Security Engineer II

Tesco PLC
Welwyn Garden City, UK
8 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£41,600.0
Working hours
Regular working hours

Tech stack

Cyber Security Python (Programming Language) Mitre Att&ck Enterprise Integration Restful APIs Security Orchestration, Automation & Response

Job description

About the role

As a Security Engineer, you will use your knowledge and expertise to play a key role in defining, implementing, and enhancing capabilities to detect, prevent, and respond to security threats and incidents. You will enable a faster and more effective response by designing and implementing automated security processes.

About the Cyber Security Team

Our cyber security team are the eyes and ears of our organisation. We use pioneering technology to increase visibility and protection of systems, services, and data. To do this we need to stay ahead of the latest threats and continuously improve our tooling, techniques, and processes. We’re continually working to step change security capability to further improve the protection and controls that we offer for our customers and colleagues across the UK, Europe, and Asia. We believe that skilled and passionate people are our greatest asset in reducing risk to our business and customers. We encourage and support continual development and learning and recognise the importance of keeping up with changes in technology and an evolving threat landscape.

You will be responsible for

  • Defining, designing, and implementing security automations to enhance the capability to detect, prevent and respond to security threats and incidents by enabling a faster and more effective response.
  • Drive the security automation roadmap based on team feedback and through your own research, testing and development.
  • Work across multiple teams with analysts and engineers to improve workflows, enabling our colleagues to spend their time doing what they do best.
  • Design and develop security automations across SOAR platform and other security products and tooling.
  • Design and develop custom integrations with 3rd party tooling using REST APIs and Python development.
  • Work with existing security automation and platform engineers to improve upon existing playbooks and automations to ensure optimal platform performance.
  • Developing and running security processes day-to-day for the Tesco Group.

Technical Skills

  • Proven hands-on experience with Security Orchestration, Automation and Response (SOAR) platforms.
  • Proven hands-on experience using Python for development.
  • Understanding of REST APIs and demonstrate ability to interact with 3rd party REST APIs.
  • Understanding of the MITRE ATT&CK framework (or equivalent) and emerging threat actor tactics, techniques, and procedures.

Soft Skills

  • Demonstrable curiosity, passion, and proactive attitude to security and personal development.
  • Good interpersonal skills, and written and oral communications, self-motivator.
  • Great teammate and independent worker, relationship builder.
  • Ability to collaborate closely with domain experts, key customers, and colleagues at all levels.

Experience

  • Desirable Certifications: Ideally one or more relevant certifications, such as: SANS SEC573, SEC598, SEC673.

Whats in it for you?

  • Annual bonus scheme of up to 20% of base salary.
  • Holiday starting at 25 days plus a personal day (plus Bank holidays).
  • Private medical insurance.
  • 26 weeks maternity and adoption leave (after 1 year’s service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay; we also offer 6 weeks fully paid paternity leave.
  • Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing.

Requirements

  • Proven hands-on experience with Security Orchestration, Automation and Response (SOAR) platforms.
  • Proven hands-on experience using Python for development.
  • Understanding of REST APIs and demonstrate ability to interact with 3rd party REST APIs.
  • Understanding of the MITRE ATT&CK framework (or equivalent) and emerging threat actor tactics, techniques, and procedures.

Soft Skills

  • Demonstrable curiosity, passion, and proactive attitude to security and personal development.
  • Good interpersonal skills, and written and oral communications, self-motivator.
  • Great teammate and independent worker, relationship builder.
  • Ability to collaborate closely with domain experts, key customers, and colleagues at all levels., * Desirable Certifications: Ideally one or more relevant certifications, such as: SANS SEC573, SEC598, SEC673.

Benefits & conditions

  • Annual bonus scheme of up to 20% of base salary.
  • Holiday starting at 25 days plus a personal day (plus Bank holidays).
  • Private medical insurance.
  • 26 weeks maternity and adoption leave (after 1 year’s service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay; we also offer 6 weeks fully paid paternity leave.
  • Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

2:59 min

The danger of adopting default REST APIs

Stefan Priebsch · World Congress 2021

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all