Barclays

ApplicationSecuritySpecialist

$0–0k Whippany, New Jersey, United States FULL TIME
The Brief

“Application Security Specialist at Barclays. Skills: Application Security, penetration testing, DevSecOps, secure SDLC, cloud-native development security, API security, mobile security. Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques. Support the delivery and continuous enhancement of the firm’s DevSecOps and Application Security programs”

What You'll Achieve.

ensure security of computer systems, applications, servers, and networks; enhance overall security posture and assurance; deliver on work that impacts the whole business function; create an environment for colleagues to thrive and deliver to a consistently excellent standard; meet required outcomes; support the resolution of escalated issues; strengthening controls in relation to the work done; achievement of the objectives of the organisation sub-function; keep up to speed with business activity and the business strategy; achieve outcomes

Industry & Context.

Problems you'll solve

Engage in complex analysis of data from multiple sources of information, internal and external sources such as procedures and practises (in other areas, teams, companies, etc). to solve problems creatively and effectively

What They're Looking For.

Must Have

Development experience in at least one ecosystem such as Java Spring, .NET, or GoLang, Cloud-native development security, container orchestration such as Kubernetes, infrastructure-as-code tools such as Terraform and Helm, Advanced knowledge of API and mobile security, including common vulnerabilities and mitigation techniques

Nice to Have

Deep understanding of modern secure SDLC processes, DevOps toolchains, CI/CD automation, and code-signing practices, Knowledge of SAST, DAST, SCA, and software supply chain security, Understanding of AI security within application security, including model vulnerabilities, malware risks, and prompt injection techniques

What You'll Do.

Development and execution of assessments

and threat models to identify vulnerabilities within the banks systems

applications and servers using penetration tools and techniques

Support the delivery and continuous enhancement of the firm’s DevSecOps and Application Security programs

Embed security controls across the software development lifecycle

integrating guidance directly into developer workflows

Identification of emerging vulnerabilities

exploit codes and cyber-attacks to develop testing methodologies and assurance activities

How You'll Work.

Team & Collaboration

Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies; Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance; Close partnership with engineering and security stakeholders to scale modern, developer-centric security capabilities that enable secure innovation; Collaborate closely with other functions/ business divisions; Lead a team performing complex tasks; Lead collaborative assignments and guide team members through structured assignments; Consult on complex providing advice to People Leaders to support the resolution of escalated issues; Perform work that is closely related to that of other areas, which requires understanding of how areas coordinate and contribute to the achievement of the objectives of the organisation sub-function; Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategy

Communication Scope

Communicate key findings and recommendations to stakeholders; Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance; Communicate complex information

Process & Methodology

Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes, Identify new directions for assignments and/ or projects, identifying a combination of cross functional methodologies or practices to meet required outcomes

Free ATS check

Applying for this Application Security Specialist role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Workday

  • Workday has a multi-step form — save your progress after every section.
  • "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
  • Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
  • Job requisition numbers are useful when following up with HR by email.

ANONYMOUS · UNFILTERED

What do employees actually say about Barclays?

Real rants from real employees. Read before you apply.

Read Company Rants →