The Threat & Exposure Management analyst helps ASOS understand and reduce the technology exposures most likely to contribute to material cyber risk.
Rather than treating vulnerabilities in isolation, the role considers vulnerabilities, misconfigurations, identity and privilege weaknesses, cloud security risks, exposed assets and attack paths in the context of threat intelligence, exploitability and business criticality.
You’ll turn technical security data into clear, risk-based priorities, helping engineering and technology teams focus remediation effort where it delivers the greatest reduction in exposure and cyber risk.
This is an analytical and collaborative role. You’ll work across ASOS’s technology estate to understand what is exposed, how it could realistically be exploited, what an attacker could reach, what matters most to ASOS, and what we should do about it.
Role details
Identify and assess technology exposures across ASOS, including vulnerabilities, misconfigurations, identity and privilege weaknesses, exposed assets and services, cloud security risks and attack paths.
Perform risk-based analysis and prioritisation, considering exploitability, threat intelligence, attacker behaviour, asset criticality, business context, accessibility and compensating controls to determine which exposures matter most.
Analyse attack paths to understand how vulnerabilities, configurations, identities, privileges and trust relationships could combine to enable compromise of critical ASOS systems, services or data.
Apply threat intelligence and exploitation data to understand which threats and exposures are most relevant to ASOS and where action should be prioritised.
Assess exposure across modern technology environments, including cloud platforms, applications, APIs, virtual machines, containers, endpoints, identities, networks and supporting infrastructure.
Support continuous attack-surface discovery, helping identify unknown, unmanaged, incorrectly classified or unexpectedly exposed assets and services.
Partner with engineering, product, platform and infrastructure teams to agree proportionate remediation or mitigation strategies, focusing effort on actions that deliver the greatest reduction in cyber risk.
Track significant exposures through to resolution, escalating material or persistent risk where appropriate and helping teams identify effective remediation or compensating controls.
Identify recurring exposure patterns and systemic control weaknesses, working with technology teams to address root causes and eliminate classes of exposure rather than repeatedly treating individual findings.
Assess the effectiveness of preventative and compensating controls in reducing identified exposures and attack paths, recommending improvements where required.
Validate significant exposures and remediation outcomes, using appropriate technical evidence to confirm that identified risk has been materially reduced.
Translate technical findings into clear risk insights, communicating exposure, potential business impact and remediation priorities to both technical and non-technical stakeholders.
Contribute to meaningful exposure metrics and reporting that demonstrate changes in organisational risk and remediation effectiveness rather than relying solely on vulnerability volumes or severity scores.
Contribute to the continuous improvement of ASOS’s Threat & Exposure Management capability, including automation, data enrichment, prioritisation models, metrics, reporting, workflow integration, processes and governance.
Promote secure-by-design and proportionate, risk-based security practices across ASOS technology teams.
/01 Company Description
We're ASOS, the online retailer for fashion lovers all around the world.
We exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgement, and channel your creativity into a platform used by millions.
Everyone needs some help showing up as their best self. We're Disability Confident Committed - let our Talent team know if you need any reasonable adjustments throughout the recruitment process.
/02 Job Qualifications
About You:
Relevant experience as a Vulnerability Analyst, SOC Analyst, or in a similar role.
Understanding of common vulnerability types and attack techniques.
Experience with vulnerability management, cloud security or security assessment tooling (e.g. Wiz, Defender, Nessus, Qualys or similar).
Understanding of enterprise technologies, including cloud platforms, infrastructure, networking and software development practices.
Ability to leverage threat intelligence to assess vulnerability risk and inform remediation priorities.
Knowledge of container and Kubernetes security is desirable.
Understanding of cyber security risk management principles and risk-based decision making.
Excellent written and verbal communication skills for presenting technical information clearly to non-technical audiences.
Naturally inquisitive, with the ability to investigate security risks across diverse technologies and identify potential threats to the organisation.
Self-motivated with strong problem-solving and critical thinking skills.
/03 Additional Info
You don’t need to have worked in a role called Threat & Exposure Management before. We’re looking for someone who can combine technical security knowledge with curiosity, analytical thinking and an understanding of risk.
You’ll ideally have:
Relevant experience in exposure management, vulnerability management, cloud security, security engineering, threat intelligence, SOC/security operations, or another role involving the analysis of technology and cyber risk.
A strong understanding of common vulnerabilities, security misconfigurations and attacker techniques across modern technology environments.
Experience using vulnerability, exposure, cloud security or security assessment tooling such as Wiz, Microsoft Defender, Nessus, Qualys or equivalent platforms.
An understanding of cloud platforms and cloud-native technologies, including virtual machines, containers and modern application architectures.
An understanding of identity and privilege as part of the attack surface, and how identity weaknesses can contribute to attack paths.
An understanding of attack paths and attacker behaviour, including how multiple weaknesses can be combined to reach critical assets or services.
An understanding of cyber security risk management and the ability to make risk-based rather than severity-based decisions.
Knowledge of container and Kubernetes security is desirable.
Strong analytical and critical-thinking skills, with a naturally inquisitive approach to investigating security issues across diverse technologies.
Strong written and verbal communication skills, with the ability to explain complex technical issues clearly and turn them into actionable priorities for different audiences.
A collaborative approach and the ability to work effectively with engineering and technology teams to achieve practical security outcomes.
What success looks like Success in this role isn’t measured by how many vulnerabilities you find or tickets you create. It’s measured by how effectively we understand and reduce the exposures that matter most to ASOS.
You’ll help us move from vulnerability management based primarily on individual findings and severity scores towards a more continuous, threat-informed and risk-based approach to understanding and reducing our attack surface.
