This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Embark on a transformative journey as a Cyber Operations Analyst at Barclays. At Barclays, our vision is clear—to redefine the future of banking through innovative solutions. In this role, you will join the Cyber Operations team, where your primary mission is to deliver 24/7 continuous monitoring, analysis, incident response, threat hunting, and intelligence services. Cybercrime and cyberattacks continue to increase in both volume and sophistication, targeting private organizations as well as critical national infrastructure. Effectively addressing these evolving threats requires a holistic approach that integrates all cybersecurity disciplines. Successful cyber incidents can lead to significant operational disruption, regulatory scrutiny, and reputational damage. As a global financial institution that manages high-value transactions and sensitive client data, Barclays remains a prime target for cybercriminals. Furthermore, as our digital presence continues to expand across online and mobile platforms, the risk posed by increasingly advanced cyber threats continues to grow.
Management of security monitoring systems, including intrusive prevention and detection systems, to alert, detect and block potential cyber security incidents, and provide a prompt response to restore normal operations with minimised system damage
Identification of emerging cyber security threats, attack techniques and technologies to detect/prevent incidents
Management and analysis of security information and event management systems to collect, correlate and analyse security logs, events and alerts/potential threats
Triage of data loss prevention alerts to identify and prevent sensitive data for being exfiltrated from the banks network
Management of cyber security incidents including remediation & driving to closure
Requirements
Basic familiarity with SIEM platforms and the ability to monitor, triage, and document security alerts in a structured SOC environment
Ability to perform initial analysis of security alerts and events, following established runbooks and escalating incidents according to defined procedures
Foundational understanding of common security incidents such as phishing emails, endpoint alerts, and basic network anomalies
Ability to recognize common malware indicators and suspicious activity using alerts from endpoints, proxies, IDS, and network security tools
Understanding of core cybersecurity concepts, including attack lifecycles, basic threat types, and the importance of defense-in-depth
Basic knowledge of operating system fundamentals (Windows & Linux) and introductory networking concepts such as TCP/IP, DNS, and HTTP
Familiarity with common attacker techniques and indicators of compromise from a defensive (blue-team) perspective
Awareness of cloud computing concepts and basic security considerations in platforms such as AWS, Azure, or Google Cloud