Vulnerability, Threat & Exposure Management Analyst

Posted 4 Days Ago
Be an Early Applicant
London, England, GBR
In-Office
Entry level
eCommerce • Retail
The Role
Analyze vulnerabilities, misconfigurations, identity weaknesses, cloud risks, exposed assets, and attack paths across ASOS’s technology estate. Use threat intelligence, exploitability, and business context to prioritize remediation, partner with engineering teams, validate risk reduction, track significant exposures, improve security controls, and communicate actionable cyber-risk insights to technical and non-technical stakeholders.
Summary Generated by Built In
Company Description

We're ASOS, the online retailer for fashion lovers all around the world.

We exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgement, and channel your creativity into a platform used by millions.

Everyone needs some help showing up as their best self. We're Disability Confident Committed - let our Talent team know if you need any reasonable adjustments throughout the recruitment process.

Job Description

The Vulnerability, Threat & Exposure Management analyst helps ASOS understand and reduce the technology exposures most likely to contribute to material cyber risk.

Rather than treating vulnerabilities in isolation, the role considers vulnerabilities, misconfigurations, identity and privilege weaknesses, cloud security risks, exposed assets and attack paths in the context of threat intelligence, exploitability and business criticality.

You’ll turn technical security data into clear, risk-based priorities, helping engineering and technology teams focus remediation effort where it delivers the greatest reduction in exposure and cyber risk.

This is an analytical and collaborative role. You’ll work across ASOS’s technology estate to understand what is exposed, how it could realistically be exploited, what an attacker could reach, what matters most to ASOS, and what we should do about it.

Role details

  • Identify and assess technology exposures across ASOS, including vulnerabilities, misconfigurations, identity and privilege weaknesses, exposed assets and services, cloud security risks and attack paths.
  • Perform risk-based analysis and prioritisation, considering exploitability, threat intelligence, attacker behaviour, asset criticality, business context, accessibility and compensating controls to determine which exposures matter most.
  • Analyse attack paths to understand how vulnerabilities, configurations, identities, privileges and trust relationships could combine to enable compromise of critical ASOS systems, services or data.
  • Apply threat intelligence and exploitation data to understand which threats and exposures are most relevant to ASOS and where action should be prioritised.
  • Assess exposure across modern technology environments, including cloud platforms, applications, APIs, virtual machines, containers, endpoints, identities, networks and supporting infrastructure.
  • Support continuous attack-surface discovery, helping identify unknown, unmanaged, incorrectly classified or unexpectedly exposed assets and services.
  • Partner with engineering, product, platform and infrastructure teams to agree proportionate remediation or mitigation strategies, focusing effort on actions that deliver the greatest reduction in cyber risk.
  • Track significant exposures through to resolution, escalating material or persistent risk where appropriate and helping teams identify effective remediation or compensating controls.
  • Identify recurring exposure patterns and systemic control weaknesses, working with technology teams to address root causes and eliminate classes of exposure rather than repeatedly treating individual findings.
  • Assess the effectiveness of preventative and compensating controls in reducing identified exposures and attack paths, recommending improvements where required.
  • Validate significant exposures and remediation outcomes, using appropriate technical evidence to confirm that identified risk has been materially reduced.
  • Translate technical findings into clear risk insights, communicating exposure, potential business impact and remediation priorities to both technical and non-technical stakeholders.
  • Contribute to meaningful exposure metrics and reporting that demonstrate changes in organisational risk and remediation effectiveness rather than relying solely on vulnerability volumes or severity scores.
  • Contribute to the continuous improvement of ASOS’s Threat & Exposure Management capability, including automation, data enrichment, prioritisation models, metrics, reporting, workflow integration, processes and governance.
  • Promote secure-by-design and proportionate, risk-based security practices across ASOS technology teams.

Qualifications

About You:

  • Relevant experience as a Vulnerability Analyst, SOC Analyst, or in a similar role.
  • Understanding of common vulnerability types and attack techniques.
  • Experience with vulnerability management, cloud security or security assessment tooling (e.g. Wiz, Defender, Nessus, Qualys or similar).
  • Understanding of enterprise technologies, including cloud platforms, infrastructure, networking and software development practices.
  • Ability to leverage threat intelligence to assess vulnerability risk and inform remediation priorities.
  • Knowledge of container and Kubernetes security is desirable.
  • Understanding of cyber security risk management principles and risk-based decision making.
  • Excellent written and verbal communication skills for presenting technical information clearly to non-technical audiences.
  • Naturally inquisitive, with the ability to investigate security risks across diverse technologies and identify potential threats to the organisation.
  • Self-motivated with strong problem-solving and critical thinking skills.

Additional Information

You don’t need to have worked in a role called Threat & Exposure Management before. We’re looking for someone who can combine technical security knowledge with curiosity, analytical thinking and an understanding of risk.

