Senior Security Analyst (GRC)
London, United Kingdom
ASOS
Discover the latest fashion trends with ASOS. Shop the new collection of clothing, footwear, accessories, beauty products and more. Order today from ASOS.Company Description
We're ASOS. We blend our flair for fashion with our love of cutting-edge technology, but more importantly were interested in how we can bring the best out of you.
We exist to give people the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgment, and channel your creativity into a platform used by millions.
Through our Fashion with Integrity strategy we are driving diversity, equity and inclusion across every aspect of ASOS and ensuring every ASOSer can be their authentic self at work. We want our people to be whoever they want to be, because we believe people who bring their best selves to work, do their best work.
Job Description
An exciting opportunity has arisen for a Senior Security Analyst to join the ASOS Governance Risk and Compliance (GRC) Team in Cyber Security.
Reporting to the Information Security, Governance, Risk and Compliance Manager, this role will assist in the development, enhancement and execution of ASOS’s information security risk and compliance function. This will include activities such as helping to maintain our compliance with the Payment Card Industry Data Security Standard (PCI DSS), maintenance of our security policies and standards, and managing third-party supplier risk. We’re passionate about protecting our colleagues and the ASOS brand, so we would love someone who can thrive and develop in an ever growing and changing security landscape.
You will need to operate at several different levels: from being a team player in the GRC team, working alongside the wider Cyber Security Team and helping other colleagues in all ASOS business areas with their risk and compliance requirements.
Key Responsibilities
Responsibilities include, although not limited to:
- Management and maintenance of ASOS compliance projects and certifications (e.g. PCI DSS and ISO 27001), including co-ordination of internal audit activities
- Assist in maintaining the CISO’s cyber security risk registers and conduct cyber security risk assessments/risk workshops as required
- Management and tracking of corrective action plans for security audit findings, standards exceptions and control deficiencies
- Supporting other Cyber Security Teams and ASOS business areas with their risk and compliance requirements
- Authorship and maintenance of ASOS security policies and standards
- Management and support for the security assessment of third-party suppliers using ASOS third-party risk management platform
What Success Looks Like
- Being an integral member of the GRC Team to support the smooth running of GRC activities
- Building effective relationships across ASOS business areas
- Providing mentorship and guidance to junior GRC Team members
Qualifications
We’d Love To Meet Someone With
- The successful candidate will demonstrate competency in cyber security by having either the relevant work experience, completed a degree or obtained industry relevant certifications (e.g. CISSP, CISM, CISA, CRISC)
- Experience in industry standards and frameworks, such as ISO 27001, PCI DSS and NIST CSF
- Good knowledge of applicable data privacy practices and laws (e.g. DPA, GDPR)
- Broad knowledge around network technologies (especially cloud) and technical security
- Excellent organizational skills to plan and manage multiple projects across the business
- Analytical, problem solving and detail-oriented, with a proven ability to multi-task conflicting priorities
- Strong communication and presentation skills and ability to influence at all levels of an organisation
Additional Information
What’s in it for you?
- Employee discount (hello ASOS discount!)
- ASOS Develops (personal development opportunities across the business)
- Employee sample sales
- Access to a huge range of LinkedIn learning materials
- 25 days paid annual leave + an extra celebration day
- Discretionary performance related bonus scheme
- Private medical care scheme
- Flexible benefits allowance - which you can choose to take as extra cash, or use towards other benefits
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: CISA CISM CISO CISSP Cloud Compliance CRISC GDPR Governance ISO 27001 NIST PCI DSS Privacy Risk assessment Risk management Security assessment Strategy
Perks/benefits: Career development Flex hours Medical leave Salary bonus Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Senior Cyber Security Engineer jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Principal Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Manager Pentest H/F jobs
- Open Product Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Cyber Security Specialist jobs
- Open Cybersecurity Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Chief Information Security Officer jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Consultant jobs
- Open Security Specialist jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Cybersecurity Specialist jobs
- Open Security Researcher jobs
- Open IT Security Engineer jobs
- Open Security Operations Analyst jobs
- Open CISM-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open ISO 27001-related jobs
- Open Pentesting-related jobs
- Open Agile-related jobs
- Open Application security-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open Analytics-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Security assessment-related jobs
- Open Java-related jobs
- Open Malware-related jobs
- Open Security Clearance-related jobs
- Open DevOps-related jobs
- Open IDS-related jobs
- Open CEH-related jobs
- Open Forensics-related jobs
- Open EDR-related jobs
- Open Kubernetes-related jobs