowers teams to achieve scalable and sustainable security maturity throughout the SDLC process.

Ideal Experience & Qualifications
  • Hands‑on product security experience from developing requirements, reviewing architecture, applying design principles, to application security, pipeline security, infrastructure, and secure monitoring.
  • Experience in leading security initiatives, dev(sec)ops practices with product and engineering teams.
  • Experience in threat modelling and designing security/privacy controls to mitigate risks.
  • Experience in application security, supply chain security, and using tools such as SAST, DAST, SCA, and IAC.
  • Experience in reviewing code to spot weaknesses and suggesting mitigations.
  • Experience applying industry standards like OWASP ASVS (Application Security Verification Standard), OWASP Top 10, CIS controls and benchmarks.
  • Good understanding of web application, REST APIs, micro services, eventing, modern application frameworks, and mobile apps.
  • Experience with cloud native and hybrid architectures with an emphasis on containerised workloads and Kubernetes.
  • Some development experience is always a plus – Java, cloud, Golang, Python. You do not need to “be a developer” but we need you to understand the implications of security on engineering velocity.
  • Degree in computer science / information systems or engineering field, or equivalent experience. Experience with regulations like GDPR, PCI‑DSS is desirable.
  • Azure or AWS cloud security certifications is desirable.
  • Good communicator, listener, influencer.
Our Vision at Tesco

Our vision at Tesco is to become every customer's favourite way to shop, whether they are at home or out on the move.

Diversity, Inclusion & Accessibility

We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. We celebrate diversity, recognise the value and opportunity it brings, and are committed to creating a workplace where differences are valued. We’re proud to have been accredited Disability Confident Leader and are committed to providing a fully inclusive and accessible recruitment process. For further information on the accessibility support we can offer, please click here.

Working Patterns

We’re a big business and we can offer a range of diverse full‑time & part‑time working patterns across our many business areas, which means that we can find something that works for you. We work in a more blended pattern – combining office and remote working. Our offices will continue to be where we connect, collaborate and innovate. If you are applying internally, please speak to the Hiring Manager about how this can work for you – everyone is welcome at Tesco.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.