The following content displays a map of the jobs location - Welwyn Garden City

Security Engineer (Systems Engineering - Application Security)

Job Reference tesco/TP/13499350/868715

This job has been closed.

Number of Positions:
2
Contract Type:
Permanent
Salary:
Competitive
Location:
Welwyn Garden City
Closing Date:
01/06/2024
Job Category:
Security
Business Unit:
GB Head Office

What’s in it for you

We’re all about the little helps. That’s why we give our wonderful colleagues bags of benefits. Including wellbeing services, an award-winning pension scheme and much, much more, our colleague reward package keeps on giving. And helps make every day a little better for you and your family. These include but are not limited to:

  • Annual bonus scheme of up to 20% of base salary
  • Holiday starting at 25 days plus a personal day (plus Bank holidays)
  • Buy holiday salary sacrifice scheme (for salaried roles)
  • Private medical insurance
  • Retirement savings plan - save between 4% and 7.5% and Tesco will match your contribution
  • Life Assurance - 5 x contractual pay
  • 26 weeks maternity and adoption leave (after 1 years’ service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 4 weeks fully paid paternity leave
  • The right to request flexible working from your first day with us
  • Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing
  • A Colleague Clubcard for you & a family member (after 3 months of service), giving you access to lots of discounts in-store & online
  • Great colleague deals and discounts, saving you money on everyday purchases, eating out and utility bills for the home
  • Access to our colleague networks providing a space for colleagues to come together from a range of backgrounds. For more information about our colleague networks please click here
  • Opportunities to get on - take advantage of our ongoing learning opportunities and award-winning training, to help you achieve the job and career you want

Click Here to read more about the full range of benefits we have available for our colleagues

About the role

An exciting opportunity to join a leading company and play an influential part in their continued dedication to Application Security.

At Tesco, the application security team’s strategy is to provide security tooling that fits seamlessly into software engineering teams ways of working, helping them find and deal with security problems early within the software development process before it reaches production.

In this role you will be responsible for helping to identify appropriate toolsets that fit with the application security team’s strategy, provide comprehensive guidance that allow engineering teams to effectively self-serve with our toolsets and help manage and maintain the chosen solutions.

You will be responsible for

You are an application security expert with a strong engineering background and a curiosity about working collaboratively with the engineering teams. You communicate clearly, present reasonable security trade-offs to the business, and work to build real world practical solutions that reduce our security risk.

In this role, you can expect to:

  • Help identify security toolsets that effectively uncover security issues in open source software and first party code
  • Provide domain expertise on all areas of security and privacy throughout the Software Development lifecycle
  • Work in-line with agile practices i.e. scrum
  • Be able to identify gaps in software engineering practices and recommend appropriate streamlined security solutions
  • Ability to deliver training on core application security products to both security and engineering teams
  • Write comprehensive guidance for the selected security tooling
  • Provide technical support for our products

You will need

Core Technical Skills

  • Proficient in one of the following programming languages: Python, JavaScript, Java
  • Experience of deploying security tooling into a DevOps environment
  • Deep understanding of application security (Web, API, Mobile)
  • An understanding of microservices and container orchestration

Experience

  • Solid grasp of Application Security Tooling (SCA/SAST/DAST/IaC Security)
  • Knowledge of OWASP Top 10, Mitre Top 25 and CVSS frameworks, mapping to business risk
  • Experience in implementing security into different stages of a DevOps lifecycle
  • A good communicator with proven written and verbal communication skills
  • A team player who is not afraid to get stuck in and work collaboratively
  • An ability to translate technical to business risk when assessing software vulnerabilities

About us

Our vision at Tesco is to become every customer's favourite way to shop, whether they are at home or out on the move. Our core purpose is ‘Serving our customers, communities and planet a little better every day’. Serving means more than a transactional relationship with our customers. It means acting as a responsible and sustainable business for all stakeholders, for the communities we are part of and for the planet.

We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We're committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We’re proud to have been accredited Disability Confident Leader and we’re committed to providing a fully inclusive and accessible recruitment process. For further information on the accessibility support we can offer, please click here.

We’re a big business and we can offer a range of diverse full-time & part-time working patterns across our many business areas, which means that we can find something that works for you.  We work in a more blended pattern - combining office and remote working.  Our offices will continue to be where we connect, collaborate and innovate.  If you are applying internally, please speak to the Hiring Manager about how this can work for you - Everyone is welcome at Tesco.