Назад
Company hidden
8 дней назад

Threat & Exposure Management Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Threat & Exposure Management Analyst (Cybersecurity): Identifying and prioritising vulnerabilities, misconfigurations, identity weaknesses, cloud risks, exposed assets, and attack paths across ASOS’s technology estate with an accent on threat intelligence, exploitability, business criticality, and risk-based remediation. Focus on analysing attack paths, discovering exposed assets, validating remediation, and improving exposure metrics, automation, workflows, and governance.

Location: London, United Kingdom

Company

hirify.global is an online fashion retailer whose technology platform serves customers worldwide.

What you will do

  • Identify and assess vulnerabilities, misconfigurations, identity and privilege weaknesses, exposed assets, cloud risks, and attack paths.
  • Prioritise exposures using exploitability, threat intelligence, attacker behaviour, asset criticality, business context, accessibility, and compensating controls.
  • Analyse how vulnerabilities, identities, privileges, configurations, and trust relationships could enable compromise of critical systems and data.
  • Support attack-surface discovery across cloud platforms, applications, APIs, virtual machines, containers, endpoints, networks, and infrastructure.
  • Partner with engineering, product, platform, and infrastructure teams on remediation and mitigation, tracking significant exposures through resolution.
  • Improve exposure metrics, reporting, automation, data enrichment, prioritisation models, workflow integration, processes, and governance.

Requirements

  • Relevant experience in vulnerability management, exposure management, cloud security, security engineering, threat intelligence, SOC operations, or a similar security role.
  • Strong understanding of vulnerabilities, security misconfigurations, attack techniques, attacker behaviour, and risk-based decision-making.
  • Experience with tools such as Wiz, Microsoft Defender, Nessus, Qualys, or equivalent vulnerability and cloud security platforms.
  • Understanding of cloud platforms, infrastructure, networking, software development practices, virtual machines, containers, modern application architectures, and identity security.
  • Ability to investigate complex security issues, analyse attack paths, and communicate technical risks and remediation priorities to technical and non-technical audiences.
  • Strong analytical, critical-thinking, problem-solving, communication, and collaboration skills.

Nice to have

  • Knowledge of container and Kubernetes security.
  • Experience identifying systemic control weaknesses and improving secure-by-design practices.

Culture & Benefits

  • Collaborative and inclusive environment focused on authenticity, curiosity, innovation, evidence-based decisions, and continuous improvement.
  • 25 days of paid annual leave plus an additional celebration day.
  • Employee discount, sample sales, private medical care, pension contributions, and a discretionary bonus scheme.
  • Flexible benefits allowance, personalised learning opportunities, and summer hours with 3pm finishes on Fridays in June, July, and August.
  • Free shuttlebus between Watford station and the Leavesden office, where applicable.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →