Purpose of the role
To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks.
Accountabilities
Vice President Expectations
All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.
Join us as a Lead Application Security Analyst for Barclays, where you will play a critical role in safeguarding the bank’s technology landscape. You will lead evaluation, delivery and continuous enhancement of Application Security and DevSecOps capabilities, bringing specialist experience in one or more of the following areas: SAST, SCA, DAST, API security and AI-assisted security testing. You will translate multi-layered security-testing data into actionable risk insights, embed proportionate controls across the software development lifecycle, and partner with engineering, risk and governance stakeholders to improve control effectiveness, standards compliance and secure innovation.
To be successful in this role, you should have experience with:
Operating and evaluating results from one or more SAST, SCA or DAST tools, including tuning policies, validating findings, reducing false positives, assessing exploitability and guiding remediation
Assessing APIs using automated and manual techniques, with knowledge of authentication, authorization, input validation and common API vulnerabilities
Applying secure coding and remediation practices in at least one development ecosystem, such as Java/Spring, .NET, Go, Python or JavaScript/TypeScript
Integrating application security testing into CI/CD pipelines, developer workflows and cloud-native environments, including containers, Kubernetes and infrastructure as code
Using data-analysis techniques and reporting tools to identify trends, prioritize risk, monitor remediation, and produce clear KRI/KCI dashboards and leadership insights
Technical analysis, defining testing strategies and providing authoritative challenge to engineering teams on highly detailed application security risks
Some other highly valued skills may include:
Knowledge of cyber governance, security policies, control frameworks and standards, with the ability to interpret requirements, assess conformance, manage exceptions and support audit or regulatory evidence
Understanding of software supply chain security, dependency risk, secrets scanning, SBOMs and vulnerability management across the secure SDLC
Exposure to AI-assisted security testing and AI application security, including prompt injection, insecure output handling, model and agent risks, data leakage, human-in-the-loop validation and responsible use of AI-generated findings
Ability to communicate multi-layered technical findings to senior stakeholders, influence remediation priorities and coach analysts and engineering teams
You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, as well as job-specific technical skills.
This role is located in Whippany, NJ.
Minimum Salary: $175,000
Maximum Salary: $225,000
The minimum and maximum salary/rate information above include only base salary or base hourly rate. It does not include any other type of compensation or benefits that may be available.
Barclays employees are eligible for a suite of competitive and generous employee benefits, including medical, dental and vision coverage, 401(k), life insurance, and other paid leave for qualifying circumstances.
This position is eligible for an incentive award.