Technical Programme Managers (TPMs) deliver complex, cross-functional technology programmes that support colleagues and help serve our customers better. In this role, you will operate as a Cyber Programme Manager, leading the delivery of Tesco’s Security Engagement & Culture portfolio.
You will work closely with behavioural specialists, learning and communications teams, cyber security leaders, and business stakeholders to turn security strategy into measurable sustainable behaviour change. While this role has a primary focus on security culture, awareness and human risk programmes, you will also be expected to flex and support other Cyber teams and initiatives where business priorities require it.
This role requires hands-on experience managing cyber or risk-related delivery, operating confidently across technical and non-technical audiences, and shaping programmes where outcomes are behavioural, not just technical.
- Annual bonus scheme of up to 20% of base salary
- Holiday starting at 25 days plus a personal day (plus Bank holidays)
- Private medical insurance
- 26 weeks maternity and adoption leave (after 1 years’ service) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 6 weeks fully paid paternity leave
- Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing
While responsibilities will evolve with business needs, the core accountabilities include:
· Deliver cyber programmes focused on reducing human-related cyber risk through education, engagement, and behaviour change.
· Lead cross-functional initiatives spanning Cyber, Technology and the wider business.
· Establish and continuously improve programme delivery approaches suited to cyber and security environments (mixing agile, iterative and campaign-based delivery models where appropriate).
· Shape and lead programmes with evolving scope, emerging insights and data-led learning loops.
· Create, own, and maintain integrated delivery plans, covering campaigns, tooling, learning content, communications, an measurement.
· Act as the central point of coordination across Cyber teams, external partners and business stakeholders.
· Proactively identify and manage delivery risks and issues, facilitate informed trade-off discussions, and manage escalations with clarity and confidence.
· Translate cyber strategy and human-risk priorities into clear objectives, milestones, and success measures.
· Support annual and in-year planning, financial forecasting, and budget management for cyber programmes.
· Build strong relationships with internal stakeholders, suppliers, and partners, holding them to account for delivery outcomes.
· Support vendor selection and management activities, including tendering, SLAs, and delivery assurance.
· Contribute to the wider TPM and Cyber delivery community, sharing good practice and continuously raising the bar for programme execution.
Your role is to enable and accelerate delivery, ensuring complex cyber initiatives are well-sequenced, outcomes-focused, and sustainably embedded.
An ideal candidate will demonstrate the following experience and skills:
Essential
· Minimum of 2 years’ experience managing cyber security delivery, programmes, or portfolios within a Cyber, Security, or Technology Risk environment.
· Proven track record delivering complex technology or security initiatives across multiple teams and stakeholders.
· Strong programme, project, and stakeholder management capability, including senior leadership engagement.
· Experience operating in environments shaped by cyber risk, threat context, or regulatory obligations.
· Ability to understand and navigate cyber and security architectures well enough to manage dependencies and delivery risk.
· Strong reporting, planning, and financial forecasting skills.
· Excellent communication and influencing skills, with the ability to translate complex technical topics into clear delivery narratives.
Desirable
· Experience working with or alongside security culture, awareness, training, risk or change environments.
· Familiarity with behavioural science, learning design, or engagement-led delivery.
· Experience delivering campaigns, simulations, or global programmes.