This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Join us as a Penetration Tester in Barclays, responsible for supporting the successful delivery of Location Strategy projects to plan, budget, agreed quality and governance standards. You'll spearhead the evolution of our digital landscape, driving innovation and excellence. You will harness cutting-edge technology to revolutionise our digital offerings, ensuring unparalleled customer experiences. Purpose of the role: To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks.
Job Responsibility:
Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders
Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies
Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance
Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance
Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing methodologies and assurance activities
Requirements:
Hands-on delivery experience in penetration testing or related fields
Proficient in Penetration testing in at least 3 of following technical domains: Web based Applications, Network/Infrastructure, APIs, Mobile Apps, Thick clients, MCPs/AI Agents/LLMs, Cloud environments
Understanding of the security mechanisms associated with Applications, Operating Systems, Networks, Databases, Virtualisation, Cloud technologies, AI
Familiarity with cloud-native environments, container security, and infrastructure-as-code
Excellent communication and collaboration skills
Nice to have:
CREST/OSCP/SANS or equivalent pentesting certifications
Red/Purple team experience. Strong understanding of attack paths and adversary emulation