This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Join us at Barclays as a Lead Security Consultant. At Barclays, we are committed to building secure, resilient, and innovative technology solutions that protect our customers, colleagues, and business operations. We are looking for a talented and forward-thinking Security Consultant to join our growing cybersecurity team and play a key role in shaping secure enterprise platforms and services across the organisation. As a Security Consultant, you will work closely with engineering, architecture, and business teams to embed security into the design and delivery of strategic initiatives, ensuring that security is integrated from concept through to implementation.
Job Responsibility:
Execution of security risk assessments and building threat models during the change & development lifecycle in order to identify vulnerabilities within the banks IT systems, applications and infrastructure, ensuring that compensating security controls and countermeasures are embedded in order to enhance security posture and resilience against cyber threats provision of timely communication of key findings and recommendations to stakeholders
Enablement of DevSecOps (and shift left), by providing engagement channels for customers and stakeholders who wish to engage early seeking security advice and input into their business plans and opportunities, or technology change designs, influencing key stakeholders in COO and CSO to create security strategies to enable business and technology evolution
Support and guidance to CISO, CIO and Product Team functions providing security reviews for prospective 3rd party technology products and services
Transfer of residual risks to the business/customer as required by the bank’s enterprise risk management framework
Collaboration with stakeholder and IT teams to support incident response and investigations using their knowledge of the banks technology systems sharing security insights
Participation in the development and maintenance of security policies, standards and procedures aligned to the banks risk tolerance, regulatory requirements and industry best practice
Requirements:
Secure by Design – Strong understanding of embedding security principles into solution architecture and system development lifecycles, ensuring security controls are proactively integrated rather than retrofitted
Threat Modelling – Experience identifying potential threats, attack vectors, and security weaknesses across applications, infrastructure, and data platforms, with the ability to recommend effective mitigations
Security Assessment Scoping – Ability to define and scope security assessments, penetration testing engagements, and risk reviews to ensure appropriate coverage and alignment with business and regulatory requirements
Nice to have:
Big Data Platform Experience – Exposure to modern data and analytics platforms such as Databricks, Snowflake, or similar technologies, with an understanding of associated security considerations and controls
Software Defined Data Centres (SDDC) – Knowledge of virtualised infrastructure, software-defined networking, storage, and compute technologies within enterprise environments
Generative AI (Gen AI) – Awareness of emerging Gen AI technologies, associated security risks, governance considerations, and secure adoption practices within large organisations