Application Security Specialist
Join us as a Application Security Specialist for Barclays, where you will play a critical role in safeguarding the bank’s technology landscape. You will lead hands‑on analysis, delivery and continuous enhancement of Application Security and Dev Sec Ops capabilities, bringing specialist experience in one or more of the following areas: SAST, SCA, DAST, API security and AI‑assisted security testing. You will translate complex security‑testing data into actionable risk insights, embed proportionate controls across the software development lifecycle, and partner with engineering, risk and governance stakeholders to improve control effectiveness, standards compliance and secure innovation.
ToBe Successful As a Application Security Specialist, You Should Have Experience In One Or More Of The Following Application Security Testing Areas
- Operating and analysing results from one or more SAST, SCA or DAST tools, including tuning policies, validating findings, reducing false positives, assessing exploitability and guiding remediation
- Assessing APIs using automated and manual techniques, with strong knowledge of authentication, authorisation, input validation and common API vulnerabilities
- Applying secure coding and remediation practices in at least one development ecosystem, such as Java/Spring, .NET, Go, Python or JavaScript/Type Script
- Integrating application security testing into CI/CD pipelines, developer workflows and cloud-native environments, including containers, Kubernetes and infrastructure as code
- Using data-analysis techniques and reporting tools to identify trends, prioritise risk, monitor remediation, and produce clear KRI/KCI dashboards and leadership insights
- Leading technical analysis, defining testing strategies and providing authoritative challenge to engineering teams on complex application security risks
- Strong knowledge of cyber governance, security policies, control frameworks and standards, with the ability to interpret requirements, assess conformance, manage exceptions and support audit or regulatory evidence
- Understanding of software supply chain security, dependency risk, secrets scanning, SBOMs and vulnerability management across the secure SDLC
- Hands‑on exposure to AI‑assisted security testing and AI application security, including prompt injection, insecure output handling, model and agent risks, data leakage, human‑in‑the‑loop validation and responsible use of AI‑generated findings
- Ability to communicate complex technical findings to senior stakeholders, influence remediation priorities and coach analysts and engineering teams
This role will be based in Knutsford.
You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job‑specific technical skills.
Purpose of the roleTo identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks.
Accountabilities- Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders.
- Collaboration with stakeholders and IT teams to identify emerging cyber‑attack techniques, tools and technologies and to support the development of penetration testing methodologies.
- Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance.
- Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance.
- Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing methodologies and assurance activities.
- To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: