Senior Security Analyst - Vulnerability Management

The Retail Appointment
Welwyn Garden City
10 months ago
Create job alert

Tesco Technology are looking for a Senior Security Analyst reporting into the Vulnerability Management team. This is an exciting opportunity for a highly motivated security focused individual to join our expanding organisation. The scale and complexity of Tesco creates a huge opportunity for someone to apply their existing skills while developing new ones and make a difference to the millions of customers we serve.

The role will involve being hands on with a focus on the availability and reliability of our data and reporting whilst having the freedom to leverage your knowledge and real-world experience to work with other teams and help drive innovation across our prevention, detection, and remediation capabilities. Your job is to provide actionable insight into the security posture of our systems and platforms prioritising remediation activities for our engineering colleagues and system owners to remediate as well as assurance that effective security controls and guardrails are in place across our on-prem and public

You will be responsible for:

Maintaining vulnerability scanning platforms to identify and analyse vulnerabilities.
Taking a risk-based approach to prioritise remediation efforts.
Working with engineering teams to remediate issues.
Building a range of reporting capabilities to inform our stakeholders on the status and progress of VM remediation efforts across engineering and up to leadership and C level.
Data correlation and identifying patterns and trends.
Reviewing submissions from our active Bug Bounty Programs.
Develop Guardrails and Standards to reduce exposure to vulnerabilities.

You will need:

We welcome colleagues with diverse experiences who can bring unique perspectives to any discussion.

Keen to cultivate a culture of collaboration, innovation and bringing industry standards to everything we do.
Proactive and able to operate independently. Comfortable with ambiguity.
You are resilient – you take ownership of seeing issues through to resolution whilst looking after yourself to be at your best.
Have a passion for technology and can share that passion with others.

Experience relevant for this role:

4+ Years of experience working in the IT Security Industry
Experience with responding to security incidents in large scale corporate environments.
Experience with Vulnerability Scanning tools such as Qualys and Tenable etc.
Ability to categorise criticality as well as risk of a vulnerability.
Expertise in networking, web services and application testing.
Expert knowledge of DNS preventative network controls.
Intelligence gathering and keeping up to date with current as well as evolving threats.
Reporting at various levels to communicate risk, compliance and remediation activities.
Produce and maintain evidence for audit and governance reporting.

What's in it for you:

We’re all about the little helps. That’s why we give our wonderful colleagues bags of benefits. Including wellbeing services, an award-winning pension scheme and much, much more, our colleague reward package keeps on giving. And helps make every day a little better for you and your family. These include but are not limited to:

Annual bonus scheme of up to 20% of base salary
Holiday starting at 25 days plus a personal day (plus Bank holidays)
Buy holiday salary sacrifice scheme (for salaried roles)
Private medical insurance
Retirement savings plan - save between 4% and 7.5% and Tesco will match your contribution
Life Assurance - 5 x contractual pay
26 weeks maternity and adoption leave (after 1 years’ service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 4 weeks fully paid paternity leave
The right to request flexible working from your first day with us
Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing
A Colleague Clubcard for you & a family member (after 3 months of service), giving you access to lots of discounts in-store & online
Great colleague deals and discounts, saving you money on everyday purchases, eating out and utility bills for the home
Access to our colleague networks providing a space for colleagues to come together from a range of backgrounds. For more information about our colleague networks please click here
Opportunities to get on - take advantage of our ongoing learning opportunities and award-winning training, to help you achieve the job and career you want

Click Here to read more about the full range of benefits we have available for our colleagues

About us:

Our vision at Tesco is to become every customer's favourite way to shop, whether they are at home or out on the move. Our core purpose is 'Serving our customers, communities and planet a little better every day'. Serving means more than a transactional relationship with our customers. It means acting as a responsible and sustainable business for all stakeholders, for the communities we are part of and for the planet.

We are proud to have an inclusive culture at Tesco where everyone truly feels able to be themselves. At Tesco, we not only celebrate diversity, but recognise the value and opportunity it brings. We're committed to creating a workplace where differences are valued, and make sure that all colleagues are given the same opportunities. We're a big business with diverse working patterns and many business areas which means that we can find something that works for you. Everyone is welcome at Tesco.

