Barclays
Application Security Specialist

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Description
Purpose of the Role
To identify potential vulnerabilities within the bank's IT systems using penetration testing tools and techniques to ensure the security of computer systems, applications, servers, and networks.
Accountabilities
- Development and execution of assessments, audits, and threat models to identify vulnerabilities within the bank's systems, applications, and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders.
- Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools, and technologies and to support the development of penetration testing methodologies.
- Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings and remediation guidance.
- Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance.
- Identification of emerging vulnerabilities, exploit codes, and cyber-attacks to develop testing methodologies and assurance activities.
Vice President Expectations
-
Contribute or set strategy, drive requirements, and make recommendations for change.
-
Plan resources, budgets, and policies; manage and maintain policies/processes; deliver continuous improvements, and escalate breaches of policies/procedures.
-
If managing a team, define jobs and responsibilities, planning for the department's future needs and operations, counselling employees on performance, and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long-term goals and ensuring that budgets and schedules meet corporate requirements.
-
If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are:
- L – Listen and be authentic
- E – Energise and inspire
- A – Align across the enterprise
- D – Develop others
-
If an individual contributor, they will be a subject matter expert within their own discipline and will guide technical direction. They will lead collaborative, multi-year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide, and coach less experienced specialists and provide information affecting long-term profits, organisational risks, and strategic decisions.
-
Advise key stakeholders, including functional leadership teams and senior management on functional and cross-functional areas of impact and alignment.
-
Manage and mitigate risks through assessment, in support of the control and governance agenda.
-
Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work their team does.
-
Demonstrate a comprehensive understanding of the organisation's functions to contribute to achieving the goals of the business.
-
Collaborate with other areas of work, for business-aligned support areas to keep up to speed with business activity and the business strategies.
-
Create solutions based on sophisticated analytical thought comparing and selecting complex alternatives. In-depth analysis with interpretative thinking will be required to define problems and develop innovative solutions.
-
Adopt and include the outcomes of extensive research in problem-solving processes.
-
Seek out, build, and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes.
-
All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence, and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge, and Drive – the operating manual for how we behave.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Join us as a Application Security Specialist for Barclays
Where you will play a critical role in safeguarding the bank's technology landscape. You will lead hands-on analysis, delivery, and continuous enhancement of Application Security and DevSecOps capabilities, bringing specialist experience in one or more of the following areas: SAST, SCA, DAST, API security, and AI-assisted security testing. You will translate complex security-testing data into actionable risk insights, embed proportionate controls across the software development lifecycle, and partner with engineering, risk, and governance stakeholders to improve control effectiveness, standards compliance, and secure innovation.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Requirements
To be successful as an Application Security Specialist, you should have experience in one or more of the following application security testing areas:
- Operating and analysing results from one or more SAST, SCA, or DAST tools, including tuning policies, validating findings, reducing false positives, assessing exploitability, and guiding remediation
- Assessing APIs using automated and manual techniques, with strong knowledge of authentication, authorisation, input validation, and common API vulnerabilities
- Applying secure coding and remediation practices in at least one development ecosystem, such as Java/Spring,.NET, Go, Python, or JavaScript/TypeScript
- Integrating application security testing into CI/CD pipelines, developer workflows, and cloud-native environments, including containers, Kubernetes, and infrastructure as code
- Using data-analysis techniques and reporting tools to identify trends, prioritise risk, monitor remediation, and produce clear KRI/KCI dashboards and leadership insights
- Leading technical analysis, defining testing strategies, and providing authoritative challenge to engineering teams on complex application security risks
Some Other Highly Valued Skills
- Strong knowledge of cyber governance, security policies, control frameworks, and standards, with the ability to interpret requirements, assess conformance, manage exceptions, and support audit or regulatory evidence
- Understanding of software supply chain security, dependency risk, secrets scanning, SBOMs, and vulnerability management across the secure SDLC
- Hands-on exposure to AI-assisted security testing and AI application security, including prompt injection, insecure output handling, model and agent risks, data leakage, human-in-the-loop validation, and responsible use of AI-generated findings
- Ability to communicate complex technical findings to senior stakeholders, influence remediation priorities, and coach analysts and engineering teams
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills