Enable job alerts via email!

Senior Security GRC Specialist

ASOS.com

London

On-site

GBP 60,000 - 90,000

Full time

2 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

ASOS is seeking a Senior Security GRC Specialist to enhance their Governance, Risk, and Compliance team. This role involves managing compliance projects, conducting risk assessments, and developing security policies. The ideal candidate will have relevant experience and certifications, contributing to a dynamic security landscape.

Benefits

Employee discount
Personal development opportunities
Sample sales access
LinkedIn Learning resources
25 days annual leave plus a celebration day
Discretionary bonus scheme
Private medical care
Flexible benefits allowance

Qualifications

  • Relevant work experience in security and compliance.
  • Experience with ISO 27001, PCI DSS, NIST CSF.
  • Knowledge of GDPR and DPA.

Responsibilities

  • Manage compliance projects and coordinate audit activities.
  • Maintain security risk registers and conduct risk assessments.
  • Support security assessments of third-party suppliers.

Skills

Analytical
Problem-solving
Communication

Education

Degree in relevant field
CISSP
CISM
CISA
CRISC

Job description

Get AI-powered advice on this job and more exclusive features.

Company Description

We're ASOS. We blend our flair for fashion with our love of cutting-edge technology, but more importantly, we're interested in how we can bring the best out of you.

We exist to give people the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgment, and channel your creativity into a platform used by millions.

Through our Fashion with Integrity strategy, we are driving diversity, equity, and inclusion across every aspect of ASOS and ensuring every ASOSer can be their authentic self at work. We want our people to be whoever they want to be because we believe people who bring their best selves to work do their best work.

Job Description

An exciting opportunity has arisen for a Senior Security GRC Specialist to join the ASOS Governance, Risk, and Compliance (GRC) team in Cyber Security.

Reporting to the Security Governance, Risk, and Compliance Manager, this role will assist in the development, enhancement, and execution of ASOS’s information security risk and compliance functions. This includes activities such as maintaining compliance with PCI DSS, updating security policies and standards, and managing third-party supplier risk. The role will also provide subject matter expertise and support on security risk management. We’re passionate about protecting our colleagues and the ASOS brand, so we seek someone who can thrive and develop in a dynamic security landscape.

You will need to operate at various levels: from being a team player within the GRC team to collaborating with the wider Security team and supporting other business areas with their risk and compliance needs.

Key Responsibilities

  • Management and maintenance of compliance projects, including coordinating audit activities
  • Assist in maintaining security risk registers and conducting risk assessments/workshops
  • Manage and support security assessments of third-party suppliers using the risk management platform
  • Track and manage corrective actions for audit findings and control deficiencies
  • Support other Security teams and business areas with risk and compliance requirements
  • Authors and maintains security policies and standards

What Success Looks Like

  • Supporting the smooth operation of GRC activities as a key team member
  • Building effective relationships across business areas
  • Mentoring and guiding junior team members

Qualifications

  • Relevant work experience, degree, or industry certifications (e.g., CISSP, CISM, CISA, CRISC)
  • Experience with standards and frameworks like ISO 27001, PCI DSS, NIST CSF
  • Knowledge of data privacy laws such as GDPR and DPA
  • Broad understanding of network technologies, especially cloud and technical security
  • Excellent organizational skills for managing multiple projects
  • Analytical, detail-oriented, with strong problem-solving skills
  • Effective communication and influencing skills at all organizational levels

Additional Information

Benefits

  • Employee discount
  • Personal development opportunities
  • Sample sales access
  • LinkedIn Learning resources
  • 25 days annual leave plus a celebration day
  • Discretionary bonus scheme
  • Private medical care
  • Flexible benefits allowance
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Security GRC Specialist

TN United Kingdom

London

On-site

GBP 60,000 - 90,000

Today
Be an early applicant

Senior Security GRC Specialist

ASOS

London

On-site

GBP 60,000 - 90,000

Today
Be an early applicant

Senior SAP Security & GRC Specialist - HYBRID

TN United Kingdom

London

Hybrid

GBP 60,000 - 100,000

25 days ago