Senior Vulnerability Management Analyst

Barclays

Greater London

Hybrid

GBP 65,000 - 100,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model
London office

Job summary

Barclays is seeking a Vulnerability Management Analyst based in London to own the end-to-end vulnerability lifecycle across the estate, from scanning through remediation tracking and reporting. You will provide security input during change/design, influencing stakeholders to enable secure business evolution.

The role involves coordinating with several engineering teams to ensure timely remediation, supporting PCI DSS requirements, and delivering risk-based prioritisation for fixes.

Qualifications

  • Experience in vulnerability management, security operations, or related security discipline.
  • Familiarity with multiple scanning tools across infrastructure, applications, and cloud/container domains.
  • Ability to contextualise vulnerabilities beyond CVSS scores for risk-based prioritisation.
  • Knowledge of PCI DSS vulnerability requirements and risk acceptance processes.
  • Strong data analysis and dashboard creation skills.
  • Experience with ticketing/workflow tools (e.g., Jira, ServiceNow).

Responsibilities

  • Own end-to-end vulnerability lifecycle across the estate, from scanning to remediation tracking.
  • Provide security input during change/design, engaging with stakeholders to influence security strategy.
  • Deliver regular vulnerability trend reporting to risk and compliance forums and board-level updates.
  • Coordinate with multiple engineering teams to ensure timely remediation of identified vulnerabilities.
  • Support CISO/CIO and product teams with security reviews for third-party products and services.

Skills

Vulnerability management
Security operations
Threat modeling
Risk assessment
Stakeholder management
DevSecOps
SLA management
Communication

Tools

Tenable
Qualys
Rapid7
SAST/DAST/SCA tools (Semgrep, Snyk, Checkmarx, Burp Suite)
Cloud/container scanning (Wiz, Prisma Cloud, Trivy)
Jira
ServiceNow

Job description

To enable ‘secure by design’, supporting the bank’s change programmes, design and implement a secure systems and architecture across a broad set of security domains. These include data security, security risk management, asset security, security architecture and engineering (incl. cloud security), communications and networks, security operations, software development, security assurance testing, identity and access management (IAM).

Accountabilities
  • Control function or security guild responsible for technology change oversight and governance.
  • Execution of security risk assessments and building threat models during the change & development lifecycle in order to identify vulnerabilities within the banks IT systems, applications and infrastructure, ensuring that compensating security controls and countermeasures are embedded in order to enhance security posture and resilience against cyber threats provision of timely communication of key findings and recommendations to stakeholders.
  • Enablement of DevSecOps (and shift left), by providing engagement channels for customers and stakeholders who wish to engage early seeking security advice and input into their business plans and opportunities, or technology change designs, influencing key stakeholders in COO and CSO to create security strategies to enable business and technology evolution.
  • Support and guidance to CISO, CIO and Product Team functions providing security reviews for prospective 3rd party technology products and services.
  • Transfer of residual risks to the business/customer as required by the bank’s enterprise risk management framework.
  • To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/ processes; deliver continuous improvements and elevate breaches of policies/procedures..
  • If managing a team, they define jobs and responsibilities, planning for the department’s future needs and operations, counselling employees on performance and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long term goals and ensuring that budgets and schedules meet corporate requirements..
  • If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L – Listen and be authentic, E – Energise and inspire, A – Align across the enterprise, D – Develop others..
  • OR for an individual contributor, they will be a subject matter expert within own discipline and will guide technical direction. They will lead collaborative, multi-year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions..
  • Advise key stakeholders, including functional leadership teams and senior management on functional and cross functional areas of impact and alignment.
  • Manage and mitigate risks through assessment, in support of the control and governance agenda.

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.

Join us a Vulnerability Management Analyst with BPL CIO- own the end-to-end vulnerability lifecycle across the entire estate: from scanning orchestration through triage, prioritisation, SLA assignment, remediation tracking, exception management, and reporting. You are the single point of accountability for knowing, at any moment, what vulnerabilities exist in the organisation’s systems, how severe they are in the context of the business, who is responsible for fixing them, and whether they are being fixed within agreed timescales.

This role is critical because vulnerability management sits at the intersection of several key processes in the CISO operating model. The pre-release security sign-off process checks a service’s open vulnerability backlog before approving a production release — if a service has critical vulnerabilities open beyond SLA, it cannot ship new features. The monthly Risk and Compliance Steerco reviews vulnerability trends as a key risk indicator. The Board receives quarterly reporting on mean time to remediate and open vulnerability counts. The PCI DSS compliance programme depends on quarterly internal and external scanning with clean results. All of this runs through you.

If you are someone who combines analytical rigour with excellent stakeholder management skills— someone who can triage a thousand findings into a prioritised, actionable list and then work across a dozen engineering teams to ensure the right items get fixed in the right order — this role will suit you.

