
Security GRC Specialist (12 Month FTC)
- London
- Permanent
- Full-time
- Risk Management: Assist in maintaining the CISO's cyber security risk registers and conduct risk assessments or workshops as needed.
- Policy and Standards Maintenance: Author and maintain ASOS's security policies and standards.
- Third-Party Supplier Risk Management: Conduct security due-diligence assessments for new suppliers and manage third-party supplier risk using ASOS's risk management platform.
- Support the implementation and maintenance of PCI DSS.
- Manage and track corrective action plans for security findings, standards exceptions, and control deficiencies.
- Provide subject matter expert knowledge and support on security risk management.
- Support other Cyber Security teams and ASOS business areas with their risk and compliance requirements.
- Candidates should demonstrate competency in cyber security through relevant work experience, a degree, or industry-relevant certifications such as CISSP, CISM, CISA, or CRISC.
- Professional certifications in industry standards and frameworks like ISO 27001 Lead Implementer/Auditor or PCI DSS (ISA, PCIP) are beneficial. Experience with standards such as NIST CSF is also valued.
- A strong understanding of information security principles.
- Knowledge of applicable data privacy practices and laws, including GDPR and DPA.
- Broad knowledge of network technologies, especially cloud and technical security.
- Analytical, problem-solving, and detail-oriented with the ability to manage conflicting priorities.
- Strong communication and presentation skills.
- Ability to build effective relationships across all ASOS business areas.
- Loves to collaborate, share, and learn by doing.
- Excellent organisational skills to manage multiple projects across the business.
- Competitive salary, pension, and private medical care scheme
- Performance related bonus
- Flex benefits allowance - which you can chose to take as extra cash, or use towards other benefits
- 25 days paid annual leave + an extra day for your birthday
- Employee discount (hello ASOS discount!)
- Tech Develops - our internal tech focussed skills development programme to focus on your personal growth as a technologist
- Opportunity to represent ASOS at industry leading events
- Opportunity to help shape and drive our DE&I initiatives in Tech (like our WIT movement and Diversity mentoring in Tech)
- Opportunity to make an impact from day one and work with the latest in cutting edge of technology