Application Security Analyst
Barclays · Whippany, NJ · 3 wk ago
Information Technology$125k/yrFull-time
About the role
Join us as an Application Security Analyst for Barclays, where you will support the delivery and continuous enhancement of Application Security and DevSecOps capabilities. You will evaluate security findings, validate risk, support remediation, and convert testing data into practical insights for engineering and security stakeholders. You will also help embed security controls across the software development lifecycle and support compliance with cyber governance requirements, policies, and standards.
Responsibilities
- Identify potential vulnerabilities within the bank’s IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks.
- Develop and execute assessments, audits, and threat models to identify vulnerabilities within the bank’s systems, applications, and servers, then communicate key findings and recommendations to stakeholders.
- Collaborate with stakeholders and IT teams to identify emerging cyber-attack techniques, tools, and technologies, and support the development of penetration testing methodologies.
- Develop and maintain comprehensive documents and reports for senior stakeholders on penetration test findings and remediation guidance.
- Collaborate with stakeholders to understand their security requirements and controls in business processes, applications, and services to enhance overall security posture and assurance.
- Identify emerging vulnerabilities, exploit codes, and cyber-attacks to develop testing methodologies and assurance activities.
- Run one or more of SAST, SCA, or DAST scans; triage and validate findings; investigate false positives; assess severity and exploitability; and work with developers to track remediation.
- Test APIs and understand common weaknesses in authentication, authorization, input validation, data exposure, and business logic.
- Apply secure coding knowledge in at least one development ecosystem (e.g., Java/Spring, .NET, Go, Python, or JavaScript/TypeScript) and support security testing within CI/CD and cloud-native workflows.
- Evaluate security data using spreadsheets, query tools, or reporting tools to identify trends, prioritize risk, monitor remediation, and produce accurate operational metrics and dashboards.
Requirements
- Experience running one or more of SAST, SCA, or DAST scans; triaging and validating findings; investigating false positives; assessing severity and exploitability; and working with developers to track remediation.
- Experience testing APIs and understanding common weaknesses in authentication, authorization, input validation, data exposure, and business logic.
- Secure coding knowledge in at least one development ecosystem, such as Java/Spring, .NET, Go, Python, or JavaScript/TypeScript, and experience supporting security testing within CI/CD and cloud-native workflows.
- Ability to evaluate security data using spreadsheets, query tools, or reporting tools to identify trends, prioritize risk, monitor remediation, and produce accurate operational metrics and dashboards.
Valued Skills
- Knowledge of cyber governance, security policies, controls, and standards, including supporting conformance assessments, evidence collection, exception management, and risk reporting.
- Understanding of secure SDLC practices, software supply chain security, dependency risk, secrets scanning, SBOMs, vulnerability management, and developer-focused remediation.
- Exposure to AI-assisted security testing and AI application security risks, including prompt injection, insecure output handling, sensitive-data leakage, model or agent vulnerabilities, and validation of AI-generated findings.
Expectations
- Advise and influence decision-making, contribute to policy development, and take responsibility for operational effectiveness.
- Collaborate closely with other functions and business divisions.
- Lead a team performing complex tasks, using well-developed professional knowledge and skills to deliver work that impacts the whole business function.
- Set objectives, coach employees, appraise performance, and determine reward outcomes (if in a leadership role).
- For individual contributors: Lead collaborative assignments, guide team members, and identify new directions for projects by incorporating cross-functional methodologies.
- Consult on complex issues and provide advice to People Leaders to support the resolution of escalated issues.
- Identify ways to mitigate risk and develop new policies/procedures in support of the control and governance agenda.
- Take ownership for managing risk and strengthening controls in relation to the work done.
- Perform work closely related to other areas, requiring an understanding of how they coordinate and contribute to organizational objectives.
- Collaborate with other areas of the business to stay aligned with business activity and strategy.
- Engage in complex analysis of data from multiple internal and external sources to solve problems creatively and effectively.
- Communicate complex or sensitive information effectively to diverse audiences.
- Influence or convince stakeholders to achieve desired outcomes.
- Demonstrate Barclays Values: Respect, Integrity, Service, Excellence, and Stewardship.
- Demonstrate the Barclays Mindset: Empower, Challenge, and Drive.
Pay
Base salary range: $125,000 – $170,000. This role is eligible for an incentive award.
Benefits
- Medical, dental, and vision coverage
- 401(k) retirement plan
- Life insurance
- Paid leave for qualifying circumstances
Location
Whippany, NJ