Padmi
Sainsbury's logo
Sainsbury's

grocery retail · supermarkets

Information Security Analyst - Product Assurance

United KingdomPosted 1 month ago
CybersecurityMid-level
Apply at Sainsbury's

Opens the source posting on hdhe.fa.em3.oraclecloud.com

Source description

About the role

View original

Job Title / Role

Information Security Analyst – Product Assurance

Reporting to

Information Security Manager – Sainsbury’s

Division/Dept

Data Governance and Information Security

Location

Holborn, Coventry, Manchester (Flexible)

In a nutshell

As an Information Security Analyst in the Data Governance and Information Security Team, you will be working within the Product Assurance team who are responsible for ensuring our Engineering and Development communities are building and maintaining secure products through their entire lifecycle.

You will be continually reviewing our security posture and setting the direction on how best to make improvements in line with the evolving threat landscape and core business objectives.

The ideal candidate will have 4+ years’ experience working within Information or Cyber Security and be passionate about continuous professional development. You will be asked to provide recent, industry-respect certificates if successful at interview to demonstrate your ongoing education.

Whilst this role isn’t ‘hands-on’ candidates are expected to have an in-depth knowledge of security technologies and how these are integrated in monolithic and microservice architectures.

What you need to do

As an Information Security Analyst, you will have good all round infosec experience coupled with finely honed Stakeholder Management skills to ensure that robust security is maintained across our environment.

As an Information Security Analyst, you will have good all round infosec experience coupled with finely honed Stakeholder Management skills to ensure that robust security is maintained across our environment.

Work in a flexible, agile manner within Engineering Families, whilst maintaining appropriate levels of challenge and governance

Ensure security is built in by design, products are delivered securely with client and employee data appropriately protected

Define Security Non-Functional Requirements for each project and ensure that they are fulfilled prior to going into service, ensuring the relevant technology standards are applied to specific projects

Liaise with the Information Security Testing Team to ensure that Ethical Hacking, Code Reviews, Application Scanning, and Infrastructure Scanning is conducted.

Provide end to end assurance of IT products across the Group, throughout its lifecycle, providing approvals where appropriate

Articulate risk in technical and non-technical terminology so that it can be interpreted by IT and Business individuals alike

Help identify, assess, and manage strategic, operational and emerging risks affecting the Cloud and Data, and articulate, quantify and monitor risks according to risk appetite.

Build and maintain strong senior stakeholder relationships within technology and the business to understand security risk and drive robust risk-based decision making.

Effectively articulate technical issues to business units and engineering teams.

Define Security Non-Functional Requirements for each project and ensure that they are fulfilled prior to going into service, ensuring the relevant technology standards are applied to specific projects.

Liaise with third-party strategic partners and providers who support Sainsbury’s.

What you need to know and show

A strong technical understanding of security to ensure systems are designed and built securely and to help continually improve our security posture

Appreciation of containerisation technologies such as Docker, Kubernetes etc.

Fundamental knowledge of logging, monitoring, load balancing/proxies and API gateways

Fundamental knowledge of GitHub, Jenkins & Jira

Basic knowledge of the OWASP Top 10, Mitre ATT&CK, NIST frameworks, PCI-DSS and Cyber Kill Chain

Fundamental understanding of PAM, EDR, AV, IPS, SIEM, WAF and DLP technologies

The ability to verify solutions and gain assurance that they are fit for purpose through demonstrable evidence of controls and testing

Strong understanding of the changing threat landscape and how this may affect our systems

The ability to challenge concerns and report through appropriate channels

Self-drive, motivation and the ability to work independently to deliver expected outcomes

In-depth understanding of data and security risks in a large enterprise

Risk & Vulnerability Management experience and understanding of Risk & Vulnerability Management Frameworks

Strong analytical and report writing skills.

Experience with serverless cloud technologies such as AWS storage and Lambda functions.

Desirable Qualifications

You will have two (or more) of the following

  • CompTIA Security+, Network+, Linux+, Cloud+, Data+, DataSys+

  • CSA CCSK / CCAK

  • AWS Certified Security

  • Microsoft Azure Security Engineer Associate

  • (ISC)² CISSP / CCSP / SSCP

  • ISACA CISA / CISM / CRISC / CGEIT

  • MSc. Information/Cyber Security

  • As well as lots of on-the-job training and endless opportunities, in return you’ll also enjoy :

  • Colleague discount across our multi-brands - Sainsbury's, Argos, TU Clothing and Habitat

  • Holiday allowance

  • Bonus scheme

  • Pension plan

  • Special offers on gym memberships, restaurants, holidays, retail vouchers and more

Work-life balance is important to us, so we offer our colleagues as much flexibility as possible in line with the needs of their role. We trust them to decide how, where and when they work, combining remote and collaborative working with a flexible approach to hours, giving them plenty of time and space for life outside of work whilst delivering against our business goals.

One address, no account. We’ll tell you when matching roles go live.

More at Sainsbury's

Related open roles

View all roles