Senior Vulnerability Management Analyst- CIO- BPL

Barclays · Canary Wharf, 1 Churchill Place · United Kingdom

Vulnerability Management Analyst- CIO- BPL Risk & Compliance

Vista previa de la oferta

Vulnerability Management Analyst- CIO- BPL

Risk & Compliance

Job Description

Purpose of the role

To enable ‘secure by design’, supporting the bank’s change programmes, design and implement a secure systems and architecture across a broad set of security domains. These include data security, security risk management, asset security, security architecture and engineering (incl. cloud security), communications and networks, security operations, software development, security assurance testing, identity and access management (IAM). 

Accountabilities

Vice President Expectations

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.

Join us a Vulnerability Management Analyst with BPL CIO- own the end-to-end vulnerability lifecycle across the entire estate: from scanning orchestration through triage, prioritisation, SLA assignment, remediation tracking, exception management, and reporting. You are the single point of accountability for knowing, at any moment, what vulnerabilities exist in the organisation’s systems, how severe they are in the context of the business, who is responsible for fixing them, and whether they are being fixed within agreed timescales.

 

This role is critical because vulnerability management sits at the intersection of several key processes in the CISO operating model. The pre-release security sign-off process checks a service’s open vulnerability backlog before approving a production release — if a service has critical vulnerabilities open beyond SLA, it cannot ship new features. The monthly Risk and Compliance Steerco reviews vulnerability trends as a key risk indicator. The Board receives quarterly reporting on mean time to remediate and open vulnerability counts. The PCI DSS compliance programme depends on quarterly internal and external scanning with clean results. All of this runs through you.

 

The role requires a particular kind of judgement. You will deal with hundreds or thousands of vulnerability findings from multiple scanning tools (SAST, SCA, DAST, infrastructure scanning, CSPM, container scanning, penetration testing). Most of those findings will not be equally important. Your job is to contextualise them: a critical CVSS vulnerability in an internet-facing payment API is fundamentally different from the same CVSS score on an internal development tool with no access to sensitive data. You prioritise based on exploitability, business context, exposure, and regulatory sensitivity — not just generic severity scores.

 

If you are someone who combines analytical rigour with excellent stakeholder management skills— someone who can triage a thousand findings into a prioritised, actionable list and then work across a dozen engineering teams to ensure the right things get fixed in the right order — this role will suit you.

 

To be successful as a Vulnerability Management Analyst, you should have experience with;

 

Some other highly valued skills may include;

 

You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job-specific technical skills

 

The successful candidate will be based in London. Our offices are located at 7 Westferry Circus (new BPL office).

 

This role is 3 days per week office-based presence expected.

 

Barclays’ payments acceptance business provides critical infrastructure to the UK economy, processing billions of pounds of payments annually for both small businesses and domestic and international corporate clients.

 

In April 2025, we announced a long-term partnership with Brookfield Asset Management to grow and transform the payments acceptance business by broadening the range of services offered, enhancing the experience for both existing and prospective clients. Leveraging extensive client relationships and deep experience of UK payments, we will create an environment of continuous innovation - activated by Brookfield’s global private equity expertise in payments, technology, operational transformation and corporate carve-outs - to ensure the business is strategically positioned for long-term growth.

Barclays will invest approximately £400m in the new business, the majority of which will be incurred during the first three years. Performance-linked incentives will drive greater alignment between the partners, underpinning the long-term commitment to the transformation. Barclays and Brookfield will work to create a standalone entity over time, continuing to use the Barclaycard Payments (BPL) brand and acting as the sole payments acceptance services provider to Barclays’ clients for a minimum of ten years.

 

For more information on our partnership with Brookfield, please visit Barclays.com.

Encuentra más ofertas como esta

Explora más ofertas activas de esta empresa o crea una cuenta en Insider Jobs para buscar, guardar y seguir oportunidades en todo el job board.