BeneFITS’
Employee discount (hello ASOS discount!)
Employee sample sales
25 days paid annual leave + an extra celebration day for a special moment
Discretionary bonus scheme
Private medical care scheme
Flexible benefits allowance - which you can choose to take as extra cash, or use towards other benefits
Opportunity for personalised learning and in-the-moment experiences that enable you to thrive and excel in your role
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
what our people say
Meet The Team
Meet Zijiao Li -
Tech @ ASOS
Meet Amy Richardson -
Tech @ ASOS
Meet Si Jobling -
Tech @ ASOS
I love working at ASOS in my team because of the great atmosphere. From day one I already felt like being part of the team, everyone is so friendly, approachable and willing to help. It’s the place where you feel trusted and are given the opportunities & time to explore your full potential. As someone who just relocated to London, I also appreciate the international and cultural diverse environment – it’s ok to be whoever you want to be!
As a software engineer with a love for fashion, I feel extremely lucky to be part of a fashion company that priorities technology, innovation and customer experience to the same degree as their clothing.
As someone who left ASOS after 7 years but came back, it speaks volumes how much I love working at ASOS. The obvious reason is the people, not just in Tech but beyond. There's an unspoken respect and authenticity between everyone who works here
Zijiao Li
Tech @ ASOS
I love working at ASOS in my team because of the great atmosphere. From day one I already felt like being part of the team, everyone is so friendly, approachable and willing to help. It’s the place where you feel trusted and are given the opportunities & time to explore your full potential. As someone who just relocated to London, I also appreciate the international and cultural diverse environment – it’s ok to be whoever you want to be!
Amy Richardson
Tech @ ASOS
As a software engineer with a love for fashion, I feel extremely lucky to be part of a fashion company that priorities technology, innovation and customer experience to the same degree as their clothing.
Si Jobling
Tech @ ASOS
As someone who left ASOS after 7 years but came back, it speaks volumes how much I love working at ASOS. The obvious reason is the people, not just in Tech but beyond. There's an unspoken respect and authenticity between everyone who works here
our business values
our business values
our business values
our business values
our business values
our business values
our business values
our business values
our business values
our business values
our business values
our business values
our business values
our business values
our business values
our business values
loading
We are Customer First
We couldn’t be ASOS without our customers.
Across every behaviour, value, and all that we do, we see everything through our customers’ eyes. That means never taking anything for granted and always zeroing in on every single detail. So we can always bring our best as a team, and our customers can have an amazing experience, every time.
We are Authentic
We work together to be honest, transparent, and our full authentic selves.
This is our ASOS. Our culture, built on collaboration and togetherness, and supported by what’s real and honest. We know that we win bigger when we win as a diverse team. That means celebrating our differences and using them to help us stand out from the crowd, without losing our authenticity and individuality.
We are Brave
We challenge each other to aim high and reach our potential.
Doing nothing gets us nowhere. We may be proud of everything we’ve done so far, but there’s still so much more to explore. We believe we can always be wiser, faster, stronger, bigger, braver, kinder…so asking ‘why’ isn’t just a question, it’s a necessity. We use our voice to drive us forward, speaking up on the things our people and customers care about and using our curiosity to create possibility.
We are Creative
We know innovation leads to inspiration – it’s what makes us stronger
Change is in our DNA. By acting fast and staying one step ahead of the curve, we can be a leader, not a follower. But for our products and platform to be innovative, they have to be fuelled by creative passion and a deep understanding of our customers and our people.
We always Deliver
We couldn’t be excellent without evidence – so whatever we’re doing, we have proof of why we’re doing it.
It takes facts and data to tell our stories and help us make our decisions in the most effective way possible. This means we can do what we say and own what we do, no matter how long it takes us to do it. We aren’t about nonsense ifs, buts and maybes, we’re about creating an ASOS that’s built for future success on delivered success.
Our Benefits
Employee Discount
The most asked-about benefit! As an ASOSer, you’ll receive an exclusive employee discount. You can also nominate a family member or friend to share your discount with.
Pension
Retirement might not be on your mind right now, but it’s important to prep for it. We offer matched contributions up to 5% to help you save.
Private Medical Care scheme
If you join our Private Medical Care scheme, you’ll get fast and effective access to medical cover.
Celebratory Day!
Get an extra day off in addition to the 25 days of annual leave you get! Spend it celebrating the big days in life, whether it’s birthdays, cultural holidays, weddings and anything else.
Shuttlebus Service (if you're based in our Leavesden office)
It’s more of a work perk, but we offer a free shuttlebus between Watford station and our office in Leavesden.
Sample Sales
We’ve always got fun things happening in our offices, but the one ASOSers get most excited about is our sample sales. Plus, all proceeds from the sample sale get donated to the ASOS Foundation, which helps our charity partners abroad.
Career Development
You’ll have the opportunity for personalised learning and in-the-moment experiences to create a dynamic and agile learning environment that empowers you to thrive and excel in your role.
Summer Hours
We finish at 3pm on Fridays in June, July and August!! This perk doesn’t mean a dip in your salary – it just gives you extra freedom to enjoy those summer weekends however you want.
Fixed Annual Payment
You'll be given a fixed annual payment depending on your level, in addition to your salary, as a thank you for all your hard work.
Location
Our HQ in London
Our HQ in Camden was once a cigarette factory – now, the iconic Art Deco building has been completely renovated with spacious office areas, ASOS Studios (where we shoot all our products), beauty rooms and a free gym. There’s also a subsidised canteen and café.