Jobs · Information Technology · New Jersey

Application Security Specialist

Barclays · Whippany, NJ · 3 wk ago
Information Technology$175k/yrFull-time

About the Role

Join us as a Lead Application Security Analyst for Barclays, where you will play a critical role in safeguarding the bank’s technology landscape. You will lead evaluation, delivery, and continuous enhancement of Application Security and DevSecOps capabilities, bringing specialist experience in one or more of the following areas: SAST, SCA, DAST, API security, and AI-assisted security testing. You will translate multi-layered security-testing data into actionable risk insights, embed proportionate controls across the software development lifecycle, and partner with engineering, risk, and governance stakeholders to improve control effectiveness, standards compliance, and secure innovation.

Responsibilities

  • Development and execution of assessments, audits, and threat models to identify vulnerabilities within the bank’s systems, applications, and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders.
  • Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools, and technologies and to support the development of penetration testing methodologies.
  • Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings and remediation guidance.
  • Collaboration with stakeholders to understand their security requirements and controls in business processes, applications/services, to enhance overall security posture and assurance.
  • Identification of emerging vulnerabilities, exploit codes, and cyber-attacks to develop testing methodologies and assurance activities.
  • Operating and evaluating results from one or more SAST, SCA, or DAST tools, including tuning policies, validating findings, reducing false positives, assessing exploitability, and guiding remediation.
  • Assessing APIs using automated and manual techniques, with knowledge of authentication, authorization, input validation, and common API vulnerabilities.
  • Applying secure coding and remediation practices in at least one development ecosystem, such as Java/Spring, .NET, Go, Python, or JavaScript/TypeScript.
  • Integrating application security testing into CI/CD pipelines, developer workflows, and cloud-native environments, including containers, Kubernetes, and infrastructure as code.
  • Using data-analysis techniques and reporting tools to identify trends, prioritize risk, monitor remediation, and produce clear KRI/KCI dashboards and leadership insights.
  • Technical analysis, defining testing strategies, and providing authoritative challenge to engineering teams on highly detailed application security risks.
  • Demonstrating leadership and accountability for managing risk and strengthening controls in relation to the work your team does.
  • Collaborating with other areas of work to keep up to speed with business activity and strategies.
  • Creating solutions based on sophisticated analytical thought, comparing and selecting complex alternatives.
  • Building and maintaining trusting relationships and partnerships with internal and external stakeholders to accomplish key business objectives.

Requirements

  • Experience with operating and evaluating results from one or more SAST, SCA, or DAST tools, including tuning policies, validating findings, reducing false positives, assessing exploitability, and guiding remediation.
  • Experience assessing APIs using automated and manual techniques, with knowledge of authentication, authorization, input validation, and common API vulnerabilities.
  • Experience applying secure coding and remediation practices in at least one development ecosystem, such as Java/Spring, .NET, Go, Python, or JavaScript/TypeScript.
  • Experience integrating application security testing into CI/CD pipelines, developer workflows, and cloud-native environments, including containers, Kubernetes, and infrastructure as code.
  • Ability to use data-analysis techniques and reporting tools to identify trends, prioritize risk, monitor remediation, and produce clear KRI/KCI dashboards and leadership insights.
  • Technical analysis skills, defining testing strategies, and providing authoritative challenge to engineering teams on highly detailed application security risks.

Qualifications & Skills

Some other highly valued skills may include:

  • Knowledge of cyber governance, security policies, control frameworks, and standards, with the ability to interpret requirements, assess conformance, manage exceptions, and support audit or regulatory evidence.
  • Understanding of software supply chain security, dependency risk, secrets scanning, SBOMs, and vulnerability management across the secure SDLC.
  • Exposure to AI-assisted security testing and AI application security, including prompt injection, insecure output handling, model and agent risks, data leakage, human-in-the-loop validation, and responsible use of AI-generated findings.
  • Ability to communicate multi-layered technical findings to senior stakeholders, influence remediation priorities, and coach analysts and engineering teams.
  • Demonstrated leadership behaviors: Listen and be authentic, Energize and inspire, Align across the enterprise, Develop others.
  • Barclays Values: Respect, Integrity, Service, Excellence, and Stewardship.
  • Barclays Mindset: Empower, Challenge, and Drive.

Vice President Expectations

  • Contribute or set strategy, drive requirements, and make recommendations for change.
  • Plan resources, budgets, and policies; manage and maintain policies/processes; deliver continuous improvements and escalate breaches of policies/procedures.
  • If managing a team, define jobs and responsibilities, plan for the department’s future needs and operations, counsel employees on performance, and contribute to employee pay decisions/changes.
  • Lead a number of specialists to influence the operations of a department, aligning with strategic and tactical priorities while balancing short and long-term goals and ensuring budgets and schedules meet corporate requirements.
  • For individual contributors, act as a subject matter expert within your discipline, guide technical direction, lead collaborative multi-year assignments, and train, guide, and coach less experienced specialists.
  • Advise key stakeholders, including functional leadership teams and senior management, on functional and cross-functional areas of impact and alignment.
  • Manage and mitigate risks through assessment in support of the control and governance agenda.
  • Demonstrate comprehensive understanding of organizational functions to contribute to achieving business goals.
  • Create solutions based on sophisticated analytical thought, comparing and selecting complex alternatives.
  • Adopt and include outcomes of extensive research in problem-solving processes.
  • Seek out, build, and maintain trusting relationships and partnerships with internal and external stakeholders to accomplish key business objectives using influencing and negotiating skills.

Pay

Minimum Salary: $175,000
Maximum Salary: $225,000

The minimum and maximum salary/rate information above includes only base salary or base hourly rate. This position is eligible for an incentive award.

Benefits

Barclays employees are eligible for a suite of competitive and generous employee benefits, including:

  • Medical, dental, and vision coverage
  • 401(k)
  • Life insurance
  • Other paid leave for qualifying circumstances

Location

This role is located in Whippany, NJ.

Similar jobs