To be successful as aVulnerability Management Analyst, you should have experience with;

  • Demonstrable experience in vulnerability management, security operations, or a related security discipline where you have been responsible for managing vulnerability findings from identification through to verified remediation
  • Experience with vulnerability scanning tools across multiple domains: infrastructure scanning (Tenable, Qualys, Rapid7, or equivalent), application scanning (SAST/DAST/SCA tools such as Semgrep, Snyk, Checkmarx, or Burp Suite), and cloud or container scanning (Wiz, Prisma Cloud, Trivy, or cloud-native equivalents)
  • Understanding of CVSS scoring and, critically, the ability to contextualise vulnerabilities beyond raw CVSS scores
  • Experience with contextual vulnerability prioritisation approaches: SSVC, EPSS, CISA KEV, or equivalent frameworks that move beyond generic severity to business-contextualised priority
  • Data analysis and dashboard creation skills
  • Familiarity with PCI DSS Vulnerability management requirements
  • Experience managing vulnerability exceptions and risk acceptances in a structured, documented process
  • Competence with ticketing and workflow tools (Jira, ServiceNow, or equivalent) for creating, tracking, and reporting on vulnerability remediation at scale

Some other highly valued skills may include;

  • Understanding of cloud and container vulnerability scanning: the differences between image scanning, registry scanning, and runtime scanning; the challenges of scanning episodic containers and serverless functions; and the implications of shared responsibility models for vulnerability ownership
  • Experience coordinating ASV (Approved Scanning Vendor) scans for PCI DSS, including scope definition, false positive management, and the rescan/remediation cycle required to achieve a clean quarterly scan
  • Payments or financial services experience, particularly in an environment subject to PCI DSS vulnerability management requirements.
  • Understanding of software composition analysis (SCA) and open-source dependency risk. The ability to assess the risk of a vulnerable transitive dependency in the context of how it is actually used in the application, rather than treating every SCA finding as equally urgent
  • Experience with exploit intelligence feeds (Recorded Future, Mandiant, CISA KEV) and using exploit availability and active exploitation status to inform prioritisation
  • Scripting skills (Python, Bash, or equivalent) for automating data extraction, normalisation, and reporting from scanning tools and APIs.

You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job-specific technical skills

The successful candidate will be based in London. Our offices are located at 7 Westferry Circus (new BPL office).

This role is 3 days per week office-based presence expected.

Barclays’ payments acceptance business provides critical infrastructure to the UK economy, processing billions of pounds of payments annually for both small businesses and domestic and international corporate clients.

In April 2025, we announced a long-term partnership with Brookfield Asset Management to grow and transform the payments acceptance business by broadening the range of services offered, enhancing the experience for both existing and prospective clients. Leveraging extensive client relationships and deep experience of UK payments, we will create an environment of continuous innovation - activated by Brookfield’s global private equity expertise in payments, technology, operational transformation and corporate carve-outs - to ensure the business is strategically positioned for long-term growth.

Barclays will invest approximately £400m in the new business, the majority of which will be incurred during the first three years. Performance-linked incentives will drive greater alignment between the partners, underpinning the long-term commitment to the transformation. Barclays and Brookfield will work to create a standalone entity over time, continuing to use the Barclaycard Payments (BPL) brand and acting as the sole payments acceptance services provider to Barclays’ clients for a minimum of ten years.

For more information on our partnership with Brookfield, please visit Barclays.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Vulnerability Management Analyst- CIO- BPL
Senior Vulnerability Management Analyst- CIO- BPL

Barclays • City Of London

On-site
GBP 70,000 - 120,000
Cyber Tech Risk and Control Manager- BPL -CIO
Cyber Tech Risk and Control Manager- BPL -CIO

Barclays • City Of London

On-site
GBP 60,000 - 90,000
Office-based 3 days/week
Vulnerability Hunting Lead
Vulnerability Hunting Lead

Barclays • Knutsford

On-site
GBP 90,000 - 140,000
Senior Product Manager - BPL
Senior Product Manager - BPL

Barclays • Greater London

On-site
GBP 90,000 - 130,000
Barclaycard Acquiring Payments - Technology Audit VP (BPL)
Barclaycard Acquiring Payments - Technology Audit VP (BPL)

Barclays • City Of London

On-site
GBP 140,000 - 210,000
BPL Senior Payment Specialist
BPL Senior Payment Specialist

Barclays • Greater London

On-site
GBP 70,000 - 100,000
Business Development Manager BPL
Business Development Manager BPL

Barclays • Greater London

On-site
GBP 65,000 - 90,000
Technical Test Manager- BPL
Technical Test Manager- BPL

8120 Barclaycard UK • Greater London

Hybrid
GBP 90,000 - 130,000
Barclaycard Acquiring Payments - Technology Audit VP (BPL)
Barclaycard Acquiring Payments - Technology Audit VP (BPL)

Barclays • Greater London

On-site
GBP 120,000 - 160,000
Product Manager - BPL- 12month FTC
Product Manager - BPL- 12month FTC

8120 Barclaycard UK • Greater London

Hybrid
GBP 90,000 - 120,000
Hybrid work pattern