Information Security, Governance, Risk and
2 weeks ago
Company Description
We're ASOS. We blend our flair for fashion with our love of cutting
- edge technology, but more importantly were interested in how we can bring the best out of you.
We exist to give people the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgment, and channel your creativity into a platform used by millions.
**Job Description**:
**The Person**:
An analytical problem solver with a strong technical foundation who enjoys working as part of a team in a rapidly evolving environment.
As the Information Security, Governance, Risk and Compliance Lead, you will be responsible for the management of the (security) Governance, Risk and Compliance Team (GRC), reporting directly to ASOS’s Chief Information Security Officer (CISO). Working alongside the other Cyber Security Leads, you will be responsible for driving and maturing ASOS’s security governance, risk and compliance function. We’re quite passionate about protecting our colleagues and the ASOS brand, so we would love someone who can thrive and develop on an ever growing and changing security landscape.
**Responsibilities**:
- Manage the day-to-day activities of the GRC Team and work as a key contact for GRC-related issues
- Define, document, and maintain, ASOS’s security policies and collaborate in the definition of technical security standards
- Maintain the CISO’s cyber security risk registers and conduct cyber security risk assessments/risk workshops as required
- Implement and maintain compliance with relevant security certifications, e.g., the Payment Card Industry Data Security Standard (PCI DSS) and ISO27001
- Ensure continued compliance with industry security standards, by implementing a schedule of compliance assessment activities
- Management and tracking of corrective action plans for security findings, standards exceptions and control deficiencies
- Conducting security due-diligence assessments of new ASOS suppliers and maintain ASOS’s third-party security risk management platform
- Input into the finalisation of third-party contractual documentation e.g., ensuring adequate security clauses have been included
- Aid the CISO in other cyber security initiatives and production of any required security risk and compliance reporting
**Qualifications**:
- Experience in industry standards and frameworks, such as ISO 27001, PCI DSS and NIST CSF. Experience as a PCI DSS QSA and ISO 27001 Lead Implementer/Auditor beneficial
- Broad technical security knowledge and understanding of applicable data privacy practices and legislation (e.g., DPA, GDPR) is required
- Analytical, problem solving and detail-oriented, with a proven ability to multi-task conflicting priorities
- Loves to collaborate, share and learn by doing
- Building effective relationships across ASOS business areas
- Strong communication and presentation skills
Additional Information
We want our people to be whoever they want to be. That’s why we’re committed to creating a truly inclusive culture at ASOS, but how we're doing it?
Through our Fashion with Integrity strategy we are driving diversity, equity and inclusion across every aspect of ASOS and ensuring every ASOSer can be their authentic self at work. We want our people to be whoever they want to be, because we believe people who bring their best selves to work, do their best work.
We’re proud members of Inclusive Companies, are Disability Confident Committed and have signed the Business in the Community Race at Work Charter. We’ve also recently been placed 8th in the Inclusive Top 50 Companies Employer List too.
There are safe space employee networks and we host a monthly DEI events series to help support and celebrate all of our people. We are constantly listening to our people, evolving, changing and taking a flexible approach to how we make ASOS truly inclusive.
-
Information Governance Trainee
1 week ago
London, United Kingdom Information Governance Services Full time**Immediate Start**: - **About Us** - **About the Role** **Key duties and responsibilities**: - Support the Lead Consultant and/or Consultants to complete client work; - Work well under instructions and within agreed timelines; - Conduct research and interpret legislation, regulations and/or guidance and provide a digest to fee earners; - Study, attend...
-
Information Governance Trainee
4 days ago
London, United Kingdom Information Governance Services Full time**Immediate Start** **A little about us**: We are a consultancy firm that cares deeply about each and every client, this attitude has enabled us to call some of the world’s leading institutions as our current and past clients. Currently our consultants all have legal backgrounds (barristers, solicitors, legal executives or law graduates, but this is not...
-
Information Security, Governance, Risk and
2 weeks ago
London, United Kingdom ASOS Full timeCompany Description We're ASOS. We blend our flair for fashion with our love of cutting - edge technology, but more importantly were interested in how we can bring the best out of you. We exist to give people the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgment, and...
-
Group Head of IT
2 weeks ago
Greater London, United Kingdom BUPA Full timeGroup Head of IT & Information Security Risk and Governance Flexible on location - attending meetings in London a couple of times a month. Hybrid & flexible working options. Permanent. Salary - £95,000 - £110,000 per annum + benefits package. Full Time - 35 hours. Closing date for applications - Monday 8th December 2025. We make health happen! At Bupa, our...
-
Information Security Analyst
1 week ago
London, United Kingdom Latcom Plc Full timeJob Role - In conjunction with the Information Security Manager, develop and implement information security policies, standards and documentation ensuring compliance with all applicable legal or regulatory legislation; - Work as an Information Security Auditor to define, maintain and implement an audit framework and schedule in compliance with the firms'...
-
Information Security Manager
1 week ago
City Of London, United Kingdom MCA New Business Development Full timeInformation Security Manager - Governance, Risk & Compliance Join to apply for the Information Security Manager - Governance, Risk & Compliance role at MCA New Business Development Location: Remote with some travel to client sites Salary: £60k + excellent benefits Are you passionate about information security and the positive impact it can make on...
-
London, United Kingdom UBS Full timeUnited Kingdom - Information Technology (IT) - Group Functions **Job Reference #** - 272091BR **City** - London **Job Type** - Full Time **Your role** - Do you have a strong technical background and experience working within the web and cloud security team? If so, we’re looking for a risk assessor to join the CIS Governance & Policy team, led by the...
-
Head of Information Security
6 days ago
London, United Kingdom Birkbeck University of London Full timeAre you ready to take on a pivotal role in safeguarding the future of information security? Join Birkbeck, University of London, as our Head of Information Security & Governance this Autumn 2024. As part of our Information Services department, you will lead a team dedicated to ensuring the confidentiality, integrity, and availability of our institutional...
-
Information Security Governance Analyst
2 weeks ago
London, United Kingdom Pension Corporation Full timeRole PurposeWe are looking for an experienced Information Security Governance Analyst to work within our Information Security team. The team are committed to supporting the effective operation of information security risk management. This includes the implementation and management of an Information Security Management System (ISMS), a framework of policies,...
-
Global IT
2 weeks ago
Greater London, United Kingdom BUPA Full timeA leading health insurer in the UK is seeking a Group Head of IT & Information Security Risk and Governance to develop and lead the global IT security risk management program. The successful candidate will oversee risk assessment methodologies, ensure compliance with industry standards, and enhance the organization’s resilience against evolving threats....