About the role
As a Senior Security Analyst in Tesco’s Security Operations Centre (SOC), you will provide technical leadership during high-severity cyber incidents, safeguarding a complex retail ecosystem serving millions of customers. You will act as a critical guardian of Tesco’s digital estate, ensuring a rapid, coordinated response while continuously evolving detection capabilities to stay ahead of sophisticated threats. This role is central to delivering an intelligence-led, proactive cyber defence, combining deep technical expertise with operational excellence. You will also drive innovation, including the responsible application of Artificial Intelligence (AI), to enhance the effectiveness and efficiency of cyber defence operations.
You will be responsible for
-
Take technical ownership of high-severity cyber incident investigations, coordinating cross-functional teams to drive rapid investigation, and supporting containment, eradication, and recovery.
- Drive maturity in detection engineering within the SOC, improving detection coverage, fidelity, and resilience against evolving adversary tactics.
- Collaborate with engineering teams to improve security data quality, logging coverage, and telemetry pipelines, ensuring analysts can make confident, evidence-based decisions.
- Apply and operationalise AI and automation to improve triage, enrichment, and investigation workflows, whilst maintaining strong human oversight and accountability.
- Provide expert guidance and coaching, fostering a high-performing team culture centred on curiosity, continuous learning, and professional growth.
- Work closely with DFIR, Detection Engineering, Threat Intelligence, Incident Management, and Technology teams to deliver a unified, customer-first cyber defence capability.
You will need
Essential:
-
Demonstrable expertise in identifying, investigating, and responding to complex cyber threats, including leading high-pressure incident resolution.
- Strong ability to assess ambiguous signals, form investigative hypotheses, and make risk-informed decisions that balance technical and business impact.
- Proven ability to understand end-to-end detection and response workflows, identifying gaps and opportunities for improvement across the lifecycle.
- Strong proficiency in Python and PowerShell with practical experience applying scripting techniques to support AI-driven use cases.
-
Evidence of proactive learning and staying current with evolving threat landscapes, adversary techniques, and defensive innovations.
- Demonstrable capability in developing others, sharing knowledge, and raising technical standards across a team.
- Strong experience working across multidisciplinary teams, fostering inclusive, supportive environments that enable high performance.
- Exposure to applying automation and AI to improve operational outcomes, with a pragmatic focus on measurable improvements rather than theoretical capability.
Desirable:
-
Exposure to core cyber defence platforms (e.g., Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), Security Orchestration, Automation and Response (SOAR)).
- Experience in security data, logging, and telemetry engineering, including an understanding of data quality and coverage challenges.
- Practical familiarity with Applied Artificial Intelligence (AI) in cyber defence, particularly in analyst workflow augmentation.
- Awareness of enterprise cyber incident management processes and escalation models.
- Understanding of retail technology environments and how cyber risks translate into business impact.
- Exposure to threat intelligence integration, research practices, and adversary tracking.
- Familiarity with cloud and container security principles.
- Experience using operational tooling such as Jira, Zendesk, and xMatters.
- Awareness of development lifecycles and modern engineering practices.
- Understanding of responsible AI governance and compliance principles.
Whats in it for you?
We’re all about the little helps. That’s why we make sure our Tesco colleague benefits package takes care of you – both in and out of work. Click Here to find out more!
- Annual bonus scheme of up to 20% of base salary.
- Holiday starting at 25 days plus a personal day (plus Bank holidays).
- Private medical insurance.
- 26 weeks maternity and adoption leave (12 months service required at the qualifying date) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 6 weeks fully paid paternity leave.
- Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing.
- This information is a shortened summary, refer to our policies for full details.
About Us
You might know us as a supermarket, technology company or even for our award-winning mobile network. Truth is, we’re all of those things, and much more. Our colleagues work with one goal in mind, helping to make every day a little better for our customers, colleagues and communities all over the world. No two customers are the same, neither are our colleagues.
At Tesco, we champion a balance that lets you thrive both in and out of work. Spend 60% of your week collaborating with colleagues at our office locations or local sites and the rest remotely. Whether you're just kicking off your career, juggling passions, or navigating big life events, we're here to support you. We always welcome a conversation about flexible working, so talk to us throughout your application about how we can support.
We're proud to be an accredited Disability Confident Leader, where everyone’s welcome. That’s why we commit to providing a fully inclusive and accessible recruitment process. If you need support with your application, click here for more information. And if you're interested in joining our team but don't tick every box, don't let that hold you back from applying.