Be at the heart of actionFly remote-controlled drones into enemy territory to gather vital information.

Apply Now

Security Engineering Specialist

Tesco Bank
Edinburgh
2 days ago
Create job alert

Serving our customers, communities, and planet a little better every day.

Salary - Between £, - £, + annual bonus & benefits

Location – Edinburgh, Permanent

Office Attendance - Our roles are hybrid; however, you should be able to travel to our Edinburgh office 2 days per week for this position.

Closing Date – Applications close //5 at 5pm

A chance to thrive

We’re looking for a Security Engineering Specialist to join our Vulnerability Management and Assurance team at Tesco Bank, part of Barclays Bank UK Plc.

The Vulnerability Management and Assurance team are the technical experts in technical vulnerabilities and weaknesses – senior stakeholders rely on our ability to understand deeply technical topics and interpret the situation at the business level. Our team is responsible for detecting, tracking, and advising on vulnerabilities to protect the Bank and our customers.

What you’ll be doing

Leading by example as the technical expert on vulnerabilities and advise on remediations. Providing security assurance and guidance for complex projects throughout their life-cycles and giving specialist input for go-live decisions. Deciding, scoping, and arranging pragmatic security assessments to be carried out by our panel of security vendors. Liaising with departments across the bank and build working relationships with other teams to spread awareness of security and help the bank achieve required levels of protection and governance. Helping us modernise our practices and drive improvements to the ways the team works, our vulnerability detection and management tooling, security testing processes and their associated processes.

We need you to have

Technical expertise on vulnerabilities and an intimate understanding of an attacker mindset and their techniques. Demonstrable experience in working with a range of security assessment types. Thorough understanding of security best practices and anti-patterns, familiarity with tooling to support these. Excellent communication abilities with technical and non-technical colleagues.

And if you have any of these, even better

Strong understanding of Agile practices and effectively employing the principles in a real life workplace. Experience in offensive IT Security tooling and practices past experience in pentesting, HackTheBox, TryHackMe,). Strong understanding of current and past OWASP Top s (web/API/mobile), CVSSv2 and CVSSv3, MITRE ATT&CK, and NIST Framework. IT Security related achievements, publications, certifications, and other credentials.

We don’t expect you to tick every box, and if you feel you hit most of the brief, it’s worth exploring to further develop your career here with us.

What’s in it for you

Prepare for your retirement with our colleague pension scheme. Private Medical Insurance (WL2+) and virtual GP Service days a year. Performance related annual bonus. Indulge in a generous holiday allowance with a minimum of weeks, with the opportunity to buy more. Embrace the benefits of our Colleague Clubcard, enjoy a % discount that increase to % every payday (worth up to 2K). As an added perk, we’ll give you a second card to share with someone else. Benefit from our family-oriented initiatives, encompassing enhanced maternity leave pay, a shared parental leave policy, and a generous paid paternity leave. A place to get on - take advantage of our ongoing learning opportunities and training, to help you achieve the job and career you want.

Everyone’s welcome

We want all our colleagues to always feel welcome and be themselves at Tesco Bank, part of Barclays Bank UK Plc. We’re committed to building a more inclusive workplace and celebrating everything that makes colleagues unique, and value the richness and diversity this brings to our business. A more diverse business helps us deliver on our purpose to serve our customers, communities, and planet a little better every day.

#LI-KS1



Related Jobs

View all jobs

Security Engineering Manager

Principal Engineer - Product Security

IIoT Security Engineer

Head of H&S Assurance

Application Security Engineer

Security Systems Engineer

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Cyber Security Recruitment Trends 2025 (UK): What Job Seekers Must Know About Today’s Hiring Process

Summary: UK cyber security hiring has shifted from title‑led CV screens to capability‑driven assessments that emphasise incident readiness, cloud & identity security, detection engineering, governance/risk/compliance (GRC), measurable MTTR/coverage gains & secure‑by‑default engineering. This guide explains what’s changed, what to expect in interviews, & how to prepare—especially for SOC analysts, detection engineers, blue/purple teamers, penetration testers, cloud security engineers, DFIR, AppSec, GRC & security architecture. Who this is for: SOC & detection engineers, security operations leads, DFIR analysts, penetration testers/red teamers, purple teamers, AppSec/DevSecOps engineers, security architects, cloud security engineers, identity/IAM engineers, vulnerability managers, GRC/compliance specialists, product security & security programme managers targeting roles in the UK.

Why Cyber Security Careers in the UK Are Becoming More Multidisciplinary

Cyber security used to be viewed primarily as a technical discipline: firewalls, encryption, intrusion detection, penetration testing. In the UK today, it’s far broader. Organisations now face complex legal frameworks, ethical dilemmas, human-behaviour risks, communication challenges & usability hurdles. This shift means cyber security careers are becoming more multidisciplinary. From protecting NHS patient records to defending financial services, securing supply chains & safeguarding national infrastructure, cyber security now touches every sector. Employers increasingly want professionals who understand law, ethics, psychology, linguistics & design alongside traditional technical skills. In this article, we’ll explore why UK cyber security careers are expanding in this way, how these five disciplines shape the profession, and what job-seekers & employers need to know to thrive in this new landscape.

Cyber Security Team Structures Explained: Who Does What in a Modern Cyber Security Department

Cyber security has become a top priority for UK organisations of all sizes. From small businesses to financial institutions, healthcare providers, and government bodies, the risk of cyber attack is now a constant concern. Threats are more sophisticated, regulations more demanding, and customers more aware of data privacy than ever before. But defending against cyber threats isn’t simply about having the right tools — it’s about having the right team. A modern cyber security department relies on clearly defined roles and responsibilities to ensure that defences are proactive, incidents are managed swiftly, and compliance is maintained. This article explains the structure of a modern cyber security team, the roles you’ll typically find within it, how they collaborate, and what skills, qualifications, and salaries are expected in the UK job market.