As a Cyber Security Engineer, you will lead the development, implementation, and continuous improvement of Tesco’s cyber security prevention capability on macOS. You will continuously evaluate the changing threat landscape, identify opportunities for improvement in existing capability, establish new prevention configuration to remain compliant to security hardening frameworks, and ensure appropriate coverage for the organisation. You will collaborate closely with multiple teams, including security operations, workplace technology, and risk & compliance, in a fast moving and agile environment. At Tesco, we believe in the power of spending more time together, face to face, than apart. So, during your working week, you can expect to spend 60% of your time in one of our office locations or local sites and the rest remotely. We also recognise that life looks a little different for each of us. Some people are at the start of their careers, some want the freedom to do the things they love. Others are going through life-changing moments like becoming a carer, nearing retirement, adapting to parenthood, or something else. That’s why at Tesco, we always welcome a conversation about flexible working. So, talk to us throughout your application about how we can support. Threat-Led Prioritisation: Evaluates and prioritises cyber threats to Tesco, analysing machine signals and intelligence and human factors to identify trends and actionable data for threat management. Develop and implement threat-led security strategy. Secure & Test-Driven Engineering: Experience in applying industry hardening frameworks (CIS, NIST etc), knowledge and familiarity with version control and configuration management tooling e.g.: Git, JAMF Intrusion Prevention & Analysis: Define and drive procedures to identify prevention opportunities, assess risk reduction, and ensure mature prevention outcomes, reporting prevention quality, coverage and cost where required. I ncident Management, Incident Investigation & Response : Coordination with security operations teams to support incident management, investigation and response activities when required. In-depth knowledge of macOS system internals and security features Working knowledge of CIS hardening of macOS operating systems Working knowledge of Prevention/Detection capability (AV, DLP, EDR, APP Control) Common Productivity Tools (Confluence, Miro, Teams) Agile Ways of Working (Scrum, Kanban)