Technical Programme Managers (TPMs) deliver complex, cross‑functional technology programmes that support colleagues and help serve our customers better. In this role, you will operate as a Cyber Programme Manager, leading the delivery of high-impact cyber security initiatives across Tesco’s organisation.
You will work across multiple Cyber domains, partnering with security engineering, operations, product and infrastructure teams to translate cyber strategy into delivered, measurable outcomes. While you may align to a specific domain, you will be expected to flex and support broader Cyber priorities where business needs require.
This role requires hands‑on experience managing cyber delivery, navigating complex technical and organisational dependencies, operating confidently in environments shaped by risk, threat context and regulatory expectations.
Why This Role
This is an opportunity to play a pivotal role in shaping and delivering Tesco’s cyber security outcomes. You will work at the intersection of strategy, intelligence, engineering, and operations helping ensure that cyber initiatives are not only well‑designed, but successfully delivered and embedded where it matters most.
- Annual bonus scheme of up to 20% of base salary.
- Holiday starting at 25 days plus a personal day (plus Bank holidays).
- Private medical insurance.
- 26 weeks maternity and adoption leave (12 months service required at the qualifying date) at full pay, followed by 13 weeks of Statutory Maternity Pay or Statutory Adoption Pay, we also offer 6 weeks fully paid paternity leave.
- Free 24/7 virtual GP service, Employee Assistance Programme (EAP) for you and your family, free access to a range of experts to support your mental wellbeing.
- This information is a shortened summary, refer to our policies for full details.
While responsibilities will evolve with business needs, the core accountabilities include:
Deliver complex cyber security programmes with multiple technical, operational and risk dependencies that directly improve Tesco’s security posture and business resilience.
Lead cross‑functional initiatives spanning Cyber, Technology, Product and operational teams.
Translate cyber strategy, risk priorities and security objectives into clear programme outcomes, milestones and measurable value.
Shape and lead programmes with evolving scope, emerging threats, and uncertain delivery paths.
Establish and continuously improve delivery approaches suited to cyber environments (combining agile, iterative and structured delivery models where appropriate).
Create, own and maintain integrated delivery plans covering technical implementation, operational readiness and change impacts.
Act as the central point of coordination across Cyber teams, Product, Engineering, and Operations.
Proactively identify delivery risks and issues, facilitate informed trade‑off discussions, and manage escalations with clarity and confidence.
Understand cyber and security architectures sufficiently to anticipate dependency, sequencing, and integration risks.
Support planning cycles, financial forecasting and budget management for cyber programmes.
Build strong relationships with stakeholders, suppliers, and partners, holding them accountable for delivery outcomes.
Support vendor selection and management activities, including tendering, SLAs, and delivery assurance.
Contribute to the wider TPM and Cyber delivery community, sharing good practice and continuously raising the bar for programme execution.
Your role is to enable and accelerate delivery, ensuring complex cyber initiatives are well‑sequenced, outcomes‑focused, and sustainably embedded.
An ideal candidate will demonstrate the following experience and skills:
Essential
Proven experience managing cyber security delivery, programmes or portfolios within a Cyber, Security or Technology Risk environment.
Strong track record delivering complex technology or security initiatives across multiple teams and stakeholders.
Excellent programme, project, and stakeholder management capability, including senior leadership engagement.
Experience operating in environments shaped by cyber risk, threat context, or regulatory obligations.
Ability to understand and navigate cyber and security architectures well enough to manage dependencies and delivery risk.
Strong reporting, planning, and financial forecasting skills.
Excellent communication and influencing skills, with the ability to translate complex technical topics into clear delivery narratives.
Desirable
Experience working with a range of Cyber domains (e.g. Identity & Access Management, Cloud Security, Threat Detection, Security Engineering).
Familiarity with threat‑informed defence, detection‑led security, or risk-based prioritisation approaches.
Experience delivering programmes that involve security tooling, automation, or platform integration.