Senior Security Engineer

2 weeks ago


Welwyn Garden City Hertfordshire, United Kingdom Tesco Full time

Senior Security Engineer - transform the way security is delivered within our engineering & product teams...

About the Security Engineering team

We are 15+ and growing team that supports Tesco technology and software development teams across cloud and other cutting-edge technologies at scale. We have a new role as the security engineer for our security engineering team based in the UK. The software development teams are responsible for their own security, so we act differently than a traditional security team. We are team of security partners, not security police... and we go as far as calling ourselves as Security Partners, not Security Architects or Consultants.

Our software engineering teams have tremendous freedom in their work and the corresponding responsibility to do the right thing for our customers. Instead of controlling our engineering teams with process and security gates, we enable them to innovate by providing security guidance to make right decisions for Tesco. The good news is that our engineering teams are (usually) willing partners in doing better security, more efficiently and earlier in the process. We'd like you to help us scale out and represent ourselves for the wider engineering domains.

Tesco has fully embraced DevOps and agile methodologies to develop our enterprise APIs, services and cloud capabilities. Our 100+ delivery teams have loads of Docker, Kubernetes and microservices galore across Azure and AWS, so our security approach must work with elastic, here today, gone tomorrow infrastructure. Our security approaches should be event driven, real-time and effective. Weekly scans are so 2010.

The role

This role is about transforming the way security is delivered within our engineering teams, specifically our online and customer focused engineering teams. As our software and enterprise APIs continue the move to the cloud, we have different security challenges, and you'll help teams navigate that change successfully. The boundary between infrastructure and application has virtually disappeared and being secure means support through the entire SDLC – from the ideas phase into threat modelling during design, during development then through to production and ops.

Developing strong security partnerships for Tesco Technology

Security partnerships are about transforming the way security is delivered within our technology domains and software engineering teams, your part to play as a security partner is to actively champion positive security change within your product teams.

On a day-to-day basis:

  • Provide engineering and product teams with direction and guidance for all security matters. There is a whole security organisation to back you up, so that is not as scary as it sounds.
  • Help product teams deliver new business features securely while balancing and clearly articulating technical and business risk.
  • Be expected to drive the deployment/integration of security capabilities into engineering teams within the product domain.
  • Drive security initiatives such as developing security requirements, threat modelling, strengthening application security, vulnerability reduction, etc., with the engineering teams.
  • Reducing friction is paramount and we are all about fast feedback within existing workflows, not adding another console for a developer to check.
  • Support teams in a collaborative manner in matters of mobile application, web application, cloud and data security, with threat modelling, risk treatment and security advice across all security domains. If you can raise a PR to resolve fix a security issue, do so.
  • Facilitate risk remediation but also challenge decisions and status-quo.
  • Facilitate in assurance activities like penetration testing, purple testing, app assurance.
  • Build quarterly/monthly roadmaps for security activities and plan them.
  • Be an evangelist for security, take part in strengthening Tesco’s internal policies and standards.

Longer-term, the nature of the role also means you are expected to identify new problem spaces, propose fixes, engage across disciplines. In other words, we want you to innovate and will give you the room to do so. If you can think of ways to do security, faster, more 3 accurately, with greater consistency and at scale while minimizing friction, you'll be supported all the way.

Ideally, you will bring the following:

  • Solid security experience across common security domains – the technology might have changed, but most of the security challenges have not.
  • A thorough understanding of modern application development practices so that security capabilities can be introduced and embedded while minimising developer friction.
  • Excellent interpersonal, facilitation, and leadership skills along with effective communication (both written and verbal) skills.
  • Be able to provide security guidance to engineering teams throughout the product development lifecycle.
  • Be able to develop threat models, attack trees, and embed security by design in product engineering effort.
  • Good understanding of web technologies, REST APIs, micro services, modern application development, and mobile apps.
  • Good understanding of software architecture, dev-sec-ops, and network security.
  • Experience in browser security or mobile app security is desirable.
  • Good understanding of industry standards such as OWASP ASVS, OWASP Top-10, CIS benchmarks.
  • Hands-on experience with complex Azure and AWS architectures with an emphasis on containerised workloads.
  • Command-line/API experience is highly desirable as security automation is a strategic priority.
  • Some coding experience in something is always a plus - Java, HTML, JavaScript. You do not need to “be a developer” but you do need to understand the implications of security on engineering velocity.
  • Knowledge of and experience with PCI-DSS will be desirable.
  • A minimum of 5 years of experience in security engineering or closely related areas.
  • Bachelor’s degree in Computer Science / Information Systems or Engineering discipline.
  • Azure or AWS cloud security certifications (preferred).

