Job Title / Role
Senior Information Security Analyst - Cloud Specialist
Reporting to
Information Security Manager - Sainsbury's
Division/Dept
Data Governance and Information Security
Location
Coventry, Holborn, Manchester (Flexible)
In a nutshell
The Senior Information Security Analyst - Cloud Specialist is responsible for helping to manage the Sainsbury's cloud estate. Sainsbury's has a multi-cloud strategy so familiarity with Azure and AWS is essential. You should hold either Specialty or Professional qualifications for at least one of these vendors. You should have expertise and knowledge of cloud security architecture along with experience of recommending secure design patterns.
What you need to do
1. Support the security, resilience and redundancy of the cloud environments
2. Liaise with the Security Testing Team to ensure that Ethical Hacking, Code Reviews, Application Scanning and Infrastructure Scanning is conducted
3. Provide Subject Management Expertise to colleagues and management
4. Help identify, assess and manage strategic, operational and emerging risks affecting the Cloud and articulate, quantify and monitor risks according to risk appetite
5. Build and maintain strong senior stakeholder relationships within technology and the business to understand security risk and drive robust risk-based decision making
6. Effectively articulate technical issues to business units and engineering teams
7. Define Security Non-Functional Requirements for each project and ensure that they are fulfilled prior to going into service, ensuring the relevant technology standards are applied to specific projects
8. Liaise with third-party strategic partners and providers who support Sainsbury's
What you need to know and show
1. A strong technical understanding of security to ensure systems are designed and built securely and to help continually improve our security posture
2. Appreciation of containerisation technologies such as Docker, Kubernetes etc.
3. Experience with logging, monitoring, load balancing/proxies and API gateways
4. Working knowledge of GitHub, Jenkins, Ansible, Chef and Puppet
5. In-depth knowledge of the OWASP Top 10, Mitre ATT&CK, NIST frameworks, PCI-DSS and Cyber Kill Chain
6. Familiarity with PAM, EDR, AV, IPS, SIEM, WAF and DLP technologies
7. The ability to verify solutions and gain assurance that they are fit for purpose through demonstrable evidence of controls and testing
8. Strong understanding of the changing threat landscape and how this may affect our systems
9. Nice to have knowledge of Oracle and SAP clouds
10. The ability to challenge concerns and report through appropriate channels
11. Self-drive, motivation and the ability to work independently to deliver expected outcomes
12. In-depth understanding of data and security risks in a large enterprise
13. Risk Management experience and understanding of Risk Management Frameworks
14. Strong analytical and report writing skills
Desirable Qualifications
You will have two (or more) of the following (including Cloud):
1. CompTIA CASP+, Cloud+, Security+, Network+, Linux+
2. CSA CCSK / CCAK
3. AWS Certified Security or Certified Solutions Architect
4. Microsoft Certified Azure Solutions Architect Expert
5. Microsoft Certified Cybersecurity Architect Expert
6. GCP Professional Cloud Security Engineer
7. GIAC Cloud Security Automation
8. (ISC)² CISSP / CCSP / SSCP
9. ISACA CISA / CISM / CRISC / CGEIT
10. MSc. Information/Cyber Security
Responsibilities
We'd all like amazing work to do, and real work-life balance. That's waiting for you at Sainsbury's. Think about the scale it takes for us to feed the nation. The level of data, transactions and variety it involves. Then you'll realise that ours is a modern software engineering environment because it has to be. We've made serious investment into a Tech Academy and into setting standards and principles. We iterate, learn, experiment and push ways of working such as Agile, Scrum and XP. So you can look forward to awesome opportunities in everything from AI to reusable tech.
Qualifications
We are committed to being a truly inclusive retailer, so you'll be welcomed whoever you are and wherever you work. Around here, there's always the chance to try something new - whether that's as part of an evolving team or somewhere else across the business - and we take development seriously and promise to support you. We also recognise and celebrate colleagues when they go the extra mile and, where possible, offer flexible working. When you join our team, we'll also offer you an amazing range of benefits.
#J-18808-Ljbffr