Job Description
As an experienced Cloud Security Manager, you will play a pivotal role in ensuring the security and integrity of our cloud-based infrastructure and services. You will supervise a small team of cloud security practitioners, ensuring the efficient and effective use of security technologies to protect our assets, mitigate risks, and preserve the confidentiality, integrity, and availability of our information systems.
This role involves a blend of technical expertise, stakeholder management skills, and communication capabilities to ensure the company's security posture is robust, efficient, and compliant with industry standards and regulations.
We’re quite passionate about protecting our colleagues and the ASOS brand, so we would love someone who can thrive and develop on an ever growing and changing security landscape.
Responsibilities:
1. Lead a small team of cloud security practitioners, providing guidance, support, and mentorship to foster professional growth
2. Contribute to and implement an overarching cloud security strategy aligned with business objectives, industry best practices, and regulatory requirements.
3. Implement and maintain security controls and configurations for cloud-based environments, including but not limited to AWS, Azure, and Google Cloud Platform.
4. Conduct risk assessments and security audits to identify vulnerabilities, threats, and compliance gaps within our cloud infrastructure.
5. Develop a suite of metrics that allow the organisation to track vulnerabilities across multiple platforms and applications, while also tracking remediation progress and providing insight into key trends.
6. Develop and enforce cloud security policies, standards, and procedures to ensure compliance with regulatory requirements and industry best practices.
7. Collaborate with cross-functional teams, including IT, DevOps, and development teams, to integrate security into the entire SDLC, cloud development lifecycle and cloud projects when needed.
Qualifications
Qualifications/Experience/Skills
8. Proven experience in cloud security expertise
9. Azure Kubernetes Service (AKS) experience, alongside Kubernetes, Docker, policy as code and securing containers expertise
10. In-depth knowledge of security frameworks, standards, and best practices (, ISO 27001, NIST Cloud Security Framework, CIS hardening and the CSA CCM).
11. Proven knowledge of “service wrappers” as they pertain to best practice around product/platform lifecycles
12. Experience working with Microsoft cloud security technologies, especially Sentinel, Defender and Purview
13. Experience working with other cloud security technologies and environments (, AWS & GCP)
14. Application security/DevSecOps knowledge is preferable, especially when applied to a Secure Software Development Life Cycle (SSDLC) framework
Additional Information
BeneFITS’
15. Employee discount (hello ASOS discount!)
16. ASOS Develops (personal development opportunities across the business)
17. Employee sample sales
18. Access to a huge range of LinkedIn learning materials
19. 25 days paid annual leave + an extra celebration day for a special moment
20. Discretionary bonus scheme
21. Private medical care scheme
22. Flexible benefits allowance - which you can choose to take as extra cash, or use towards other benefits