As one of our Security Engineers, you will join a multidisciplinary team, working together with other Security Engineers, Product Managers and Security teams. You will design, build and deliver secure, high-quality enterprise solutions across numerous initiatives within the organisation, spreading your security knowledge to an ever-expanding engineering community, increasing our security posture and helping identify and reduce our risk exposure when building applications. Your primary focus is to safeguard software applications from potential threats and breaches. You work as a bridge between security and engineering, ensuring that applications are designed, developed, and deployed in a secure manner. Your impact will be felt within Cyber Security and wider by our tech communities, engineers and operations teams. Responsibilities • Drive security efforts across ASOS Engineering (SecDevOps, Secure SDLC) • Drive security risk decisions and influence technical architecture. • Drive Application Security Assessments (incl. Threat Modelling, Attack Surface Analysis, Application Security Architecture Reviews and Security Code Reviews) • Play a role in proactively identifying potential security risks, developing mitigation strategies, and ensuring that security measures are incorporated right from the beginning of the application development process. • Produce and Deliver Security Training around Security Best Practices. • Develop security tooling with business objectives, industry best practices, and regulatory requirements. • Understand and support teams with adherence to regulations (e.g. GDPR, PCI-DSI) • Helping teams implement Cryptography correctly, in line with ASOS and industry standards. • Ability to articulate mitigation and development techniques around emerging threats to technical and non-technical stakeholders • Collaborate with the incident response team in investigating and responding to security incidents. • Support with risk assessments and vulnerability assessments to identify potential security gaps or weaknesses in existing technologies Were ASOS, the online retailer for fashion lovers all around the world. We exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. At ASOS, youre free to be your true self without judgement, and channel your creativity into a platform used by millions. But how are we showing up? Were proud members of Inclusive Companies, are Disability Confident Committed and have signed the Business in the Community Race at Work Charter and we placed 8th in the Inclusive Top 50 Companies Employer list. Everyone needs some help showing up as their best self. Let our Talent team know if you need any adjustments throughout the process in whatever way works best for you. About you: • Solid understanding of typical threats, risks and remediations around software and architecture including OWASP Top 10 • Familiarity with security frameworks such as MITRE Attack Framework, NIST, ISO 27001 • Experience writing applications using an object-oriented language (e.g. C#, Java, Python) and/or scripting languages (e.g. Powershell) • Experienced in agile software delivery, Software Development Lifecycle and Secure SDLC • Experience with/understanding of DevOps/DevSecOps, Security best practices and driving cultural change. • Experience with implementing and using Application Security Tooling • Experience with securing cloud environments • Knowledge of Docker/Kuberenetes