We have recently announced that we will be moving towards a more blended working week – combining office and remote working. Our offices will continue to be where we connect, collaborate and innovate. Please talk to us to about how this can work for you.

NOTE: Should you be successful in your application, your offer will be subject to and conditional upon you providing your bank account details on your agreed start date.

We're proud to have been accredited Disability Confident Leader and we're committed to providing a fully inclusive and accessible recruitment process. For further information on the accessibility support we can offer, please visithttps://www.tesco-careers.com/accessibility

Related Jobs

View all jobs

Senior Security Analyst

Senior Security Analyst

Senior Security Analyst

Senior Security Analyst

Senior Security Analyst - Vulnerability Management

Senior Security Analyst XDR

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Negotiating Your Cybersecurity Job Offer: Equity, Bonuses & Perks Explained

How to Secure Compensation That Reflects Your Value in the UK’s High-Stakes Cybersecurity Sector Introduction As cyber threats grow more sophisticated and frequent, cybersecurity professionals have never been more in demand. From thwarting ransomware attacks to architecting secure cloud infrastructures, mid‑senior cybersecurity experts play a critical role in safeguarding a company’s data and reputation. Thanks to this growing reliance on cybersecurity, employers in the UK are going above and beyond simple salary offers to attract the top echelon of talent. Although base salary remains a key component of any job offer, the broader package—encompassing equity, bonuses, and perks—can often surpass what you’d gain from a small bump in monthly pay. For cybersecurity specialists working in areas such as threat intelligence, incident response, penetration testing, or compliance, the complexity and risk mitigation you bring to the table is massive. Knowing how to negotiate the entire package ensures you are duly rewarded for keeping an organisation’s data, assets, and operations safe. In this guide, we’ll delve into every aspect of negotiating a cybersecurity job offer. Whether you’re pivoting to a mid‑senior role or cementing your expertise at an established security consultancy, understanding the full range of compensation elements will help you secure an offer that acknowledges the criticality of what you do. Let’s explore equity options, performance bonuses, and the perks that matter most, so you can come out of your next job negotiation confident that you’re getting more than just a salary.

Cyber Security Jobs in the Public Sector: Protecting the UK’s Digital Future

Cyber threats have grown exponentially in recent years, targeting both private businesses and government institutions. As technology becomes ever more embedded in daily life—managing everything from national security to healthcare records—the risk of cyber attacks also increases. In the UK public sector, where vital services and sensitive citizen data are at stake, cyber security has become a top priority. For professionals looking for a meaningful career at the intersection of technology, national security, and public service, cyber security jobs in the UK public sector present an exciting and fulfilling path. In this blog post, we’ll delve into why cyber security is so critical to government agencies, the most in-demand roles, the skills and qualifications required, and how to navigate the application process. By the end, you’ll have a clearer sense of how you can leverage your technical expertise to protect the nation’s digital infrastructure.

Contract vs Permanent Cybersecurity Jobs: Which Pays Better in 2025?

Cybersecurity has become one of the fastest-growing and most crucial fields in modern business. With high-profile breaches dominating headlines and the ongoing digital transformation exposing organisations to new threats, companies across the UK are competing to attract skilled cybersecurity professionals. Roles range from penetration testers (pen testers) and SOC (Security Operations Centre) analysts to compliance officers, cloud security architects, threat intelligence analysts, and CISOs (Chief Information Security Officers). As demand continues to surge, cybersecurity salaries have climbed accordingly, and businesses have turned to more flexible hiring practices. Alongside permanent employment, many professionals explore short-term day‑rate contracting or fixed-term contracts (FTCs), searching for the ideal balance of pay, job security, and growth opportunities. Which arrangement truly pays better in 2025—and which best aligns with your ambitions? In this article, we dive into the contract vs. permanent debate with a focus on cybersecurity roles. We will examine the current market, the structure of day‑rate vs. FTC vs. permanent positions, the pros and cons of each, and some hypothetical pay comparisons. By the end, you should have a clearer sense of which career path might suit your situation and goals—whether you are a seasoned specialist aiming for top rates, or an up-and-coming analyst seeking a stable environment to develop in.