At a Glance
- Tasks: Lead offensive security assessments and enhance ASOS's cyber defence capabilities.
- Company: Join ASOS, a global fashion retailer committed to inclusivity and creativity.
- Benefits: Enjoy employee discounts, personal development opportunities, and 25 days paid leave.
- Why this job: Be part of a dynamic team improving security while fostering a culture of cyber awareness.
- Qualifications: Relevant certifications and experience in penetration testing and ethical hacking required.
- Other info: On-call duties on a 4-week rota; flexibility is essential.
The predicted salary is between 36000 - 60000 £ per year.
We’re ASOS, the online retailer for fashion lovers all around the world. We exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you’re free to be your true self without judgement, and channel your creativity into a platform used by millions.
ASOS is recruiting for an Offensive Security Specialist within the SOC. This role will report into the SOC and IR Manager. This role will be key to leading offensive security assessments that strengthen defence capabilities for ASOS. Working closely with the cyber teams, you will identify security weaknesses, validate detection mechanisms, and provide actionable recommendations to enhance our security posture. You will contribute to the SOC team’s continuous validation and improvement in security controls and detection capabilities.
The role will involve the following:
- Threat Hunting - Proactively searching for signs of malicious activity within the network, identifying threats that might go undetected by automated systems.
- Penetration Testing - Simulating real-world attacks to test the effectiveness of security controls and identify weaknesses.
- Red Teaming - Engaging in adversarial simulations to assess the organisation's overall security posture and identify areas for improvement.
- Collaboration with Defensive Teams - Working closely with defensive security teams to share insights, improve detection capabilities, and enhance incident response processes.
- Developing Offensive Security Strategies - Designing and implementing strategies to proactively identify and mitigate security risks.
- Endpoint Monitoring - Contributing to incidents through to resolution and root cause analysis.
- Malware Analysis and Investigation.
- Contributing to Processes and SOPs.
- Developing and Mentoring Junior Team Members - Improving their skills and capabilities, along with wider knowledge transfer to other security and non-security teams to help build a culture of cyber security in departments.
- Maintaining Awareness - Keeping up to date with real-world cyber security threats and engaging in the innovation of new analytic methods for proactively detecting threats.
- On-Call Requirements - The role includes on-call duties on a 4-week rota basis. You will be required to be available for on-call shifts, ensuring prompt response to emergencies and urgent situations. Flexibility and reliability are essential for this aspect of the role.
About You:
- Relevant industry certifications like GPEN, OSCP, OSCE, CRTO, CRTP, PNPT, and experience working with frameworks like MITRE ATT&CK/D3FEND.
- Experience in Penetration testing, ethical hacking, red team methodologies and tools.
- Effectively communicate findings and remediation strategy to stakeholders.
- Develop comprehensive and accurate reports and presentations for both technical and non-technical audiences.
- Strong problem-solving skills and leadership abilities, with good interpersonal skills to build relationships and communicate findings professionally.
- Working knowledge of creating and tuning detection signatures, Indicators of Compromise (IOCs), and other content to detect malicious activity.
- Preferred experience with Microsoft’s security stack.
- Committed to continuous learning and professional development, and passionate about developing others.
Benefits:
- Employee discount (hello ASOS discount!)
- ASOS Develops (personal development opportunities across the business)
- Employee sample sales
- Access to a huge range of LinkedIn learning materials
- 25 days paid annual leave + an extra celebration day for a special moment
- Discretionary bonus scheme
- Private medical care scheme
Offensive Security Specialist employer: ASOS
Contact Detail:
ASOS Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Offensive Security Specialist
✨Tip Number 1
Familiarise yourself with the latest trends in offensive security and the tools commonly used in penetration testing. Being well-versed in frameworks like MITRE ATT&CK will not only help you understand the role better but also demonstrate your commitment to staying updated in this fast-paced field.
✨Tip Number 2
Engage with the cybersecurity community through forums, webinars, and local meetups. Networking with professionals in the field can provide valuable insights and may even lead to referrals or recommendations for the Offensive Security Specialist position at ASOS.
✨Tip Number 3
Prepare to discuss real-world scenarios during interviews. Be ready to share examples of past experiences where you've successfully identified vulnerabilities or improved security measures. This will showcase your practical knowledge and problem-solving skills.
✨Tip Number 4
Highlight your ability to communicate complex technical findings to non-technical stakeholders. ASOS values effective communication, so demonstrating how you've done this in previous roles can set you apart from other candidates.
We think you need these skills to ace Offensive Security Specialist
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities of an Offensive Security Specialist at ASOS. Familiarise yourself with key terms like threat hunting, penetration testing, and red teaming to tailor your application effectively.
Highlight Relevant Experience: In your CV and cover letter, emphasise your experience with penetration testing, ethical hacking, and any relevant certifications such as GPEN or OSCP. Use specific examples to demonstrate your skills and how they relate to the job description.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for cybersecurity and your commitment to continuous learning. Mention how your background aligns with ASOS's values and how you can contribute to their security posture.
Proofread Your Application: Before submitting, carefully proofread your CV and cover letter for any spelling or grammatical errors. A polished application reflects your attention to detail, which is crucial in the field of cybersecurity.
How to prepare for a job interview at ASOS
✨Showcase Your Technical Skills
Be prepared to discuss your experience with penetration testing, red teaming, and threat hunting. Bring examples of past projects or assessments you've conducted, and be ready to explain the methodologies you used and the outcomes achieved.
✨Understand ASOS's Security Landscape
Research ASOS's current security posture and any recent incidents in the news. This will help you tailor your responses and demonstrate your genuine interest in contributing to their security team.
✨Communicate Clearly
Since you'll need to present findings to both technical and non-technical audiences, practice explaining complex concepts in simple terms. This will show your ability to bridge the gap between different teams within the organisation.
✨Emphasise Continuous Learning
ASOS values professional development, so highlight your commitment to continuous learning. Discuss any relevant certifications you hold or are pursuing, and mention how you stay updated on the latest cyber threats and trends.