UK remote
Threat & Exposure Management Analyst
About this role
The Threat & Exposure Management analyst helps ASOS understand and reduce the technology exposures most likely to contribute to material cyber risk. Rather than treating vulnerabilities in isolation, the role considers vulnerabilities, misconfigurations, identity and privilege weaknesses, cloud security risks, exposed assets and attack paths in the context of threat intelligence, exploitability and business criticality.
You’ll turn technical security data into clear, risk-based priorities, helping engineering and technology teams focus remediation effort where it delivers the greatest reduction in exposure and cyber risk. This is an analytical and collaborative role. You’ll work across ASOS’s technology estate to understand what is exposed, how it could realistically be exploited, what an attacker could reach, what matters most to ASOS, and what we should do about it.
Role details Identify and assess technology exposures across ASOS, including vulnerabilities, misconfigurations, identity and privilege weaknesses, exposed assets and services, cloud security risks and attack paths. Perform risk-based analysis and prioritisation, considering exploitability, threat intelligence, attacker behaviour, asset criticality, business context, accessibility and compensating controls to determine which exposures matter most.
Analyse attack paths to understand how vulnerabilities, configurations, identities, privileges and trust relationships could combine to enable compromise of critical ASOS systems, services or data. Apply threat intelligence and exploitation data to understand which threats and exposures are most relevant to ASOS and where action should be prioritised. Assess exposure across modern technology environments, including cloud platforms, applications, APIs, virtual machines, containers, endpoints, identities, networks and supporting infrastructure.
Support continuous attack-surface discovery, helping identify unknown, unmanaged, incorrectly classified or unexpectedly exposed assets and services. Partner with engineering, product, platform and infrastructure teams to agree proportionate remediation or mitigation strategies, focusing effort on actions that deliver the greatest reduction in cyber risk. Track significant exposures through to resolution, escalating material or persistent risk where appropriate and helping teams identify effective remediation or compensating controls.