- Company Name
- Tesco Technology
- Job Title
- Head of Security Engineering – Application Security & Security Testing
- Job Description
-
Job Title: Head of Security Engineering – Application Security & Security Testing
Role Summary: Lead a multi‑disciplinary security engineering function focused on vulnerability management, application security engineering, and adversarial testing. Deliver full‑stack security assurance from code to infrastructure, driving innovation and operational excellence while embedding security throughout delivery pipelines.
Expactations: • Own and grow a 20+ engineer team across sub‑functions (vulnerability management, app security engineering, penetration testing). <br>• Translate strategic security goals into actionable plans, monitor progress, and report on metrics. <br>• Foster a culture of continuous improvement, talent development, and succession planning. <br>• Serve as a senior stakeholder liaison across security, product, and platform teams.
Key Responsibilities: • Manage three Security Engineering Managers and a Principal Security Engineer/Architect. <br>• Oversee design, deployment, and operation of tools for vulnerability detection across code, applications, infrastructure, packages, and external assets. <br>• Ensure robust SAST, SCA, ASPM, threat modelling, GenAI‑driven security solutions, and red/purple team testing capabilities. <br>• Drive automation, coverage expansion, and continuous improvement of testing methodologies. <br>• Translate Tesco Tech Excellence programme objectives into actionable team plans, track delivery, and maintain operational metrics. <br>• Collaborate with Heads of Security Partnerships, Cyber Defence, and Platform Security Architecture to align security initiatives with broader technology goals. <br>• Embed security into product and programme pipelines and act as key contact for senior stakeholders.
Required Skills: • Proven leadership of large‑scale security engineering teams. <br>• Deep technical expertise in vulnerability management, application security engineering, and adversarial testing. <br>• Strong knowledge of secure development practices, modern engineering tooling, and DevSecOps pipelines. <br>• Experience with ASPM platforms, threat modelling, and GenAI‑driven security solutions. <br>• Ability to balance strategic vision with hands‑on execution. <br>• Excellent communication, stakeholder engagement, and performance‑tracking skills. <br>• Familiarity with operational metrics and continuous improvement frameworks.
Required Education & Certifications: • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience). <br>• Professional certifications such as CISSP, CISM, CEH, OSCP, or equivalent are highly desirable.
Welwyn garden city, United kingdom
On site
30-10-2025