Cyber Tech Risk and Control Manager- BPL -CIO

Barclays · Canary Wharf, 1 Churchill Place · United Kingdom

Cyber Tech Risk and Control Manager- BPL -CIO senior · Risk & Compliance

Vista previa de la oferta

Cyber Tech Risk and Control Manager- BPL -CIO

senior · Risk & Compliance

Job Description

Purpose of the role

To enable ‘secure by design’, supporting the bank’s change programmes, design and implement a secure systems and architecture across a broad set of security domains. These include data security, security risk management, asset security, security architecture and engineering (incl. cloud security), communications and networks, security operations, software development, security assurance testing, identity and access management (IAM). 

Accountabilities

Vice President Expectations

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.

Join us as the Cyber Tech Risk and Control Manager-- you will be the connective tissue between the security capabilities delivered by the other three pillars and the compliance evidence and assurance that GRC needs to demonstrate to regulators, auditors, and the Board. You own the design (collaboratively with the control owners), documentation, and effectiveness testing of security controls across the entire organisation.

 

In practical terms, this means you are the person who answers the question: “Are our security controls actually working, and can we prove it?” The Security Architecture and Engineering pillar builds the cloud security guardrails. The Product Security pillar runs the vulnerability scanning pipeline.

 

The role sits within GRC but works across all four pillars of the CISO team on a daily basis. You will spend significant time with cloud security engineers validating CSPM controls, with AppSec engineers reviewing pipeline security gates, with SOC analysts verifying detection rule coverage, and with the IAM engineer testing access review processes. You need enough technical fluency to understand what these controls do and how to test them, combined with the governance rigour to document findings in a way that satisfies a QSA or FCA supervisor.

 

If you are someone who enjoys working at the intersection of technical security and regulatory compliance — someone who can read a Terraform policy and a PCI DSS requirement and connect the two — this role will suit you well.

 

To be successful as a Cyber Tech Risk and Control Manager-, you must have the following essential skills;

 

Some other highly valued skills may include;

 

You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job-specific technical skills

 

The successful candidate will be based in London. Our offices are located at 7 Westferry Circus (new BPL office).

 

This role is 3 days per week office-based presence expected.

 

Barclays’ payments acceptance business provides critical infrastructure to the UK economy, processing billions of pounds of payments annually for both small businesses and domestic and international corporate clients.

 

In April 2025, we announced a long-term partnership with Brookfield Asset Management to grow and transform the payments acceptance business by broadening the range of services offered, enhancing the experience for both existing and prospective clients. Leveraging extensive client relationships and deep experience of UK payments, we will create an environment of continuous innovation - activated by Brookfield’s global private equity expertise in payments, technology, operational transformation and corporate carve-outs - to ensure the business is strategically positioned for long-term growth.

Barclays will invest approximately £400m in the new business, the majority of which will be incurred during the first three years. Performance-linked incentives will drive greater alignment between the partners, underpinning the long-term commitment to the transformation. Barclays and Brookfield will work to create a standalone entity over time, continuing to use the Barclaycard Payments (BPL) brand and acting as the sole payments acceptance services provider to Barclays’ clients for a minimum of ten years.

 

For more information on our partnership with Brookfield, please visit Barclays.com.

Encuentra más ofertas como esta

Explora más ofertas activas de esta empresa o crea una cuenta en Insider Jobs para buscar, guardar y seguir oportunidades en todo el job board.