The role This role is about transforming the way security is delivered within our engineering teams in Tesco Technology.
As our software and enterprise APIs continue the move to the cloud, we have different security challenges, and this role is to help teams navigate that change successfully.
The boundary between infrastructure and application has virtually disappeared and being secure means support through the entire SDLC – from the ideas phase into threat modelling during design, during development then through to production and ops. Developing strong security partnerships for Tesco Technology Security partnerships are about transforming the way security is delivered within our technology domains and software engineering teams.
We have different security challenges, and your role as a security partner is to actively champion positive security change within your product teams.
Job accountabilities On a day-to-day basis you will
• Provide engineering and product teams with direction and guidance for all security matters. There is a whole security organization to back you up, so that is not as scary as it sounds.
• Help product teams deliver new business features securely while balancing and clearly articulating technical and business risk.
• You will be expected to drive the deployment/integration of security capabilities into engineering teams within the product domain.
• You will drive security initiatives such as developing security requirements, threat modelling, strengthening application security, vulnerability reduction, etc., with the engineering teams.
• Reducing friction is paramount and we are all about fast feedback within existing workflows, not adding another console for a developer to check.
• Support teams in a collaborative manner in matters of mobile application, web application, cloud and data security, with threat modelling, risk treatment and security advice across all security domains. If you can raise a PR to resolve fix a security issue, do so.
• Facilitate risk remediation but also challenge decisions and status-quo
. • Facilitate in assurance activities like penetration testing, purple testing, app assurance.
• Build quarterly/monthly roadmaps for security activities and plan them.
• Be an evangelist for security, take part in strengthening Tesco’s internal policies and standards. Longer-term, the nature of the role also means you are expected to identify new problem spaces, propose fixes, engage across disciplines.
In other words, we want you to innovate and will give you the room to do so. If you can think of ways to do security, faster, more 3 accurately, with greater consistency and at scale while minimising friction, you will be supported all the way.