8 дней назад
Threat & Exposure Management Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat & Exposure Management Analyst (Cybersecurity): Identifying and prioritising vulnerabilities, misconfigurations, identity weaknesses, cloud risks, exposed assets, and attack paths across ASOS’s technology estate with an accent on threat intelligence, exploitability, business criticality, and risk-based remediation. Focus on analysing attack paths, discovering exposed assets, validating remediation, and improving exposure metrics, automation, workflows, and governance.
Location: London, United Kingdom
Company
is an online fashion retailer whose technology platform serves customers worldwide.
What you will do
- Identify and assess vulnerabilities, misconfigurations, identity and privilege weaknesses, exposed assets, cloud risks, and attack paths.
- Prioritise exposures using exploitability, threat intelligence, attacker behaviour, asset criticality, business context, accessibility, and compensating controls.
- Analyse how vulnerabilities, identities, privileges, configurations, and trust relationships could enable compromise of critical systems and data.
- Support attack-surface discovery across cloud platforms, applications, APIs, virtual machines, containers, endpoints, networks, and infrastructure.
- Partner with engineering, product, platform, and infrastructure teams on remediation and mitigation, tracking significant exposures through resolution.
- Improve exposure metrics, reporting, automation, data enrichment, prioritisation models, workflow integration, processes, and governance.
Requirements
- Relevant experience in vulnerability management, exposure management, cloud security, security engineering, threat intelligence, SOC operations, or a similar security role.
- Strong understanding of vulnerabilities, security misconfigurations, attack techniques, attacker behaviour, and risk-based decision-making.
- Experience with tools such as Wiz, Microsoft Defender, Nessus, Qualys, or equivalent vulnerability and cloud security platforms.
- Understanding of cloud platforms, infrastructure, networking, software development practices, virtual machines, containers, modern application architectures, and identity security.
- Ability to investigate complex security issues, analyse attack paths, and communicate technical risks and remediation priorities to technical and non-technical audiences.
- Strong analytical, critical-thinking, problem-solving, communication, and collaboration skills.
Nice to have
- Knowledge of container and Kubernetes security.
- Experience identifying systemic control weaknesses and improving secure-by-design practices.
Culture & Benefits
- Collaborative and inclusive environment focused on authenticity, curiosity, innovation, evidence-based decisions, and continuous improvement.
- 25 days of paid annual leave plus an additional celebration day.
- Employee discount, sample sales, private medical care, pension contributions, and a discretionary bonus scheme.
- Flexible benefits allowance, personalised learning opportunities, and summer hours with 3pm finishes on Fridays in June, July, and August.
- Free shuttlebus between Watford station and the Leavesden office, where applicable.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
14 дней назад
Senior Trust Security Analyst (UK Sovereign)
14 дней назад
Cybersecurity Consulting – EU Practice Lead (Cybersecurity)
9 дней назад
Privileged Access Management Assistant Manager (Cybersecurity)
13 дней назад
Information Security Analyst (Cybersecurity)
35 000 - 45 000GBP
10 дней назад
Cyber Threat Engineer (Cybersecurity)
12 дней назад