Threat & Exposure Management Analyst

ASOS·London·United Kingdom·Networking & Systems Engineering

ASOS is hiring a Threat & Exposure Management Analyst in London. Posted 2026-09-18; applications close 2026-11-17 (in 59 days).

Role details

Role Overview

The Threat & Exposure Management Analyst helps ASOS understand and reduce the technology exposures most likely to contribute to material cyber risk.

Rather than treating vulnerabilities in isolation, this role considers vulnerabilities, misconfigurations, identity and privilege weaknesses, cloud security risks, exposed assets, and attack paths within the context of threat intelligence, exploitability, and business criticality.

You will turn technical security data into clear, risk-based priorities, guiding engineering and technology teams to focus remediation efforts where they deliver the greatest reduction in exposure and cyber risk. This is an analytical and collaborative role, requiring you to work across ASOS’s technology estate to understand what is exposed, how it could realistically be exploited, what an attacker could reach, what matters most to ASOS, and what actions should be taken.

Key Responsibilities

  • Identify and assess technology exposures across ASOS, including vulnerabilities, misconfigurations, identity and privilege weaknesses, exposed assets and services, cloud security risks, and attack paths.
  • Perform risk-based analysis and prioritization, considering exploitability, threat intelligence, attacker behavior, asset criticality, business context, accessibility, and compensating controls to determine which exposures matter most.
  • Analyze attack paths to understand how vulnerabilities, configurations, identities, privileges, and trust relationships could combine to enable compromise of critical ASOS systems, services, or data.
  • Apply threat intelligence and exploitation data to determine which threats and exposures are most relevant to ASOS and where action should be prioritized.
  • Assess exposure across modern technology environments, including cloud platforms, applications, APIs, virtual machines, containers, endpoints, identities, networks, and supporting infrastructure.
  • Support continuous attack-surface discovery by helping identify unknown, unmanaged, incorrectly classified, or unexpectedly exposed assets and services.
  • Partner with engineering, product, platform, and infrastructure teams to agree upon proportionate remediation or mitigation strategies, focusing efforts on actions that deliver the greatest reduction in cyber risk.
  • Track significant exposures through to resolution, escalating material or persistent risk where appropriate and assisting teams in identifying effective remediation or compensating controls.
  • Identify recurring exposure patterns and systemic control weaknesses, working with technology teams to address root causes and eliminate classes of exposure rather than repeatedly treating individual findings.
  • Assess the effectiveness of preventative and compensating controls in reducing identified exposures and attack paths, recommending improvements where required.
  • Validate significant exposures and remediation outcomes, using appropriate technical evidence to confirm that identified risk has been materially reduced.
  • Translate technical findings into clear risk insights, communicating exposure, potential business impact, and remediation priorities to both technical and non-technical stakeholders.
  • Contribute to meaningful exposure metrics and reporting that demonstrates changes in organizational risk and remediation effectiveness, moving beyond reliance solely on vulnerability volumes or severity scores.
  • Contribute to the continuous improvement of ASOS’s Threat & Exposure Management capability, including automation, data enrichment, prioritization models, metrics, reporting, workflow integration, processes, and governance.
  • Promote secure-by-design and proportionate, risk-based security practices across ASOS technology teams.

Qualifications and Experience

About You

  • Relevant experience as a Vulnerability Analyst, SOC Analyst, or in a similar security role.
  • Understanding of common vulnerability types and attack techniques.
  • Experience with vulnerability management, cloud security, or security assessment tooling (e.g., Wiz, Defender, Nessus, Qualys, or similar).
  • Understanding of enterprise technologies, including cloud platforms, infrastructure, networking, and software development practices.
  • Ability to leverage threat intelligence to assess vulnerability risk and inform remediation priorities.
  • Knowledge of container and Kubernetes security is desirable.
  • Understanding of cyber security risk management principles and risk-based decision-making.
  • Excellent written and verbal communication skills for presenting technical information clearly to non-technical audiences.
  • Naturally inquisitive, with the ability to investigate security risks across diverse technologies and identify potential threats to the organization.
  • Self-motivated with strong problem-solving and critical thinking skills.

Additional Desired Skills

While prior experience in Threat & Exposure Management is not required, we seek candidates who can combine technical security knowledge with curiosity, analytical thinking, and an understanding of risk. Ideally, you will possess:

  • Relevant experience in exposure management, vulnerability management, cloud security, security engineering, threat intelligence, SOC/security operations, or another role involving the analysis of technology and cyber risk.
  • A strong understanding of common vulnerabilities, security misconfigurations, and attacker techniques across modern technology environments.
  • Experience using vulnerability, exposure, cloud security, or security assessment tooling such as Wiz, Microsoft Defender, Nessus, Qualys, or equivalent platforms.
  • An understanding of cloud platforms and cloud-native technologies, including virtual machines, containers, and modern application architectures.
  • An understanding of identity and privilege as part of the attack surface, and how identity weaknesses can contribute to attack paths.
  • A deep understanding of attack paths and attacker behavior, including how multiple weaknesses can be combined to reach critical assets or services.
  • A working knowledge of cyber security risk management and the ability to make risk-based, rather than severity-based, decisions.
  • Strong analytical and critical-thinking skills, paired with a naturally inquisitive approach to investigating security issues across diverse technologies.
  • Strong written and verbal communication skills, enabling you to explain complex technical issues clearly and translate them into actionable priorities for various audiences.
  • A collaborative approach and the ability to work effectively with engineering and technology teams to achieve practical security outcomes.

What Success Looks Like

Success in this role is measured not by the number of vulnerabilities found or tickets created, but by how effectively we understand and reduce the exposures that matter most to ASOS. You will help transition our approach from vulnerability management based primarily on individual findings and severity scores toward a more continuous, threat-informed, and risk-based method for understanding and reducing our attack surface.

Benefits

  • Employee discount (hello ASOS discount!)
  • Employee sample sales
  • 25 days paid annual leave plus an extra celebration day for a special moment
  • Discretionary bonus scheme
  • Private medical care scheme
  • Flexible benefits allowance (usable as extra cash or towards other benefits)
  • Opportunity for personalized learning and in-the-moment experiences that enable you to thrive and excel.

More open roles at ASOS

Other open Networking & Systems Engineering roles

Applying to this role

This Threat & Exposure Management Analyst role at ASOS runs through the firm's own careers portal and expects a CV and cover letter written specifically for the posting, not a portable submission carried across firms. Jorb AI's application agent tailors a CV and cover letter from your background to this posting and tracks the role alongside the rest of your applications.

Jorb AI tracks details for Threat & Exposure Management Analyst at ASOS. Postings refresh hourly from primary careers pages. Job details mirror the firm's posting; the apply link goes directly to the source. Last refreshed 2026-09-19.

ASOS careers

Save this role and tailor your cover letter with Jorb AI.