Jobs

Senior Application Security Engineer


Job details
  • ASOS
  • London
  • 2 weeks ago

Job Description

As one of our Security Engineers, you will join a multidisciplinary team, working together with other Security Engineers, Product Managers and Security teams. You will design, build and deliver secure, high-quality enterprise solutions across numerous initiatives within the organisation, spreading your security knowledge to an ever-expanding engineering community, increasing our security posture and helping identify and reduce our risk exposure when building applications.

Your primary focus is to safeguard software applications from potential threats and breaches. You work as a bridge between security and engineering, ensuring that applications are designed, developed, and deployed in a secure manner. Your impact will be felt within Cyber Security and wider by our tech communities, engineers and operations teams.

Responsibilities

  • Drive security efforts across ASOS Engineering (SecDevOps, Secure SDLC)
  • Drive security risk decisions and influence technical architecture.
  • Drive Application Security Assessments (incl. Threat Modelling, Attack Surface Analysis, Application Security Architecture Reviews and Security Code Reviews)
  • Play a role in proactively identifying potential security risks, developing mitigation strategies, and ensuring that security measures are incorporated right from the beginning of the application development process.
  • Produce and Deliver Security Training around Security Best Practices.
  • Develop security tooling with business objectives, industry best practices, and regulatory requirements.
  • Understand and support teams with adherence to regulations (e.g. GDPR, PCI-DSI)
  • Helping teams implement Cryptography correctly, in line with ASOS and industry standards.
  • Ability to articulate mitigation and development techniques around emerging threats to technical and non-technical stakeholders
  • Collaborate with the incident response team in investigating and responding to security incidents.
  • Support with risk assessments and vulnerability assessments to identify potential security gaps or weaknesses in existing technologies


Qualifications

About you: 

  • Solid understanding of typical threats, risks and remediations around software and architecture including OWASP Top 10
  • Familiarity with security frameworks such as MITRE Attack Framework, NIST, ISO 27001
  • Experience writing applications using an object-oriented language (e.g. C#, Java, Python) and/or scripting languages (e.g. Powershell)
  • Experienced in agile software delivery, Software Development Lifecycle and Secure SDLC
  • Experience with/understanding of DevOps/DevSecOps, Security best practices and driving cultural change.
  • Experience with implementing and using Application Security Tooling
  • Experience with securing cloud environments
  • Knowledge of Docker/Kuberenetes



Additional Information

BeneFITS’ 

  • Employee discount (hello ASOS discount!) 
  • ASOS Develops (personal development opportunities across the business) 
  • Employee sample sales  
  • Access to a huge range of LinkedIn learning materials 
  • 25 days paid annual leave + an extra celebration day for a special moment 
  • Discretionary bonus scheme  
  • Private medical care scheme 
  • Flexible benefits allowance - which you can choose to take as extra cash, or use towards other benefits 

Why take our word for it? Search #InsideASOS on our socials to see what life at ASOS is like. 

Want to find out how we’re tech powered? Check out the ASOS Tech Podcast herehttps://open.spotify.com/show/6rT4V6N9C7pAXcX60kzzxo. Prefer reading? Check out our ASOS Tech Blog herehttps://medium.com/asos-techblog

Sign up for our newsletter

The latest news, articles, and resources, sent to your inbox weekly.

Similar Jobs

Senior Application Security Engineer

Senior Application Security EngineerHybrid From Any UK Hub (London, Swindon, Manchester, Glasgow, Belfast)Salary – Up to £100,000 Depending on experience + Discretionary Bonus + Additional Corporate Benefits PackageThe Client: A leading financial services firm requires a senior application security engineer!The Role:As a Senior Application Security Engineer here, you'll sit within...

Lorien London

Senior Application Security Engineer @ ASOS

ASOS Discover the latest fashion trends with ASOS. Shop the new collection of clothing, footwear, accessories, beauty products and more. Order today from ASOS. We’re ASOS, the online retailer for fashion lovers all around the world.Is your CV ready If so, and you are confident this is the role for...

Cyber Crime London

Senior Application Security Engineer (31118)

Join Our Team at Holland & Barrett!Do you have the skills to fill this role Read the complete details below, and make your application today.Are you passionate about application security and eager to make a meaningful impact? Holland & Barrett is seeking anApplication Security Specialistto help us enhance our security...

Holland and Barrett London

Senior Application Security Engineer

Job DescriptionAs one of our Security Engineers, you will join a multidisciplinary team, working together with other Security Engineers, Product Managers and Security teams. You will design, build and deliver secure, high-quality enterprise solutions across numerous initiatives within the organisation, spreading your security knowledge to an ever-expanding engineering community, increasing...

ASOS London

APAC AppSec Manager, Stores Application Security

Amazon is continuously innovating new services and features for our customers. Our engineers invent, build, and sometimes break things to make them easier, faster, better, and more cost-effective. However, no matter what we’re building – from websites to web services, AR to AI, drones to devices – security is always...

Amazon London

Engineer Pentesting

Who are we?Vertiv, a $ global organization with nearly 24,000 employees, designs, builds and services critical infrastructure that enables vital applications for data centers, communication networks, and commercial and industrial facilities.  We support today’s growing mobile and cloud computing markets with a portfolio of power, thermal and infrastructure management solutions.The...

Vertiv Bedford