logo

JobNob

Your Career. Our Passion.

Security Engineer II


Tesco


Location

Welwyn Garden City, Hertfordshire | United Kingdom


Job description

We are 15+ and growing team that supports Tesco technology and software development teams across cloud and other cutting-edge technologies at scale. We have a new role as the Security Engineer for our security partners team based in the UK. The software development teams are responsible for their own security, so we act differently than a traditional security team. We are team of security partners, not security police... and we go as far as calling ourselves as Security Partners, not Security Architects or Engineers. Our software engineering teams have tremendous freedom in their work and the corresponding responsibility to do the right thing for our customers. Instead of controlling our engineering teams with process and security gates, we enable them to innovate by providing security guidance to make right decisions for Tesco. The good news is that our engineering teams are (usually) willing partners in doing better security, more efficiently and earlier in the process. We want you to help us scale out and represent ourselves for the wider engineering domains. Tesco has fully embraced devops and agile methodologies to develop our enterprise APIs, services and cloud capabilities. Our 100+ delivery teams have loads of Docker, Kubernetes and microservices galore across Azure and AWS, so our security approach must work with elastic, here today, gone tomorrow infrastructure. Our security approaches should be event-driven, real-time and effective. Weekly scans are so 2010. You will be responsible for: As a Security Engineer II, you will closely work with the Partners in the team to drive and execute security initiatives for one or more engineering teams. To do this, you’re good at secure design and secure coding principles. And you are versatile to learn multiple development environments (frameworks, languages and tools), and take up new challenges. Developing strong security partnerships for Tesco Technology Security partnerships are about transforming the way security is delivered within our technology domains and software engineering teams. We have different security challenges, and your role as a security partner is to actively champion positive security change within your product teams. Job accountabilities On a day-to-day basis you will Build a good understanding of the product area, and able to develop or assess security or privacy controls. Demonstrate how weaknesses in design or code can be exploited through POCs. Assist partnerships with security initiatives, be ready to hit the ground and perform. Assist/support product teams to deliver new business features securely, while balancing and clearly articulating technical risks. Assist/support adoption of security capabilities into the engineering teams and product domains. Ready to review designs, code, pipelines, setups, configs for verification. Good understanding of security by design, security by default. Be ready to code. If you can raise a PR (pull request) to fix a security issue, do so. Or, develop a security control or test as suitable for the nature of the product. Scope security pentests and assist product teams in scheduling. Be an advocate for good security, take part in strengthening our internal standards and guidelines. Good interpersonal skills along with effective communication (both written and verbal) skills. Longer-term, the nature of the role also means you are expected to identify new problem spaces, propose fixes, engage across disciplines. In other words, we want you to innovate and will give you the room to do so. If you can think of ways to do security, faster, more accurately, with greater consistency and at scale while minimising friction, you will be supported all the way. You will need: To excel in this position, we expect you to have the following: 8+ years of work experience with a bachelor’s degree or at least 4 years of work experience with an master degree in related areas. Programming background with Java, JavaScript or .Net. Familiarity with popular frameworks, SDKs and tools. Proficient at secure design and coding and can audit as required. Experience with scripting using python, bash or PowerShell. Exposure to micro-service style architecture, distributed computing, Linux operating system, REST APIs, modern application frameworks, container based development and deployments. Good understanding of software security and dev(sec)ops, the shift-left culture. Good understanding of OWASP Top-10, Top 25 CWEs, open source security, data security. Good understanding of security & privacy patterns, security standards and RFCs. Working experience with public cloud (Azure/AWS/GCP) and their popular services. General security principles, privacy principles, industry standards such as NIST and CIS benchmarks. Hands-on experience with threat models and attack trees is a plus. If you’ve got AWS or Azure certifications, great! If you have only one, we’ll train you on everything else. If you have neither, that’s a more challenging conversation, but may not be a show-stopper if you stand out in other areas.

#LI-TI1

#LI-Hybrid What's in it for you: We’re all about the little helps. That’s why we give our wonderful colleagues bags of benefits. Including wellbeing services, an award-winning pension scheme and much, much more, our colleague reward package keeps on giving. And helps make every day a little better for you and your family. These include but are not limited to: Annual bonus scheme of up to 20% of base salary Holiday starting at 25 days plus a personal day (plus Bank holidays) Buy holiday salary sacrifice scheme (for salaried roles) Private medical insurance Retirement savings plan - save between 4% and 7.5% and Tesco will match your contribution Life Assurance - 5 x contractual pay 26 weeks maternity and adoption leave (after 1 years’ service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 4 weeks fully paid paternity leave The right to request flexible working from your first day with us Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing A Colleague Clubcard for you & a family member (after 3 months of service), giving you access to lots of discounts in-store & online Great colleague deals and discounts, saving you money on everyday purchases, eating out and utility bills for the home Access to our colleague networks providing a space for colleagues to come together from a range of backgrounds. For more information about our colleague networks please click here Opportunities to get on - take advantage of our ongoing learning opportunities and award-winning training, to help you achieve the job and career you want Click Here to read more about the full range of benefits we have available for our colleagues About us: Our vision at Tesco is to become every customer's favourite way to shop, whether they are at home or out on the move. Our core purpose is 'Serving our customers, communities and planet a little better every day'. Serving means more than a transactional relationship with our customers. It means acting as a responsible and sustainable business for all stakeholders, for the communities we are part of and for the planet. We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We're committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We're a big business with diverse working patterns and many business areas which means that we can find something that works for you. Everyone is welcome at Tesco. We have recently announced that we will be moving towards a more blended working week – combining office and remote working. Our offices will continue to be where we connect, collaborate and innovate. Please talk to us to about how this can work for you. NOTE: Should you be successful in your application, your offer will be subject to and conditional upon you providing your bank account details on your agreed start date. We're proud to have been accredited Disability Confident Leader and we're committed to providing a fully inclusive and accessible recruitment process. For further information on the accessibility support we can offer, please visit


Job tags

Permanent employmentWork at officeRemote jobHybrid workHoliday workFlexible hoursShift work


Salary

All rights reserved