Job Description

Day to Day Responsibilities: 

  • Accountable for leading the Security Architecture domain, performing an architecture and consultancy role, as well as providing thought leadership, liaising with the architect community and other senior IT and Business partners to guide them in security related architectural and strategic matters.
  • You will be leading a team of Security Architects, owning the security strategies for ASOS.
  • Develop security architecture and technology solutions to address the current and emerging security and compliance requirements of the organisation. You will help ensure enterprise information is secured by determining security requirements; planning, implementing, and testing security systems; preparing security standards, policies, and procedures; mentoring team members. 
  • Review the existing security architecture, identifying design gaps, and recommending security enhancements. You will ensure alignment between security architecture frameworks and standards with overall business strategy.
  • You’ll be assisting the preparation and presentation of business cases for strategic initiatives to senior management for funding approval. Where this is cross domain, it will require collaboration with peers and be led by the Chief Architect.
  • There will be day-to-day management functions for direct reports such as performance management, workload management as well as developing career and capability of the existing Security Architects in your team.
  • This is a highly collaborative/facilitator role. You will be required to operate at several different levels: from working with various architect roles at differing seniority, to working very closely with the CISO and Security Team and contributing to the Information Architecture governance activities. You will also work closely with the Secure Development engineering team.
  • Qualifications

    Getting to know you: 

  • We are looking for an existing senior Security Architect, working in a cloud environment.
  • Your experience includes Security Architecture strategy and design and working effectively within application security, including secure application development (security in SDLC phases) and architecture.
  • You will have demonstrable experience of Operational Technology Security (e.g. IEC 62443, NIST 800-82) and regulatory compliance and information security management frameworks (e.g., IS027000, COBIT, NIST 800, etc.)
  • Experience in the following during your career: Network Security, Network Hardware Configuration, Network Protocols, Networking Standards, Supervision, Conceptual Skills, Decision Making, Informing Others, Functional and Technical Skills, Dependability, Information Security Policies.
  • You will have experience in Attack Surface Analysis, Threat Modelling, Static Analysis, Dynamic Analysis & Architecture and Design reviews.
  • You will have good knowledge of secure coding standards (CERT/OWASP/SANS/WASC/MITRE) and understand the most appropriate cryptographic techniques and how they should be used by commercial organisations. 
  • You will have familiarity or experience of architectural frameworks such as TOGAF, Zachman and previous experience in retail would be beneficial to assist you rapidly add value in your exciting journey at ASOS.
  • You will have experience of mentoring, coaching and line managing others to become the best they can be.
  • Ideally, you will hold industry recognised security certifications such as CISSP, CISM, ISSAP, SANS, etc.
  • Additional Information

    What’s in it for you?

  • Competitive salary, pension, and private medical care scheme
  • Performance related bonus
  • Flex benefits allowance – which you can chose to take as extra cash, or use towards other benefits
  • 25 days paid annual leave + an extra day for your birthday
  • Employee discount (hello ASOS discount!)
  • Tech Develops – our internal tech focussed skills development programme to focus on your personal growth as a technologist
  • Opportunity to represent ASOS at industry leading events
  • Opportunity to help shape and drive our DE&I initiatives in Tech (like our WIT movement and Diversity mentoring in Tech)
  • Opportunity to make an impact from day one and work with the latest in cutting edge of technology