You’ll ideally have:

  • Relevant experience in exposure management, vulnerability management, cloud security, security engineering, threat intelligence, SOC/security operations, or another role involving the analysis of technology and cyber risk.
  • A strong understanding of common vulnerabilities, security misconfigurations and attacker techniques across modern technology environments.
  • Experience using vulnerability, exposure, cloud security or security assessment tooling such as Wiz, Microsoft Defender, Nessus, Qualys or equivalent platforms.
  • An understanding of cloud platforms and cloud-native technologies, including virtual machines, containers and modern application architectures.
  • An understanding of identity and privilege as part of the attack surface, and how identity weaknesses can contribute to attack paths.
  • An understanding of attack paths and attacker behaviour, including how multiple weaknesses can be combined to reach critical assets or services.
  • An understanding of cyber security risk management and the ability to make risk-based rather than severity-based decisions.
  • Knowledge of container and Kubernetes security is desirable.
  • Strong analytical and critical-thinking skills, with a naturally inquisitive approach to investigating security issues across diverse technologies.
  • Strong written and verbal communication skills, with the ability to explain complex technical issues clearly and turn them into actionable priorities for different audiences.
  • A collaborative approach and the ability to work effectively with engineering and technology teams to achieve practical security outcomes.

What success looks like
Success in this role isn’t measured by how many vulnerabilities you find or tickets you create. It’s measured by how effectively we understand and reduce the exposures that matter most to ASOS.

You’ll help us move from vulnerability management based primarily on individual findings and severity scores towards a more continuous, threat-informed and risk-based approach to understanding and reducing our attack surface.

BeneFITS’ 

  • Employee discount (hello ASOS discount!) 
  • Employee sample sales 
  • 25 days paid annual leave + an extra celebration day for a special moment 
  • Discretionary bonus scheme 
  • Private medical care scheme 
  • Flexible benefits allowance - which you can choose to take as extra cash, or use towards other benefits 
  • Opportunity for personalised learning and in-the-moment experiences that enable you to thrive and excel in your role 

Skills Required

  • Relevant experience as a Vulnerability Analyst, SOC Analyst, or in a similar role
  • Understanding of common vulnerability types and attack techniques
  • Experience with vulnerability management, cloud security, or security assessment tooling
  • Understanding of enterprise technologies, including cloud platforms, infrastructure, networking, and software development practices
  • Ability to leverage threat intelligence to assess vulnerability risk and inform remediation priorities
  • Understanding of cybersecurity risk management principles and risk-based decision-making
  • Excellent written and verbal communication skills
  • Strong problem-solving, analytical, and critical-thinking skills
  • Knowledge of container and Kubernetes security
  • Experience in exposure management, vulnerability management, cloud security, security engineering, threat intelligence, or SOC/security operations
  • Understanding of identity and privilege as part of the attack surface
  • Understanding of attack paths and attacker behavior
  • Collaborative approach when working with engineering and technology teams

ASOS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ASOS and has not been reviewed or approved by ASOS.

  • Wellbeing & Lifestyle Benefits — Feedback suggests perks like a sizable, shareable product discount, access to sample sales, free gym access, and on-site amenities are valued. Such lifestyle-oriented benefits are frequently highlighted as standout aspects of the package.
  • Leave & Time Off Breadth — Feedback suggests employees benefit from substantial annual leave with bank holidays and an extra celebratory or birthday day off, with summer early finishes referenced in some contexts. This breadth of time-off options supports work-life balance.
  • Healthcare Strength — Feedback suggests access to a private medical care scheme is a core part of the package. This contributes to a perception of strong healthcare support.

ASOS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
3,200 Employees
Year Founded: 2000

What We Do

We exist to give people the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you’re free to be your true self without judgment, and channel your creativity into a platform used by millions. Whatever your role, asos will encourage you to be you, fulfilling your creative potential with our global reach. Push boundaries, and challenge expectations. We’re determined to succeed, so we’ll trust you to deliver. Help drive our journey to becoming the global fashion destination for 20-somethings At ASOS our 3,000+ employees are immersed in the creative worlds and have a truly entrepreneurial attitude. Our ASOSers are authentic, brave, creative and disciplined to the core and find ways to blend our passion for fashion with cutting edge technology. Sound up your street? Join us.

Similar Jobs

Ericsson Logo Ericsson

Architect

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office or Remote
2 Locations
88000 Employees

Tulip Logo Tulip

Account Executive

Enterprise Web • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
UK
310 Employees

Boeing Logo Boeing

Business Improvement Specialist

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Bristol, England, GBR
170000 Employees

Mastercard Logo Mastercard

Director, Product Management

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
London, Greater London, England, GBR
38800 Employees

Similar Companies Hiring

Tastewise Thumbnail
Artificial Intelligence • Big Data • Food • Retail • Software • Generative AI • Big Data Analytics
NYC, NYC
120 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account