The Details
ASOS is recruiting for an Offensive Security Specialist within the SOC. This role will report to the SOC and IR Manager. It is key to leading offensive security assessments that strengthen defense capabilities for ASOS. Working closely with cyber teams, you'll identify security weaknesses, validate detection mechanisms, and provide actionable recommendations to enhance our security posture. You'll contribute to the SOC team's continuous validation and improvement of security controls and detection capabilities.
The role will involve the following
- Threat Hunting - Proactively searching for signs of malicious activity within the network, identifying threats that might go undetected by automated systems.
- Penetration Testing - Simulating real-world attacks to test the effectiveness of security controls and identify weaknesses.
- Red Teaming - Engaging in adversarial simulations to assess the organisation's overall security posture and identify areas for improvement.
- Collaboration with Defensive Teams - Working closely with defensive security teams to share insights, improve detection capabilities, and enhance incident response processes.
- Developing Offensive Security Strategies - Designing and implementing strategies to proactively identify and mitigate security risks.
- Endpoint monitoring, contributing to incidents through to resolution and root cause analysis.
- Malware Analysis and investigation.
- Contributing to processes and SOPs.
- Developing and mentoring junior team members to improve their skills and capabilities, along with wider knowledge transfer to other security and non-security teams to help build a culture of cybersecurity in departments.
- Maintaining awareness of real-world cybersecurity threats and engaging in the innovation of new analytic methods for proactively detecting threats.
- Available for on-call rota for escalated security incidents.
On-Call Requirements
- The role includes on-call duties on a 4-week rota basis. You will be required to be available for on-call shifts, ensuring prompt response to emergencies and urgent situations.
- Flexibility and reliability are essential for this aspect of the role.
At ASOS, the online retailer for fashion lovers worldwide, we exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. We encourage everyone to be their true selves without judgment and to channel their creativity into a platform used by millions.
We are proud members of Inclusive Companies, are Disability Confident Committed, and have signed the Business in the Community Race at Work Charter. We placed 8th in the Inclusive Top 50 Companies Employer list.
Let our Talent team know if you need any adjustments throughout the process in whatever way works best for you.
About You
- Practical experience in ethical hacking, penetration testing, and red team methodologies.
- Familiar with industry-recognized frameworks for threat simulation and defense.
- Able to communicate technical findings and remediation strategies clearly to both technical and non-technical audiences.
- Skilled in producing accurate and well-structured reports and presentations.
- Strong problem-solving and analytical skills, with a proactive and collaborative mindset.
- Effective interpersonal skills, with the ability to build relationships and influence stakeholders.
- Experience contributing to threat detection efforts, including identifying malicious activity and fine-tuning detection logic.
- Comfortable working with modern security tools and enterprise environments.
- Committed to continuous learning and passionate about mentoring and developing others.
Benefits
- Employee discount (hello ASOS discount!)
- ASOS Develops (personal development opportunities across the business)
- Employee sample sales
- Access to a huge range of LinkedIn Learning materials
- 25 days paid annual leave plus an extra celebration day for special moments
- Discretionary bonus scheme
- Private medical care scheme