About Tesco

Our vision at Tesco is to become every customer’s favourite place to shop, at home, in town, or on the move, anywhere in the world.

Our continuous drive for the best tools and technologies helps us to deliver this vision. We’re driving innovation and transforming our technology solutions to become one of the world’s leading retailers.

We need people who share our ambition to deliver for our customers: passionate and confident people willing to take the initiative and drive us forwards. In return we offer an exciting environment in a world class technology department, an excellent benefits package, and amazing career development opportunities. If that sounds exciting, then we'd love to hear from you

Please reach out panashe.garande@tesco.com, or apply here.


  • Senior Security Engineer

    Found in: Appcast UK C C2 - 1 week ago


    Welwyn Garden City, United Kingdom Tesco Full time

    Senior Security Engineer - transform the way security is delivered within our engineering & product teams...About the Security Engineering teamWe are 15+ and growing team that supports Tesco technology and software development teams across cloud and other cutting-edge technologies at scale. We have a new role as the security engineer for our security...

  • Senior Security Engineer

    Found in: Appcast UK C2 - 1 week ago


    Welwyn Garden City, United Kingdom Tesco Full time

    Senior Security Engineer - transform the way security is delivered within our engineering & product teams...About the Security Engineering teamWe are 15+ and growing team that supports Tesco technology and software development teams across cloud and other cutting-edge technologies at scale. We have a new role as the security engineer for our security...

  • Senior Security Engineer

    Found in: Appcast Linkedin GBL C2 - 2 weeks ago


    Welwyn Garden City, United Kingdom Tesco Full time

    Senior Security Engineer - transform the way security is delivered within our engineering & product teams...About the Security Engineering teamWe are 15+ and growing team that supports Tesco technology and software development teams across cloud and other cutting-edge technologies at scale. We have a new role as the security engineer for our security...

  • Senior Security Engineer

    Found in: Whatjobs ES C2 - 4 days ago


    Welwyn Garden City, United Kingdom Tesco Full time

    Senior Security Engineer - transform the way security is delivered within our engineering & product teams... About the Security Engineering team We are 15+ and growing team that supports Tesco technology and software development teams across cloud and other cutting-edge technologies at scale. We have a new role as the security engineer for our security...

  • Senior Security Engineer

    Found in: Talent UK 2A C2 - 2 weeks ago


    Welwyn Garden City, United Kingdom Tesco Full time

    Senior Security Engineer - transform the way security is delivered within our engineering & product teams...About the Security Engineering teamWe are 15+ and growing team that supports Tesco technology and software development teams across cloud and other cutting-edge technologies at scale. We have a new role as the security engineer for our security...


  • Welwyn Garden City, Hertfordshire, United Kingdom Tesco Full time

    Senior Security Engineer - Product Security Senior Security Engineer - transform the way security is delivered within our engineering & product teams... About the Security Engineering team We are 15+ and growing team that supports Tesco technology and software development teams across cloud and other cutting-edge technologies at scale. We have a new...

  • Security Technology Engineer

    Found in: Jooble UK C2 - 2 weeks ago


    Welwyn Garden City, Hertfordshire, United Kingdom Tesco Full time

    Senior Security Engineer - transform the way security is delivered within our engineering & product teams... About the Security Engineering team We are 15+ and growing team that supports Tesco technology and software development teams across cloud and other cutting-edge technologies at scale. We have a new role as the security engineer for our security...


  • Welwyn Garden City, Hertfordshire, United Kingdom Tesco Full time

    Senior Security Engineer - transform the way security is delivered within our engineering & product teams... About the Security Engineering team We are 15+ and growing team that supports Tesco technology and software development teams across cloud and other cutting-edge technologies at scale. We have a new role as the security engineer for our security...

  • Security Systems Engineer

    Found in: Whatjobs ES C2 - 20 hours ago


    Welwyn Garden City, United Kingdom SHD Recruitment Full time

    Security Systems Engineer Opportunity in the Security Industry! About Us: SHD Recruitment is thrilled to announce an exciting opportunity for a Security Systems Engineer role with our esteemed client, a specialist in the security industry. Join our team and be part of shaping the future of security solutions!


