The following content displays a map of the jobs location - Welwyn Garden City
Senior Incident Responder (DFIR)
What’s in it for you
We offer excellent benefits that help make Tesco a great place to work! These include but are not limited to:
- Annual bonus scheme
- Holiday starting at 25 days plus a personal day (and bank holidays)
- Great colleague discounts and deals, saving you money on everyday purchases, utility bills for the home and more
- Retirement savings plan – save between 4% and 7.5% and Tesco will match your contribution
- Buy as you earn and Save as you earn share schemes
- Opportunities to get on – take advantage of our ongoing learning opportunities and award-winning training to help you achieve the career you want
About the role
Our Digital Forensics and Incident Response (DFIR) team lead the technical investigation and response to security incidents at Tesco. As part of this team, you’ll work alongside our security operations, threat intelligence, and security engineering teams to protect, detect, and respond to security threats across Tesco’s diverse and evolving estate.
You’ll apply your deep technical knowledge and ability to think critically to investigate and understand the full extent of security incidents and threats. Your ability to distil and clearly convey technical information will allow you to provide the key contextual information to decision makers that enables them to make informed decisions.
As a senior position, when you’re not investigating security incidents, you’ll have the freedom to leverage your knowledge and real-world experience to work with other teams and help drive innovation across our prevention, detection, and response capabilities.
You will be responsible for
- Investigation and Response: Perform host, network, and cloud-based forensic analysis to understand the full extent of security incidents and take appropriate response actions to contain, remediate, and recover.
- Incident Handling: Support the incident managers and decision makers with root cause analysis and formulating recommendations for detective and preventive controls.
- Threat Hunting: Lead intelligence-based threat hunts to uncover anomalous behaviour in our estate that is representative of the security threats most relevant to Tesco.
- Detection Engineering: Use your observations from security incidents, threat hunts, and reporting about relevant security threats to contribute to our internal detection engineering programme.
You will need
- 4+ years of experience working in the IT Security industry.
- Experience with responding to security incidents in large scale corporate on-premises and public cloud environments (preferably Microsoft Azure).
- Experience with forensic analysis on Windows, MacOS, and Unix operating systems.
- Experience with a broad range of security technologies such as EDR, SOAR, and SIEM.
- Ability to think critically and lead technical investigations.
- Ability to handle high pressure situations in a calm, productive, and professional manner.
- Proficiency in at least one programming or scripting language, such as Python & Powershell
Our vision at Tesco is to become every customer’s favourite way to shop, whether they are at home or out on the move. Our core purpose is “Serving our customers, communities and planet a little better every day”. Serving means more than a transactional relationship with our customers. It means acting as a responsible and sustainable business for all stakeholders, for the communities we are part of, and for the planet.
We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We’re committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We’re a big business with diverse working patterns and many business areas which means that we can find something that works for you. Everyone is welcome at Tesco.
We have recently announced that we are moving to a more blended working week – combining office and remote working. Our offices continue to be where we connect, collaborate and innovate. Talk to us about how this can work for you.
Note: Should you be successful in your application, your employment will be subject to and conditional upon you providing your bank account details on your agreed start date.