As one of our Security Engineers you are passionate about security and great engineering practises. You will join a multidisciplinary team working together with other Security Engineers Product Managers and Security teams. As an Engineer you will design build and deliver secure highquality enterprise solutions across numerous initiatives within the organisation spreading your security knowledge to an everexpanding engineering community increasing our security posture and helping identify and reduce our risk exposure when building applications.
You will use your strong software / platform engineering skillset to help design and build tooling and integrations across a wide range of areas. You will gain deep knowledge on automated security tools and support the delivery and maintenance of these tools to empower engineers to build high quality secure applications with minimal disruption to their delivery. Your impact will be felt within Cyber Security and wider by our tech communities engineers and operations teams.
Responsibilities
- Drive security efforts across ASOS Engineering (SecDevOps Secure SDLC) through building scalable security tool integrations into the developers workflow.
- Provide documentation training guidance and support to teams using our tools.
- Develop tools services and scripts to support with internal Security projects.
- Support with security risk decisions and influence technical architecture.
- Support with Application Security Assessments (incl. Threat Modelling Attack Surface Analysis Application Security Architecture Reviews and Security Code Reviews) where required.
- Support with security training around Security Best Practices.
- Understand and support teams with adherence to regulations (e.g. GDPR PCIDSI)
- Defining and explaining security nonfunctional requirements for development teams.
- Ability to articulate mitigation and development techniques around emerging threats to technical and nontechnical stakeholders
- Work with other Security Engineers on collaborative projects and deliverables that support other Security & Fraud functions and business needs.
- Stay updated on emerging security threats industry trends and evolving technologies.
Qualifications : About You
Experience gained working in Cloud Security Platform Engineering or Software Engineering or other related roles with a leaning towards automation DevOps and toolingStrong experience with scripting and automation within a CI / CD DevOps contextA solid understanding of fundamental security scanning practises such as SAST SCA IAC Scanning Credential Scanning DASTExperience with implementing Application Security ToolingExperience building applications scripts pipelines or automation using modern technologies and languages such as PowerShell YAML Python C# Java Docker KubernetesA good understanding of objectoriented software languages (e.g. C# Java Python)REST / Graph API experienceStrong communication skillsExperienced in agile software delivery and Software Development Lifecycle / Secure SDLCExperience with / understanding of DevOps / DevSecOps Security best practices and driving cultural change.Additional Information :
BeneFITS
Employee discount (hello ASOS discount!ASOS Develops (personal development opportunities across the business)Employee sample salesAccess to a huge range of LinkedIn learning materials25 days paid annual leave an extra celebration day for a special momentDiscretionary bonus schemePrivate medical care schemeFlexible benefits allowance which you can choose to take as extra cash or use towards other benefitsWhy take our word for it Search #InsideASOS on our socials to see what life at ASOS is like.
Want to find out how were tech powered Check out the ASOS Tech Podcast here . Prefer reading Check out our ASOS Tech Blog here Work :
Employment Type :
Fulltime
Key Skills
Car Driving,Access,CFA,Excel,Irrigation,Marine Services
Experience : years
Vacancy : 1