Skip to main content

Vulnerability Management Analyst- CIO- BPL

London, United Kingdom

Apply for job

Key information

Date live: 02/09/2026

Business Area: BPL - Technology

Area of Expertise: Technology

Contract: Permanent

Reference Code: JR-0000129207

It’s happening at Barclays.

Be a part of a place where challenges are measured in billions, qubits and nanoseconds. Build your career in an environment where we’re advancing machine learning, leveraging blockchains, and harnessing FinTech. Working in Barclays technology, you’ll reimagine possibilities: learning and innovating to solve the challenges ahead, delivering for millions of customers.
We are shaping the future of financial technology.
Why not join us and make it happen here?

Join us a Vulnerability Management Analyst with BPL CIO- own the end-to-end vulnerability lifecycle across the entire estate: from scanning orchestration through triage, prioritisation, SLA assignment, remediation tracking, exception management, and reporting. You are the single point of accountability for knowing, at any moment, what vulnerabilities exist in the organisation’s systems, how severe they are in the context of the business, who is responsible for fixing them, and whether they are being fixed within agreed timescales.

This role is critical because vulnerability management sits at the intersection of several key processes in the CISO operating model. The pre-release security sign-off process checks a service’s open vulnerability backlog before approving a production release — if a service has critical vulnerabilities open beyond SLA, it cannot ship new features. The monthly Risk and Compliance Steerco reviews vulnerability trends as a key risk indicator. The Board receives quarterly reporting on mean time to remediate and open vulnerability counts. The PCI DSS compliance programme depends on quarterly internal and external scanning with clean results. All of this runs through you.

The role requires a particular kind of judgement. You will deal with hundreds or thousands of vulnerability findings from multiple scanning tools (SAST, SCA, DAST, infrastructure scanning, CSPM, container scanning, penetration testing). Most of those findings will not be equally important. Your job is to contextualise them: a critical CVSS vulnerability in an internet-facing payment API is fundamentally different from the same CVSS score on an internal development tool with no access to sensitive data. You prioritise based on exploitability, business context, exposure, and regulatory sensitivity — not just generic severity scores.

If you are someone who combines analytical rigour with excellent stakeholder management skills— someone who can triage a thousand findings into a prioritised, actionable list and then work across a dozen engineering teams to ensure the right things get fixed in the right order — this role will suit you.

To be successful as aVulnerability Management Analyst, you should have experience with;

  • Demonstrable experience in vulnerability management, security operations, or a related security discipline where you have been responsible for managing vulnerability findings from identification through to verified remediation
  • Experience with vulnerability scanning tools across multiple domains: infrastructure scanning (Tenable, Qualys, Rapid7, or equivalent), application scanning (SAST/DAST/SCA tools such as Semgrep, Snyk, Checkmarx, or Burp Suite), and cloud or container scanning (Wiz, Prisma Cloud, Trivy, or cloud-native equivalents)
  • Understanding of CVSS scoring and, critically, the ability to contextualise vulnerabilities beyond raw CVSS scores
  • Experience with contextual vulnerability prioritisation approaches: SSVC, EPSS, CISA KEV, or equivalent frameworks that move beyond generic severity to business-contextualised priority
  • Data analysis and dashboard creation skills
  • Familiarity with PCI DSS Vulnerability management requirements
  • Experience managing vulnerability exceptions and risk acceptances in a structured, documented process
  • Competence with ticketing and workflow tools (Jira, ServiceNow, or equivalent) for creating, tracking, and reporting on vulnerability remediation at scale

Some other highly valued skills may include;