  • Welwyn Garden City, Hertfordshire, United Kingdom Energy Jobline CVL Full time

    Fire and Security Engineers wanted Our client are an established & very successful Fire and Security company based in Hertfordshire, due to a number of contracts recently won they are looking for x2 Fire and Security engineers based in the Hertfordshire area. * You will have a minimum of 5-8 years' experience within Fire and Security * Driving License...


  • Welwyn Garden City, United Kingdom SHD Recruitment Full time

    Exciting Opportunity: Supervisor/Senior Engineer Position Available! 🔐 Are you ready to take your career to new heights in the security industry? SHD Recruitment is delighted to announce an outstanding opportunity for a Supervisor/Senior Engineer role with our client, a prominent specialist in the security industry. If you're a seasoned professional...


  • Welwyn Garden City, United Kingdom Pontoon Full time

    ** Security Engagement Partner - Product Management Opportunity** Reports into: Security Engagement & Culture Manager Function: Technology Department: Security & Capability Work Level: 2 Job location: Office - required 2 days on site a week Site Location Highwoods - Welwyn Garden City Job Summary: This role will be dedicated to technical security training...


  • Welwyn Garden City, United Kingdom GCB Recruitment Full time

    Our clients specialise in Structural and Civil Engineering and operate from 2 offices. They have an excellent reputation for quality and performance in both the commercial and domestic sectors. They are recruiting for a Senior Structural Engineer to jointheir growing team to help them deal with their increased workload. Their scope of work caters from the...


  • Welwyn Garden City, Hertfordshire, United Kingdom Aldwych Consulting Ltd Full time

    Senior Civil Design Engineer Welwyn Garden City, Hertfordshire Do you want to progress your career within a leading construction consultancy in Hertfordshire? Are you ready to get involved with challenging and exciting infrastructure projects? We are seeking an experienced Chartered or near Chartered Civil Engineer to join our client's team in...


  • Stevenage, Hertfordshire, United Kingdom Complete Security Recruitment Full time

    Job Description – TECHNICAL SERVICES ENGINEER This fantastic company, are looking for an experienced Technical Services Engineer to join the team. As a business they design, install, maintain, and support high-level CCTV, Access Control & Intruder Alarms Security Systems. As an independent, privately-owned company with over 20 years of experience, we act...

  • Fire and Security Tutor

    Found in: Whatjobs ES C2 - 4 days ago


    Hertfordshire, United Kingdom Complete Security Recruitment Full time

    An exciting opportunity exists for an experienced Fire and Security engineer to upskill as an apprenticeship tutor (Fully Funded) and pass on their knowledge to the next generation and those who are looking for a change.A leading provider of apprenticeships to the Fire and Security sector are looking to recruit enthusiastic, knowledgeable and passionate...


  • Covent Garden, United Kingdom Momentum Security Recruitment Full time

    **CCTV Control Room Operator** **Location: Covent Garden, Central London** **Rate of pay: £12 per hour** **Shift pattern: 4 on 4 off (days 8am to 8pm & nights 8pm to 8am)** This is a chance to work in the security control room at an iconic location in Covent Garden. Applicants should hold a SIA CCTV license. Essential Criteria: - Prior experience...

  • Area Relief

    5 days ago


    Welwyn Garden City, United Kingdom Atalian Servest Full time

    **Job Reference: SEC/GE/02-02/796/5** **Job Title: Area Relief - Security Officer** **Pay Rate: £10.50 - £11.50 per hour (Depending on site/Travel)** **Working Hours: Variable shift rota - 36 hours per week - Nights, Days, Weekends 12-hour shifts** **Location: Enfield / Hatfield / Welwyn Garden City** **Would you be interested to join a leading...

  • Senior Security Engineer

    Found in: Appcast UK C2 - 1 week ago


    City Of London, United Kingdom Stott and May Full time

    Senior Cyber Security Engineer (Global)Stott & May are partnering with a prestigious global law firm poised for expansion. They are seeking a talented individual to join their team as a Senior Cyber Security Engineer, playing a pivotal role in safeguarding their operations and ensuring compliance with industry standards.Job Title: Senior Cyber Security...

  • Senior Security Engineer

    Found in: Appcast Linkedin GBL C2 - 2 weeks ago


    City Of London, United Kingdom Stott and May Full time

    Senior Cyber Security Engineer (Global)Stott & May are partnering with a prestigious global law firm poised for expansion. They are seeking a talented individual to join their team as a Senior Cyber Security Engineer, playing a pivotal role in safeguarding their operations and ensuring compliance with industry standards.Job Title: Senior Cyber Security...