Purpose of the role
To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks.
Accountabilities
Assistant Vice President Expectations
All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.
Embark on a transformative journey as a Penetration Tester - AVP. At Barclays, our vision is clear –to redefine the future of banking and help craft innovative solutions. Penetration Testing team provide a core cyber assurance service. Services are provided via a global internal team and preferred suppliers. We provide Security Assurance capabilities which are aligned to the ‘lifecycle’ of a service or application. In this role, you will play a critical role in the delivery of security assurance across annual lifecycle testing and change/project engagements. This will be across a range of different technologies (e.g. web application, API, infrastructure, virtualization/containers, mobile, cloud, AI). In addition to BAU pen testing, there will be close collaboration with teams such as vulnerability management, application security, and CTEM to ensure proactive security.
To be successful as a Penetration Tester - AVP, you should have:
Practical experience for delivery experience in penetration testing or related fields
Proficiency in Penetration testing in following technical domains, Web based Applications, Network/Infrastructure, APIs, Mobile Apps, Thick clients, MCPs/AI Agents/LLMs, Cloud environments
Understanding of the security mechanisms associated with Applications, Operating Systems, Networks, Databases, Virtualization, Cloud technologies, AI
Familiarity with cloud-native environments, container security, and infrastructure-as-code
Excellent communication and collaboration skills
Other highly valued skills include:
CREST/OSCP/SANS or equivalent pen testing certifications
Red/Purple team experience. Considerable understanding of attack paths and adversary emulation
Enterprise vulnerability management experience (vulnerability research, scanning, operational process)
Wider SDL activities such as threat/attack modelling and design review
Familiarity and experience with key industry frameworks such as OWASP, MITRE ATT&CK/CTID, CISA Secure-by-Design, NIST CSF 2.0/CRI Profile, DORA/FFIEC
You may be assessed on the key critical skills relevant for success in this role, such as risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, as well as job-specific technical skills.
This role is located in our Whippany, NJ office.
Minimum Salary: $125,000
Maximum Salary: $170,000
The minimum and maximum salary/rate information above includes only base salary or base hourly rate. It does not include any other type of compensation or benefits that may be available.
Barclays employees are eligible for a suite of competitive and generous employee benefits, including medical, dental and vision coverage, 401(k), life insurance, and other paid leave for qualifying circumstances.
This position is eligible for an incentive award.