About the role
Application Security Analyst Whippany, United States Apply for job Key information Date live: 08/05/2026 Business Area: Chief Information Security Office Area of Expertise: Technology Contract: Permanent Reference Code: JR-0000096029 Salary / Rate $ 125,000.00 - $ 170,000.00 Key info Job overview Success profile Benefits Our technology Location Working flexibly About Barclays Application process Apply for job It’s happening at Barclays. Be a part of a place where challenges are measured in billions, qubits and nanoseconds. Build your career in an environment where we’re advancing machine learning, leveraging blockchains, and harnessing FinTech. Working in Barclays technology, you’ll reimagine possibilities: learning and innovating to solve the challenges ahead, delivering for millions of customers. We are shaping the future of financial technology. Why not join us and make it happen here? Where will you be located? Explore location Join us as an Application Security Analyst for Barclays, where you will support the delivery and continuous enhancement of Application Security and DevSecOps capabilities, bringing practical experience in one or more of the following areas: SAST, SCA, DAST, API security and AI-assisted security testing. You will evaluate security findings, validate risk, support remediation, and convert testing data into practical insights for engineering and security stakeholders. You will also help embed security controls across the software development lifecycle and support compliance with cyber governance requirements, policies, and standards. To be successful as an Application Security Analyst, you should have experience with: • Running one or more of SAST, SCA or DAST scans; triaging and validating findings; investigating false positives; assessing severity and exploitability; and working with developers to track remediation • Testing APIs and understanding common weaknesses in authentication, authorization, input validation, data exposure, and business logic • Applying secure coding knowledge in at least one development ecosystem, such as Java/Spring, .NET, Go, Python or JavaScript/TypeScript, and supporting security testing within CI/CD and cloud-native workflows • Evaluating security data using spreadsheets, query or reporting tools to identify trends, prioritize risk, monitor remediation, and produce accurate operational metrics and dashboards Some other highly valued skills may include: • Knowledge of cyber governance, security policies, controls and standards, including supporting conformance assessments, evidence collection, exception management and risk reporting • Understanding of secure SDLC practices, software supply chain security, dependency risk, secrets scanning, SBOMs, vulnerability management and developer-focused remediation • Exposure to AI-assisted security testing and AI application security risks, including prompt injection, insecure output handling, sensitive-data leakage, model or agent vulnerabilities, and validation of AI-generated findings You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, as well as job-specific technical skills. This role is located in Whippany, NJ. Minimum Salary: $ 125,000 Maximum Salary: $ 170,000 The minimum and maximum salary/rate information above include only base salary or base hourly rate. It does not include any other type of compensation or benefits that may be available. Barclays employees are eligible for a suite of competitive and generous employee benefits, including medical, dental and vision coverage, 401(k), life insurance, and other paid leave for qualifying circumstances. This position is eligible for an incentive award. Purpose of the role To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks. Accountabilities Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders. Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies. Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance. Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance. Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing methodologies and assurance activities. Assistant Vice President Expectations To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions/ business divisions. Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L – Listen and be authentic, E – Energise and inspire, A – Align across the enterprise, D – Develop others. OR for an individual contributor, they will lead collaborative assignments and guide team members...
Key responsibilities
- check_circleCollaborate with the team on day-to-day project tasks
- check_circleLearn tools and processes used by the organization
- check_circleDocument work and participate in team meetings
- check_circleSupport quality checks and continuous improvement
Requirements
- check_circleRelevant education or self-taught skills for the role
- check_circleStrong willingness to learn and take feedback
- check_circleGood communication in English (written and verbal)
- check_circleAbility to commit to the internship/role duration
Skills & keywords
Benefits & perks
- check_circleMentorship
- check_circleCertificate of completion
- check_circleFlexible work arrangement where applicable
