BUK CISO - Security Analyst

Barclays


Date: 1 week ago
City: Knutsford
Contract type: Full time
Join us as a Security Analyst at Barclays where you'll spearhead the evolution of our digital landscape, driving innovation and excellence. You'll harness cutting-edge technology to revolutionise our digital offerings, ensuring unapparelled customer experiences.

BUK CISO are looking for a motivated, technically minded individual to join our Cyber Assurance Team to supporting across all core Cyber domains. This includes the following scope


  • Penetration Testing – supporting adherence to all penetration testing requirements through delivery of lifecycle assurance penetration testing.
  • Application Security – supporting with the roll out of a new Application Security strategy and partnering BUK application Teams with existing and new requirements.
  • Infrastructure Vulnerability Management – reporting and driving the remediation of all identified Infrastructure Vulnerabilities across the BUK Services/Applications within SLA
  • Thematic assessment – assessment of any thematic issues across BUK applications resulting from findings out of the testing and ensure that application development teams are fully engaged on how to address these in an enduring manner
  • Education and Awareness – supports the education and awareness of the development community across BUK to build high level of understanding on how to ensure Barclays applications are secure by design.
  • Respond to and support with ad-hoc Cyber related work streams as and when they materialise and impact upon the BUK business.


As AVP of BUK Cyber Assurance you will be expected to:


  • Demonstrate accountability for the delivery of security testing services within BUK
  • Ensure testing services are delivered to BUK in a joined-up and cohesive fashion.
  • Drive and lead security remediation requirements across a number of stakeholder and federated IT Application Teams to ensure the organisations assets and IT systems are appropriately protected against unauthorised activities.
  • Grow and develop talent within the team, providing not just managerial leadership, but inspiring the technical and non-technical staff who are key to the success of this service offering.
  • Ensure close collaboration within the teams and with other areas of Security Assurance and Barclays.
  • Manage key relationships with stakeholders, including negotiation of scope and intensity of testing of development and production systems.
  • Design, develop and deliver relevant MI reports related to team utilisation, high risk vulnerabilities & common issues,
  • Analysis of any holistic issues found in a cross section of engagements and use this information to develop highly bespoke, relevant action plans to remediate the core issues.


Key Accountabilities


  • Secure Development Lifecycle Services
  • Vulnerability Management
  • Application Security
  • Thematic Assessment
  • Reporting & MI
  • Education and Secure Coding
  • Team Mentoring and Development
  • Vendor management
  • Stakeholder Management and Leadership
  • Risk and Control Objectives


To be successful as a Security Analyst, you should have experience with:


  • Understands and can articulate the business context/significance of technical test findings to non-technical business owners
  • Ability to lead team members to ensure there is the successful remediation of cyber vulnerabilities and findings across core infrastructure and/or applications
  • Has strong knowledge of information security frameworks and standards such as ISO17799/27001 and their application into diverse environments


Other Highly Valued Skills Include


  • Sound understanding of Cyber Security Policy and Standards and can convey requirements to others
  • Has excellent time management and organizational skills
  • Understanding and awareness of security strategies and technologies; secure network design, Secure Software Development Lifecycles
  • Understands core development methodologies and their associated technologies
  • Has detailed knowledge of the purpose of - and approaches to - security testing.
  • Is able to balance business impact, cost and risk against technical criticality
  • Understands major internal support functions and services


You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job-specific technical skills

This role will be based out of our Knutsford campus.

Purpose of the role

To provide a primary liaison service between the business, technology, and security functions. In order to ensure the confidentiality, integrity and availability of information, and support the mitigation of security risk.

Accountabilities


  • Collaboration with stakeholders to understand their security requirements in business processes and IT projects, to enhance overall risk management.
  • Execution of risk assessments to identify and prioritise potential cybersecurity threats that could impact the banks operations and data and guide the implementation of mitigation strategies and communicate findings to relevant findings to relevant senior stakeholders.
  • Collaboration with business units to develop and implement security policies and procedures for the banks operations aligned to the risk management framework.
  • Management of the implementation, testing and monitoring of security controls across the banks IT systems to ensure the effectiveness of controls and mitigation of risk.
  • Execution of training content and sessions to educate employees, enhance cybersecurity awareness and provide guidance on safe online practices.
  • Management of complex cybersecurity incidents by collaborating with IT teams and response experts to effectively resolve cases through analysis, expertise support and project supervision.
  • Identification of emerging cybersecurity trends, threats, and new technologies to address potential risks by advocating the adoption of new security solutions.


Assistant Vice President Expectations


  • To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions/ business divisions.
  • Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes
  • If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L – Listen and be authentic, E – Energise and inspire, A – Align across the enterprise, D – Develop others.
  • OR for an individual contributor, they will lead collaborative assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will identify new directions for assignments and/ or projects, identifying a combination of cross functional methodologies or practices to meet required outcomes.
  • Consult on complex issues; providing advice to People Leaders to support the resolution of escalated issues.
  • Identify ways to mitigate risk and developing new policies/procedures in support of the control and governance agenda.
  • Take ownership for managing risk and strengthening controls in relation to the work done.
  • Perform work that is closely related to that of other areas, which requires understanding of how areas coordinate and contribute to the achievement of the objectives of the organisation sub-function.
  • Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategy.
  • Engage in complex analysis of data from multiple sources of information, internal and external sources such as procedures and practises (in other areas, teams, companies, etc).to solve problems creatively and effectively.
  • Communicate complex information. 'Complex' information could include sensitive information or information that is difficult to communicate because of its content or its audience.
  • Influence or convince stakeholders to achieve outcomes.


All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Test Lead

hackajob, Knutsford
4 days ago
hackajob is collaborating with Barclays to connect them with exceptional tech professionals for this role.Join us as a Test Lead at Barclays, where you'll be part of the project team responsible for developing thestrategic solution providing enhanced features and better integration with Case Management Tool., you’ll also benefit from being part of a vast professional network, collaborating with industry expertsTo...

Technical Delivery Manager

Barclays, Knutsford
1 week ago
Join us at Barclays as a Technical Delivery Manager. In this role you will manage the efficient delivery of large-scale technical projects and capabilities across the bank and collaborate with internal and external stakeholders to understand their needs and expectations throughout the software product lifecycle, adhering to agreed time, budget and quality requirements.To be successful in the role of a...

Senior PostgreSQL SRE

Barclays, Knutsford
3 weeks ago
Join us as a Senior PostgreSQL SRE at Barclays where you'll effectively monitor and maintain the bank’s critical technology infrastructure and resolve more complex technical issues, whilst minimizing disruption to operations. In this role you will assume a key technical leadership role. You will shape the direction of our database administration, ensuring our technological approaches are innovative and aligned with...