At a Glance
- Tasks: Join ASOS as a Senior Security Engineer, focusing on secure enterprise solutions and risk reduction.
- Company: ASOS is a global online fashion retailer empowering customers to express their true selves.
- Benefits: Enjoy employee discounts, personal development, 25 days leave, and flexible benefits.
- Why this job: Be part of a creative culture that values inclusivity and innovation in cybersecurity.
- Qualifications: Experience in Cloud Security, automation, and strong scripting skills are essential.
- Other info: Mid-senior level role with opportunities for growth and collaboration in a dynamic team.
The predicted salary is between 43200 - 72000 £ per year.
We’re ASOS, the online retailer for fashion lovers all around the world. We exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you’re free to be your true self without judgement, and channel your creativity into a platform used by millions. We’re proud members of Inclusive Companies, are Disability Confident Committed, and have signed the Business in the Community Race at Work Charter. We placed 8th in the Inclusive Top 50 Companies Employer list.
As a Security Engineer at ASOS, you will be passionate about security and engineering best practices. You will join a multidisciplinary team, collaborating with other Security Engineers, Product Managers, and Security teams. Your role involves designing, building, and delivering secure, high-quality enterprise solutions across various initiatives, sharing your security expertise to enhance our security posture and reduce risks. You will leverage your software and platform engineering skills to develop tooling and integrations, gaining deep knowledge of automated security tools, supporting their delivery and maintenance to empower engineers to build secure applications efficiently. Your impact will resonate within Cyber Security, engineering communities, and operations teams.
Responsibilities
- Drive security efforts across ASOS Engineering through scalable security tool integrations into developer workflows.
- Provide documentation, training, guidance, and support for our security tools.
- Develop tools, services, and scripts to support internal security projects.
- Support security risk assessments and influence technical architecture decisions.
- Assist with Application Security Assessments, including Threat Modelling, Attack Surface Analysis, and Security Code Reviews.
- Conduct security training on best practices.
- Ensure compliance with regulations like GDPR and PCI-DSS.
- Define and communicate security non-functional requirements to development teams.
- Explain mitigation techniques for emerging threats to technical and non-technical stakeholders.
- Collaborate with other Security Engineers on projects supporting security and fraud functions.
- Stay updated on security threats, industry trends, and emerging technologies.
Qualifications
About You
- Experience in Cloud Security, Platform Engineering, or Software Engineering, with a focus on automation, DevOps, and tooling.
- Strong scripting and automation skills within CI/CD DevOps environments.
- Knowledge of security scanning practices such as SAST, SCA, IAC Scanning, Credential Scanning, DAST.
- Experience implementing Application Security Tooling.
- Proficiency in modern technologies and languages like PowerShell, YAML, Python, C#, Java, Docker, Kubernetes.
- Understanding of object-oriented languages (e.g., C#, Java, Python).
- Experience with REST/Graph API.
- Excellent communication skills.
- Experience with agile development and Secure SDLC.
- Understanding of DevSecOps practices and security best practices fostering cultural change.
Additional Information
Benefits
- Employee discount (hello ASOS discount!)
- Personal development opportunities through ASOS Develops
- Employee sample sales
- Access to LinkedIn Learning resources
- 25 days paid leave plus a celebration day
- Discretionary bonus scheme
- Private medical care
- Flexible benefits allowance, convertible to cash or other benefits
Discover what life at ASOS is like by searching #InsideASOS on social media.
Senior Security Engineer employer: ASOS.com
Contact Detail:
ASOS.com Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer
✨Tip Number 1
Familiarise yourself with ASOS's culture and values. Understanding their commitment to inclusivity and creativity can help you align your responses during interviews, showcasing how you embody these principles.
✨Tip Number 2
Stay updated on the latest trends in security technologies and practices. Being able to discuss recent developments or tools in your interview will demonstrate your passion for the field and your proactive approach to learning.
✨Tip Number 3
Prepare to discuss specific examples of your experience with cloud security and automation. Highlighting your hands-on experience with relevant tools and scripting languages will set you apart from other candidates.
✨Tip Number 4
Network with current or former ASOS employees on platforms like LinkedIn. Gaining insights from their experiences can provide you with valuable information about the role and the company culture, which you can leverage in your application.
We think you need these skills to ace Senior Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in Cloud Security, Platform Engineering, and Software Engineering. Emphasise your automation and DevOps skills, as well as any specific tools or languages mentioned in the job description.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for security and engineering best practices. Mention how your previous experiences align with ASOS's mission and values, and express your enthusiasm for contributing to their security efforts.
Showcase Relevant Projects: Include examples of past projects where you implemented security tooling or conducted security assessments. Highlight your role in these projects and the impact they had on improving security posture.
Prepare for Technical Questions: Anticipate technical questions related to security practices, automation, and the tools you’ve used. Be ready to discuss your experience with security scanning practices and how you’ve applied them in real-world scenarios.
How to prepare for a job interview at ASOS.com
✨Showcase Your Security Passion
Make sure to express your enthusiasm for security and engineering best practices during the interview. Share specific examples of projects where you implemented security measures or improved security posture, as this will demonstrate your commitment to the field.
✨Demonstrate Technical Expertise
Be prepared to discuss your experience with cloud security, automation, and the various security scanning practices mentioned in the job description. Highlight your proficiency in scripting languages like Python or PowerShell, and be ready to explain how you've used these skills in past roles.
✨Communicate Clearly
Since excellent communication skills are essential for this role, practice explaining complex security concepts in simple terms. This will help you connect with both technical and non-technical stakeholders, showcasing your ability to bridge the gap between different teams.
✨Stay Updated on Industry Trends
Research the latest security threats and emerging technologies relevant to the role. Being knowledgeable about current trends will not only impress your interviewers but also show that you are proactive and committed to continuous learning in the ever-evolving field of cybersecurity.