This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Join us as an Application Security Specialist for Barclays, where you will play a critical role in safeguarding the bank’s technology landscape. You will lead the hands-on delivery and continuous enhancement of the firm’s DevSecOps and Application Security initiatives. Also, embed security controls across the software development lifecycle, integrating guidance directly into developer workflows. This position requires close partnership with engineering and security stakeholders to scale modern, developer-centric security capabilities that enable secure innovation.
Job Responsibility:
Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders
Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies
Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance
Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance
Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing methodologies and assurance activities
Requirements:
Strong development experience in at least one ecosystem (e.g. Java (Spring), .NET, GoLang)
Expertise in cloud-native development security, container orchestration (e.g. Kubernetes), and infrastructure-as-code tools such as Terraform and Helm
Advanced knowledge of API and mobile security, including common vulnerabilities and mitigation techniques
Nice to have:
Deep understanding of modern secure SDLC processes, DevOps toolchains, CI/CD automation, and code-signing practices
Knowledge of SAST, DAST, SCA, and software supply chain security
Understanding of AI security within application security, including model vulnerabilities, malware risks, and prompt injection techniques