Flexa
Discover companiesFind a jobResourcesSign in/up
For employers
< Back to search
Tesco

Cyber Incident Manager (CIM)

Location:  Welwyn Garden City, UK
Location flexibility:  2 office days / week
View company profile
Apply

Job Description

As a Cyber Incident Manager at Tesco, you will lead the coordinated response to cyber incidents, protecting the integrity of the retail ecosystem that serves millions of customers every day.
Acting as a central orchestrator, you will ensure swift, structured, and effective incident resolution, minimising operational disruption and customer impact.
This role is critical to maintaining trust in Tesco’s digital platforms by driving proactive, intelligence-led response and embedding continuous improvement across the cyber defence lifecycle.
You will operate at the intersection of technology, business impact, and customer outcomes, championing innovation and resilience.

  • Lead Incident Orchestration: Direct end-to-end cyber incident management activities, coordinating cross-functional technical teams to ensure rapid containment, eradication, and recovery.
  • Drive Effective Communication: Act as the central point of coordination during incidents, providing clear, concise, and timely updates to technical and non-technical stakeholders, including senior leadership.
  • Enable Automated Response: Leverage Applied Artificial Intelligence (AI) and automation to enhance incident triage, prioritisation, and decision-making at pace.
  • Optimise Operational Tooling: Utilise platforms such as Zendesk and xMatters to manage incidents, streamline workflows, and ensure high-quality service delivery.
  • Embed Continuous Improvement: Translate lessons learned from incidents into actionable improvements across detection, response, and prevention capabilities.
  • Collaborate Across Domains: Work closely with Security Operations, Threat Intelligence, Detection Engineering, and Technology teams to deliver a unified, customer-first cyber defence posture.
  • Lead Through Change: Champion modern, agile ways of working, fostering innovation, resilience, and a culture of inclusion and continuous improvement within the incident response community.

Essential:

  • Incident Leadership: Demonstrable understanding of cyber incident management and incident response processes, with the ability to coordinate complex, high-pressure situations effectively.
  • Critical Thinking & Decision-Making: Strong analytical and problem-solving capability, with the ability to assess risk, prioritise actions, and make sound decisions under pressure.
  • Communication & Influencing: Proven ability to communicate complex technical issues clearly and influence stakeholders across a diverse organisational landscape.
  • Operational Tooling Expertise: Hands-on experience or exposure to incident management platforms such as Zendesk and xMatters in a cyber or operational environment.
  • Applied Automation in Cyber Defence: Foundational understanding of how AI and automation can be applied to enhance cyber defence outcomes, particularly in incident detection and response.
  • Technology Awareness: Broad exposure to core enterprise technology environments, with an understanding of how cyber incidents impact business-critical systems.
  • Strategic Thinking: Ability to connect tactical incident response with broader strategic outcomes, driving improvements that enhance long-term resilience.
  • Change Leadership: Experience in embracing and enabling change, promoting modern engineering and operational practices across teams.
  • Collaboration & Inclusion: Demonstrable commitment to fostering inclusive, high-performing teams, working collaboratively across diverse technical and business functions.

Desirable:

  • Exposure to digital forensics techniques and investigative practices.
  • Familiarity with tools such as Jira for workflow and task management.
  • Understanding of cloud and container security principles.
  • Awareness of core cyber defence technologies (e.g., Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR)).
  • Interest in data analytics and the use of insights to improve incident outcomes.
  • Knowledge of development lifecycles and product-based delivery models.
  • Awareness of retail technology environments and associated risks.
  • Evidence of continuous learning, curiosity, and contribution to the wider cybersecurity profession.

You might know us as a supermarket, technology company or even for our award-winning mobile network. Truth is, we’re all of those things, and much more. Our colleagues work with one goal in mind, helping to make every day a little better for our customers, colleagues and communities all over the world. No two customers are the same, neither are our colleagues. At Tesco, we champion a balance that lets you thrive both in and out of work. Spend 60% of your week collaborating with colleagues at our office locations or local sites and the rest remotely. Whether you're just kicking off your career, juggling passions, or navigating big life events, we're here to support you. We always welcome a conversation about flexible working, so talk to us throughout your application about how we can support. We're proud to be an accredited Disability Confident Leader, where everyone’s welcome. That’s why we commit to providing a fully inclusive and accessible recruitment process. If you need support with your application, click here for more information. And if you're interested in joining our team but don't tick every box, don't let that hold you back from applying.

Apply

Other jobs you might like

Tesco

Security Manager - SOC

Welwyn Garden City, UK

Tesco

Senior Incident Responder (DFIR)

Welwyn Garden City, UK

EY UK

Cyber Defense Incident Responder - Assistant Director

Manchester, UK

#2 MOST INCLUSIVE COMPANY

Working at Tesco

Hybrid

A little flex time

Company benefits

25 days annual leave + bank holidays
Additional voluntary pension contribution
Adoption leave – 26 weeks full pay (after 52 weeks service)
Annual bonus
Annual pay rises
Bike parking
Buy or sell annual leave
Car allowance
Charity donation scheme
Chill out zone
Cinema discounts
Coffee discounts
Collaboration spaces
Company car
Company freebies
Compassionate leave
Critical Illness Insurance
Cycle to work scheme
Death in service
Dental coverage
Discretionary sick pay
Electric Car Salary Sacrifice
Emergency leave
Employee assistance programme
Employee discounts – 10% off and 15% on pay day weekends
Employee phone programme
Enhanced maternity leave – 26 weeks full pay (after 52 weeks service)
Enhanced paternity leave – 6 weeks full pay (after 52 weeks service)
Enhanced pension match/contribution – up to 7.5% matching
Equity packages
Ergonomic workstations
Eye Care Support
Faith rooms
Family health insurance
Fertility treatment leave
Financial advice
Fully stocked snack cupboard
Gym membership
Health assessment
Health insurance
In house training
L&D budget
Learning license
Learning platform
Legal consults
Life assurance – Five times your pay
Life insurance
Lunch and learns
Meditation space
Menopause support
Mental health first aiders
Mental health platform access
Mentoring
Modern office
On-site barista
On-site catering
On-site gym
On-site personal trainer
On-site shower
On-site wellness room
On-site wellness services
On-site workout classes
Open to compressed hours
Open to job sharing
Open to part time work for some roles
Open to part-time employees
Optional unpaid leave
Paid fostering leave
Personal development budgets
Personal development days
Pregnancy loss leave
Private booths
Referral bonus
Religious celebration leave
Relocation packages
Restaurant discounts
Sabbaticals
Salary advance
Salary sacrifice
Secure on-site parking
Sensory-Friendly Setup
Share options
Skilled worker visas
Sports teams
Study support
Teambuilding days
Theme park discounts
Time off in-lieu
Tree planting
Volunteer days
Wellbeing incentive programme
Reservist leave
Apply
Flex spring

Join the mailing list

Get the latest insights and expert guidance on job hunting, career progression, and creating thriving workplaces.

Enter your email
  • About us
  • Contact us
  • FAQs
  • Info for employers
  • Join Flexa
  • Legal
  • Live feed
  • Resources
  • Sign in/up
  • The Flexa awards
Flexa

EY UK

Cyber Defense Incident Responder - Associate Director

Zurich, CH

#2 MOST INCLUSIVE COMPANY

Vodafone

Cyber Defence Incident Manager

Newbury, United Kingdom

#1 MOST LOVED - ENTERPRISE COMPANIES

Company employees:

330,000+

Gender diversity (m:f):

49:51

Hiring in countries

Ireland

United Kingdom

Office Locations