Purpose of the role
To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks.
Accountabilities
Assistant Vice President Expectations
All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.
Join us as an Application Security Analyst for Barclays, where you will support the delivery and continuous enhancement of Application Security and DevSecOps capabilities, bringing practical experience in one or more of the following areas: SAST, SCA, DAST, API security and AI-assisted security testing. You will evaluate security findings, validate risk, support remediation, and convert testing data into practical insights for engineering and security stakeholders. You will also help embed security controls across the software development lifecycle and support compliance with cyber governance requirements, policies, and standards.
To be successful as an Application Security Analyst, you should have experience with:
• Running one or more of SAST, SCA or DAST scans; triaging and validating findings; investigating false positives; assessing severity and exploitability; and working with developers to track remediation
• Testing APIs and understanding common weaknesses in authentication, authorization, input validation, data exposure, and business logic
• Applying secure coding knowledge in at least one development ecosystem, such as Java/Spring, .NET, Go, Python or JavaScript/TypeScript, and supporting security testing within CI/CD and cloud-native workflows
• Evaluating security data using spreadsheets, query or reporting tools to identify trends, prioritize risk, monitor remediation, and produce accurate operational metrics and dashboards
Some other highly valued skills may include:
• Knowledge of cyber governance, security policies, controls and standards, including supporting conformance assessments, evidence collection, exception management and risk reporting
• Understanding of secure SDLC practices, software supply chain security, dependency risk, secrets scanning, SBOMs, vulnerability management and developer-focused remediation
• Exposure to AI-assisted security testing and AI application security risks, including prompt injection, insecure output handling, sensitive-data leakage, model or agent vulnerabilities, and validation of AI-generated findings
You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, as well as job-specific technical skills.
This role is located in Whippany, NJ.
Minimum Salary: $ 125,000
Maximum Salary: $ 170,000
The minimum and maximum salary/rate information above include only base salary or base hourly rate. It does not include any other type of compensation or benefits that may be available.
Barclays employees are eligible for a suite of competitive and generous employee benefits, including medical, dental and vision coverage, 401(k), life insurance, and other paid leave for qualifying circumstances.
This position is eligible for an incentive award.