Application Security Specialist
Listed on 2026-09-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Join us as a Lead Application Security Analyst for Barclays, where you will play a critical role in safeguarding the bank’s technology landscape. You will lead evaluation, delivery and continuous enhancement of Application Security and Dev Sec Ops capabilities, bringing specialist experience in one or more of the following areas: SAST, SCA, DAST, API security and AI-assisted security testing. You will translate multi-layered security-testing data into actionable risk insights, embed proportionate controls across the software development lifecycle, and partner with engineering, risk and governance stakeholders to improve control effectiveness, standards compliance and secure innovation.
To be successful in this role, you should have experience with:
- Operating and evaluating results from one or more SAST, SCA or DAST tools, including tuning policies, validating findings, reducing false positives, assessing exploitability and guiding remediation
- Assessing APIs using automated and manual techniques, with knowledge of authentication, authorization, input validation and common API vulnerabilities
- Applying secure coding and remediation practices in at least one development ecosystem, such as Java/Spring, .NET, Go, Python or JavaScript/Type Script
- Integrating application security testing into CI/CD pipelines, developer workflows and cloud-native environments, including containers, Kubernetes and infrastructure as code
- Using data-analysis techniques and reporting tools to identify trends, prioritize risk, monitor remediation, and produce clear KRI/KCI dashboards and leadership insights
- Technical analysis, defining testing strategies and providing authoritative challenge to engineering teams on highly detailed application security risks
- Knowledge of cyber governance, security policies, control frameworks and standards, with the ability to interpret requirements, assess conformance, manage exceptions and support audit or regulatory evidence
- Understanding of software supply chain security, dependency risk, secrets scanning, SBOMs and vulnerability management across the secure SDLC
- Exposure to AI-assisted security testing and AI application security, including prompt injection, insecure output handling, model and agent risks, data leakage, human-in-the-loop validation and responsible use of AI-generated findings
- Ability to communicate multi-layered technical findings to senior stakeholders, influence remediation priorities and coach analysts and engineering teams
You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, as well as job-specific technical skills.
This role is located in Whippany, NJ.
Minimum Salary: $175,000
Maximum Salary: $225,000
The minimum and maximum salary/rate information above include only base salary or base hourly rate. It does not include any other type of compensation or benefits that may be available.
Barclays employees are eligible for a suite of competitive and generous employee benefits, including medical, dental and vision coverage, 401(k), life insurance, and other paid leave for qualifying circumstances.
This position is eligible for an incentive award.
Purpose of the roleTo identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks.
Accountabilities- Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders.
- Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies.
- Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance.
- Collaboration with stakeholders to understand their security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).