Posted:5 days ago|
Platform:
On-site
Full Time
As a Senior Cyber Security Partner; you will
transform the security maturity of key product areas and teams. You will be theface of security group for them. Everything you do is in the context of theproduct; roadmap; its risk acceptance level; the technology stack; and itsarchitecture.You build a comprehensive understanding of the threat landscape and itspotential risks to the business. Through effective partnership; you engage theleadership to make well-informed decisions about security and privacy.
Following our Business Code of Conduct and always
acting with integrity and due diligence and have these specific riskresponsibilities:• Provide product and engineering teams with direction and guidance on allsecurity matters. There is a whole securitygroup to back you up; so it is not as scary as it sounds.• Engage engineering leadership on security roadmap and oversee securityposture of what they build.• Co-own the security roadmap; discuss; prioritise; and co-develop plans forremediation for the product areas.• Empower security champions to succeed and creating a strong feedback loop forimprovements.• Represent security in all product and architecture meet-ups. Be part ofcritical decisions about security.• Oversee product security activities; from the early development of securityrequirements; architecture reviews; andthreat modelling; to strengthening application security; mitigatingsupply-chain risks; securing secrets; pipelines;reviewing vulnerabilities; and infrastructure security.• Perform security architecture reviews of third-party services.• Identify acceptable risk levels and assist with action plan; policy; andprocedural changes for risk mitigation.• Adopt a risk-based approach and guide management in identifying businessrisks and potential impact to Tesco.Continuously seek both tactical and strategic solutions to enhance security.• As the security expert for the product area; engage across the security groupto strengthen controls acrossidentification; protection; detection; response; and recovery.• Oversee assurance activities like security testing; purple testing;assurance; auditing.• Reduce security fatigue for engineering and provide faster feedback withinexisting developer workflows; not addinganother tool for them to check.• Empower the teams you work with; but also challenge the status-quo.• As a senior member of the team; engage across the security group on new ideasand initiatives.• Contribute to strengthen organisation standards and policies; develop cookbooks;secure patterns; take part insecurity research and tool evaluations.• You are committed to continuous improvement; seizing opportunities; andinspire change for the team.• Mentor others in the team and take part in enhancing their skills and careerdevelopment.
To excel in this position, we expect you to have
the following:• Possess experience across multiple sectors and have undertaken diverse rolesin engineering and security.Demonstratable accomplishments of collaborating with leadership and managementon security programmes and initiatives.• Good knowledge of various security domains, and solid experience inarchitecture practices and design patterns – the technology might have changedbut most of the security challenges have not.• Experience in designing security and privacy controls with soundunderstanding of standards and regulation.• Experience in threat modelling, attack trees, vulnerability chaining,applying MITRE ATT&CK framework.• Good understanding of web applications, REST APIs, micro services, eventing,modern application frameworks, and mobile apps.• Good understanding of software architecture, network topologies, SaaS, PaaS,IaaS (infrastructure as a service).• Proficient in applying industry standards such as OWASP ASVS (ApplicationSecurity Verification Standard), OWASP Top10, CIS (Centre of Internet Security) controls and benchmarks.• Experience with cloud native and hybrid architectures with an emphasis oncontainerised workloads and Kubernetes.• Some development experience is always a plus - Java, cloud, Golang, python.You do not need to “be a developer” but we need you to understand theimplications of security on engineering velocity.• Degree in computer science / information systems or engineering field, orequivalent experience.• Experience with regulations like GDPR (General Data Protection Regulation),PCI-DSS is desirable.• Azure or AWS (Amazon Web Services) cloud security certifications isdesirable.• Excellent interpersonal skills and leadership skills.
At Tesco, we are committed to providing the best for you.
As a result, our colleagues enjoy a unique, differentiated, market- competitive reward package, based on the current industry practices, for all the work they put into serving our customers, communities and planet a little better every day.
Our Tesco Rewards framework consists of pillars - Fixed Pay, Incentives, and Benefits.
Total Rewards offered at Tesco is determined by four principles -simple, fair, competitive, and sustainable.
Tesco in Bengaluru is a multi-disciplinary
team serving our customers, communities, and planet a little better every dayacross markets. Our goal is to create a sustainable competitive advantage forTesco by standardising processes, delivering cost savings, enabling agilitythrough technological solutions, and empowering our colleagues to do even morefor our customers. With cross-functional expertise, a wide network of teams,and strong governance, we reduce complexity, thereby offering high-qualityservices for our customers.
Tesco in Bengaluru, established in 2004 to
enable standardisation and build centralised capabilities and competencies,makes the experience better for our millions of customers worldwide and simplerfor over 3,30,000 colleagues
Today, our Technology team consists of over
5,000 experts spread across the UK, Poland, Hungary, the Czech Republic, andIndia. In India, our Technology division includes teams dedicated toEngineering, Product, Programme, Service Desk and Operations, SystemsEngineering, Security & Capability, Data Science, and other roles.
Tesco Bengaluru
Upload Resume
Drag or click to upload
Your data is secure with us, protected by advanced encryption.
Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.
We have sent an OTP to your contact. Please enter it below to verify.
Practice Java coding challenges to boost your skills
Start Practicing Java NowBengaluru, Karnataka, India
Experience: Not specified
Salary: Not disclosed
Bengaluru, Karnataka, India
Salary: Not disclosed
Bengaluru, Karnataka, India
2.0 - 4.5 Lacs P.A.
Bengaluru, Karnataka, India
Salary: Not disclosed
Bengaluru, Karnataka, India
Salary: Not disclosed
Bengaluru, Karnataka, India
Salary: Not disclosed