SecJobs
RoleSuite
CompaniesRemoteAboutMethodologyContactPrivacy
Updated 2026-06-10 02:00 UTC·© 2025–2026 RoleSuite
← Back to listings

Penetration Tester - AVP

Barclays · Building 400-Whippany Campus, Jefferson Park

Job Description

Purpose of the role

To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks. 

Accountabilities

  • Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders.
  • Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies.
  • Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance.
  • Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance.
  • Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing methodologies and assurance activities.

Assistant Vice President Expectations

  • To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions/ business divisions.
  • Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes
  • If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L – Listen and be authentic, E – Energise and inspire, A – Align across the enterprise, D – Develop others.
  • OR for an individual contributor, they will lead collaborative assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will identify new directions for assignments and/ or projects, identifying a combination of cross functional methodologies or practices to meet required outcomes.
  • Consult on complex issues; providing advice to People Leaders to support the resolution of escalated issues.
  • Identify ways to mitigate risk and developing new policies/procedures in support of the control and governance agenda.
  • Take ownership for managing risk and strengthening controls in relation to the work done.
  • Perform work that is closely related to that of other areas, which requires understanding of how areas coordinate and contribute to the achievement of the objectives of the organisation sub-function.
  • Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategy.
  • Engage in complex analysis of data from multiple sources of information, internal and external sources such as procedures and practises (in other areas, teams, companies, etc).to solve problems creatively and effectively.
  • Communicate complex information. 'Complex' information could include sensitive information or information that is difficult to communicate because of its content or its audience.
  • Influence or convince stakeholders to achieve outcomes.

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.

Embark on a transformative journey as a Penetration Tester - AVP. At Barclays, our vision is clear –to redefine the future of banking and help craft innovative solutions. Penetration Testing team provide a core cyber assurance service. Services are provided via a global internal team and preferred suppliers. We provide Security Assurance capabilities which are aligned to the ‘lifecycle’ of a service or application. In this role, you will play a critical role in the delivery of security assurance across annual lifecycle testing and change/project engagements. This will be across a range of different technologies (e.g. web application, API, infrastructure, virtualization/containers, mobile, cloud, AI). In addition to BAU pen testing, there will be close collaboration with teams such as vulnerability management, application security, and CTEM to ensure proactive security.

To be successful as a Penetration Tester - AVP, you should have:

  • Practical experience for delivery experience in penetration testing or related fields

  • Proficiency in Penetration testing in following technical domains, Web based Applications, Network/Infrastructure, APIs, Mobile Apps, Thick clients, MCPs/AI Agents/LLMs, Cloud environments

  • Understanding of the security mechanisms associated with Applications, Operating Systems, Networks, Databases, Virtualization, Cloud technologies, AI

  • Familiarity with cloud-native environments, container security, and infrastructure-as-code

  • Excellent communication and collaboration skills

Other highly valued skills include:

  • CREST/OSCP/SANS or equivalent pen testing certifications

  • Red/Purple team experience. Considerable understanding of attack paths and adversary emulation

  • Enterprise vulnerability management experience (vulnerability research, scanning, operational process)

  • Wider SDL activities such as threat/attack modelling and design review

  • Familiarity and experience with key industry frameworks such as OWASP, MITRE ATT&CK/CTID, CISA Secure-by-Design, NIST CSF 2.0/CRI Profile, DORA/FFIEC

You may be assessed on the key critical skills relevant for success in this role, such as risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, as well as job-specific technical skills.

This role is located in our Whippany, NJ office.

Minimum Salary: $125,000

Maximum Salary: $170,000

The minimum and maximum salary/rate information above includes only base salary or base hourly rate. It does not include any other type of compensation or benefits that may be available.

Barclays employees are eligible for a suite of competitive and generous employee benefits, including medical, dental and vision coverage, 401(k), life insurance, and other paid leave for qualifying circumstances.

This position is eligible for an incentive award.

Apply →

Other roles at Barclays

  • Head of Governance & Management System - BPLCanary Wharf, 1 Churchill Place
  • Head of Business and Performance Insight – BPLCanary Wharf, 1 Churchill Place
  • Head Governance & Oversight, Corporate Client ServicingKnutsford, Radbroke Hall
  • Head of Product Security – CISO function - BPLCanary Wharf, 1 Churchill Place
  • Software Engineer - PythonCanary Wharf, 1 Churchill Place
  • Corporate Risk and Control LeadPune, Gera Commerzone SEZ
  • Executive AssistantCanary Wharf, 1 Churchill Place
  • Europe Change Business AnalystDublin, Molesworth Street
  • Head of Resilience Emerging Risks and InnovationsGlasgow Campus
  • CIO Strategy - Quantitative AnalystCanary Wharf, 1 Churchill Place

More Security roles

  • Site Security ManagerBooz Allen Hamilton · Okinawa
  • Identity Developer (SailPoint IdentityIQ)Accenture · Ballarat, 11 University Drive
  • Security EngineerStack AI · SF Office - 171 2nd, 4th floor
  • Privacy Engineer - Systems Experiences, Apps, and TechnologiesApple · Cupertino
  • Vulnerability ResearcherApple · Seattle
  • Staff Product Security Engineer Rivian · Palo Alto, California
  • Contract Special Security Officer (CSSO)Accenture Federal Services · Chantilly, VA
  • Senior Information Security Engineer, Offensive SecurityGrvty · San Antonio, Texas, United States
  • Full Time Security Officer Fri/Sat(12a-6a)& Sun-Tue(6p-12am)Comstock · Rockville, MD
  • Principal Infrastructure Security EngineerCrusoe · San Francisco, CA - US