791,964open jobs
50,470companies
123,351added this week
Browse all
Salary
≈ $77k – $165k per year (Estimated)
Location
In office (London)
Seniority
Middle
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 25, 2026. First seen by Alion on Sep 24, 2026. ASOS scores B on the Alion truth index.

Overview
Company
Impact
Profile match
ASOS is a major British online fast-fashion and cosmetics retailer targeted primarily at young adult consumers. Founded in London in 2000, the e-commerce giant curates a selection of over 850 partner brands alongside its proprietary fashion labels, including ASOS Design and Topshop. Operating through localized digital storefronts and global distribution hubs, the company fulfills orders for millions of active customers across more than 150 countries.

We're ASOS, the online retailer for fashion lovers all around the world.

We exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgement, and channel your creativity into a platform used by millions.

Everyone needs some help showing up as their best self. We're Disability Confident Committed - let our Talent team know if you need any reasonable adjustments throughout the recruitment process.

The Vulnerability, Threat & Exposure Management analyst helps ASOS understand and reduce the technology exposures most likely to contribute to material cyber risk.

Rather than treating vulnerabilities in isolation, the role considers vulnerabilities, misconfigurations, identity and privilege weaknesses, cloud security risks, exposed assets and attack paths in the context of threat intelligence, exploitability and business criticality.

You’ll turn technical security data into clear, risk-based priorities, helping engineering and technology teams focus remediation effort where it delivers the greatest reduction in exposure and cyber risk.

This is an analytical and collaborative role. You’ll work across ASOS’s technology estate to understand what is exposed, how it could realistically be exploited, what an attacker could reach, what matters most to ASOS, and what we should do about it.

Role details

  • Identify and assess technology exposures across ASOS, including vulnerabilities, misconfigurations, identity and privilege weaknesses, exposed assets and services, cloud security risks and attack paths.
  • Perform risk-based analysis and prioritisation, considering exploitability, threat intelligence, attacker behaviour, asset criticality, business context, accessibility and compensating controls to determine which exposures matter most.
  • Analyse attack paths to understand how vulnerabilities, configurations, identities, privileges and trust relationships could combine to enable compromise of critical ASOS systems, services or data.
  • Apply threat intelligence and exploitation data to understand which threats and exposures are most relevant to ASOS and where action should be prioritised.
  • Assess exposure across modern technology environments, including cloud platforms, applications, APIs, virtual machines, containers, endpoints, identities, networks and supporting infrastructure.
  • Support continuous attack-surface discovery, helping identify unknown, unmanaged, incorrectly classified or unexpectedly exposed assets and services.
  • Partner with engineering, product, platform and infrastructure teams to agree proportionate remediation or mitigation strategies, focusing effort on actions that deliver the greatest reduction in cyber risk.
  • Track significant exposures through to resolution, escalating material or persistent risk where appropriate and helping teams identify effective remediation or compensating controls.
  • Identify recurring exposure patterns and systemic control weaknesses, working with technology teams to address root causes and eliminate classes of exposure rather than repeatedly treating individual findings.
  • Assess the effectiveness of preventative and compensating controls in reducing identified exposures and attack paths, recommending improvements where required.
  • Validate significant exposures and remediation outcomes, using appropriate technical evidence to confirm that identified risk has been materially reduced.
  • Translate technical findings into clear risk insights, communicating exposure, potential business impact and remediation priorities to both technical and non-technical stakeholders.
  • Contribute to meaningful exposure metrics and reporting that demonstrate changes in organisational risk and remediation effectiveness rather than relying solely on vulnerability volumes or severity scores.
  • Contribute to the continuous improvement of ASOS’s Threat & Exposure Management capability, including automation, data enrichment, prioritisation models, metrics, reporting, workflow integration, processes and governance.
  • Promote secure-by-design and proportionate, risk-based security practices across ASOS technology teams.

About You:

  • Relevant experience as a Vulnerability Analyst, SOC Analyst, or in a similar role.
  • Understanding of common vulnerability types and attack techniques.
  • Experience with vulnerability management, cloud security or security assessment tooling (e.g. Wiz, Defender, Nessus, Qualys or similar).
  • Understanding of enterprise technologies, including cloud platforms, infrastructure, networking and software development practices.
  • Ability to leverage threat intelligence to assess vulnerability risk and inform remediation priorities.
  • Knowledge of container and Kubernetes security is desirable.
  • Understanding of cyber security risk management principles and risk-based decision making.
  • Excellent written and verbal communication skills for presenting technical information clearly to non-technical audiences.
  • Naturally inquisitive, with the ability to investigate security risks across diverse technologies and identify potential threats to the organisation.
  • Self-motivated with strong problem-solving and critical thinking skills.

You don’t need to have worked in a role called Threat & Exposure Management before. We’re looking for someone who can combine technical security knowledge with curiosity, analytical thinking and an understanding of risk.

You’ll ideally have:

  • Relevant experience in exposure management, vulnerability management, cloud security, security engineering, threat intelligence, SOC/security operations, or another role involving the analysis of technology and cyber risk.
  • A strong understanding of common vulnerabilities, security misconfigurations and attacker techniques across modern technology environments.
  • Experience using vulnerability, exposure, cloud security or security assessment tooling such as Wiz, Microsoft Defender, Nessus, Qualys or equivalent platforms.
  • An understanding of cloud platforms and cloud-native technologies, including virtual machines, containers and modern application architectures.
  • An understanding of identity and privilege as part of the attack surface, and how identity weaknesses can contribute to attack paths.
  • An understanding of attack paths and attacker behaviour, including how multiple weaknesses can be combined to reach critical assets or services.
  • An understanding of cyber security risk management and the ability to make risk-based rather than severity-based decisions.
  • Knowledge of container and Kubernetes security is desirable.
  • Strong analytical and critical-thinking skills, with a naturally inquisitive approach to investigating security issues across diverse technologies.
  • Strong written and verbal communication skills, with the ability to explain complex technical issues clearly and turn them into actionable priorities for different audiences.
  • A collaborative approach and the ability to work effectively with engineering and technology teams to achieve practical security outcomes.

What success looks like

Success in this role isn’t measured by how many vulnerabilities you find or tickets you create. It’s measured by how effectively we understand and reduce the exposures that matter most to ASOS.

You’ll help us move from vulnerability management based primarily on individual findings and severity scores towards a more continuous, threat-informed and risk-based approach to understanding and reducing our attack surface.

BeneFITS’

  • Employee discount (hello ASOS discount!)
  • Employee sample sales
  • 25 days paid annual leave + an extra celebration day for a special moment
  • Discretionary bonus scheme
  • Private medical care scheme
  • Flexible benefits allowance - which you can choose to take as extra cash, or use towards other benefits
  • Opportunity for personalised learning and in-the-moment experiences that enable you to thrive and excel in your role
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
791,964 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
London
$63k – $81k per year • In office • Full-Time • Huntingdon
Python
PowerShell
AI/ML
Machine Learning
DevOps
Rest API
Terraform
Ansible
GitHub Actions
Istio
Rancher
GitLab CI
CI/CD
Jenkins
Git
Kubernetes
Service Mesh
IAM
Cybersecurity
SonarQube
Trivy
CIS Benchmarks
OWASP Top 10
SIEM
Cryptography
Vault
Apply
SOC Reporter 2 days ago
≈ $45k – $98k per year (Estimated) • In office • Full-Time • Warrington
Apply
≈ $45k – $98k per year (Estimated) • In office • Full-Time • Warrington
Apply
≈ $48k – $116k per year (Estimated) • In office • Full-Time • 2+ years exp • Mansfield
Cybersecurity
MITRE ATT&CK
CVSS
Apply
$124k – $214k per year • In office • Cheltenham
DevOps
Splunk
Kibana
Azure
Cybersecurity
Crowdstrike
Microsoft Sentinel
Microsoft Defender
Microsoft Entra ID
X-Ways Forensics
SIEM
Apply
Hybrid • Full-Time • London
Python
JavaScript
PowerShell
Bash
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
Platform Engineering
Linux
Management
Agile
Apply
≈ $31k – $64k per year (Estimated) • Hybrid • 4+ years exp • Bachelor's Degree • Moscow
Python
SQL
AI/ML
LangChain
Claude
ChatGPT
LlamaIndex
vLLM
CUDA Toolkit
Fine-tuning
Prompt Engineering
Chain-of-Thought
AI Agents
Ollama
Gemini
LLM
RAG
CUDA
LLMOps
Structured Outputs
Tool Use
Machine Learning
DevOps
Docker
Kubernetes
Management
n8n
Apply
In office • Internship • Bachelor's Degree • Singapore
Python
Java
SQL
C++
Databases
ClickHouse
HBase
Milvus
Presto
Trino
StarRocks
DevOps
Kubernetes
Apply
≈ $84k – $223k per year (Estimated) • In office • 5+ years exp • Jakarta
Python
Go
Java
Databases
MySQL
PostgreSQL
Redis
RabbitMQ
Apache Kafka
AI/ML
Copilot
Claude
ChatGPT
Prompt Engineering
LLM
DevOps
GCP
CI/CD
AWS
Docker
Kubernetes
Apply
≈ $101k – $208k per year (Estimated) • In office • Bachelor's Degree • Jakarta
Python
Go
Java
C++
Databases
MySQL
Redis
Apache Kafka
DevOps
CI/CD
Kubernetes
Apply
Security Analyst 14 days ago
≈ $71k – $153k per year (Estimated) • Hybrid • Full-Time • London
Management
SharePoint
Intercom
Apply
≈ $98k – $200k per year (Estimated) • Hybrid • Full-Time • London
Python
Scala
Databases
Databricks
AI/ML
Spark
Machine Learning
DevOps
Azure
CI/CD
Apply
SEO Lead 2 days ago
≈ $83k – $166k per year (Estimated) • Hybrid • Full-Time • London
AI/ML
LLM
Management
Agile
Apply
≈ $68k – $118k per year (Estimated) • Hybrid • Full-Time • London
SQL
AI/ML
Copilot
Analytics
Power BI
Alteryx
Microsoft Excel
Apply
≈ $46k – $115k per year (Estimated) • In office • Full-Time • London
Management
Power Automate
Power Apps
Agile
Apply
$106k – $199k per year • Equity 0.2–0.8% • In office • Full-Time • 1+ year exp • London
TypeScript
Databases
PostgreSQL
AI/ML
Red Teaming
Edge AI
Browser Agents
DevOps
Linux
Windows
Cybersecurity
Okta
ISO 27001
OWASP Top 10
SOC 2
Zero Trust
Microsoft Entra ID
Apply
≈ $66k – $156k per year (Estimated) • In office • Full-Time • Manchester • London • Cardiff • Edinburgh • Belfast
AI/ML
Recommender Systems
Apply
≈ $101k – $166k per year (Estimated) • Remote (United Kingdom, GMT hours) • Full-Time • London
AI/ML
Model Context Protocol
AI Agents
Ray
Cybersecurity
DLP
Management
Agile
Apply
≈ $13k – $32k per year (Estimated) • In office • 7+ years exp • London • Kuala Lumpur
Apply
Equity • In office • London
Apply
See all jobs
This is one of many
791,964 more open roles from verified company boards, updated every day.