  • Understanding of cloud and container vulnerability scanning: the differences between image scanning, registry scanning, and runtime scanning; the challenges of scanning ephemeral containers and serverless functions; and the implications of shared responsibility models for vulnerability ownership
  • Experience coordinating ASV (Approved Scanning Vendor) scans for PCI DSS, including scope definition, false positive management, and the rescan/remediation cycle required to achieve a clean quarterly scan
  • Payments or financial services experience, particularly in an environment subject to PCI DSS vulnerability management requirements.
  • Understanding of software composition analysis (SCA) and open-source dependency risk. The ability to assess the risk of a vulnerable transitive dependency in the context of how it is actually used in the application, rather than treating every SCA finding as equally urgent
  • Experience with exploit intelligence feeds (Recorded Future, Mandiant, CISA KEV) and using exploit availability and active exploitation status to inform prioritisation
  • Scripting skills (Python, Bash, or equivalent) for automating data extraction, normalisation, and reporting from scanning tools and APIs.
  • Experience operating vulnerability management in an agile or DevOps environment, including sprint-aligned remediation tracking and integration with CI/CD pipeline scan results
  • Background in penetration testing, security engineering, or software development — technical depth helps you write better tickets, validate remediations more effectively, and have more credible conversations with engineering teams

You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job-specific technical skills

The successful candidate will be based in London. Our offices are located at 7 Westferry Circus (new BPL office).

This role is 3 days per week office-based presence expected.

Barclays’ payments acceptance business provides critical infrastructure to the UK economy, processing billions of pounds of payments annually for both small businesses and domestic and international corporate clients.

In April 2025, we announced a long-term partnership with Brookfield Asset Management to grow and transform the payments acceptance business by broadening the range of services offered, enhancing the experience for both existing and prospective clients. Leveraging extensive client relationships and deep experience of UK payments, we will create an environment of continuous innovation - activated by Brookfield’s global private equity expertise in payments, technology, operational transformation and corporate carve-outs - to ensure the business is strategically positioned for long-term growth.

Barclays will invest approximately £400m in the new business, the majority of which will be incurred during the first three years. Performance-linked incentives will drive greater alignment between the partners, underpinning the long-term commitment to the transformation. Barclays and Brookfield will work to create a standalone entity over time, continuing to use the Barclaycard Payments (BPL) brand and acting as the sole payments acceptance services provider to Barclays’ clients for a minimum of ten years.

For more information on our partnership with Brookfield, please visit Barclays.com.

Purpose of the role

To enable ‘secure by design’, supporting the bank’s change programmes, design and implement a secure systems and architecture across a broad set of security domains. These include data security, security risk management, asset security, security architecture and engineering (incl. cloud security), communications and networks, security operations, software development, security assurance testing, identity and access management (IAM). 

Accountabilities

  • Control function or security guild responsible for technology change oversight and governance.
  • Execution of security risk assessments and building threat models during the change & development lifecycle in order to identify vulnerabilities within the banks IT systems, applications and infrastructure, ensuring that compensating security controls and countermeasures are embedded in order to enhance security posture and resilience against cyber threats provision of timely communication of key findings and recommendations to stakeholders.
  • Enablement of DevSecOps (and shift left), by providing engagement channels for customers and stakeholders who wish to engage early seeking security advice and input into their business plans and opportunities, or technology change designs, influencing key stakeholders in COO and CSO to create security strategies to enable business and technology evolution.
  • Support and guidance to CISO, CIO and Product Team functions providing security reviews for prospective 3rd party technology products and services.
  • Transfer of residual risks to the business/customer as required by the bank’s enterprise risk management framework.
  • Collaboration with stakeholder and IT teams to support incident response and investigations using their knowledge of the banks technology systems sharing security insights.
  • Participation in the development and maintenance of security policies, standards and procedures aligned to the banks risk tolerance, regulatory requirements and industry best practice.

Vice President Expectations

  • To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/ processes; deliver continuous improvements and escalate breaches of policies/procedures..
  • If managing a team, they define jobs and responsibilities, planning for the department’s future needs and operations, counselling employees on performance and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long term goals and ensuring that budgets and schedules meet corporate requirements..
  • If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L – Listen and be authentic, E – Energise and inspire, A – Align across the enterprise, D – Develop others..
  • OR for an individual contributor, they will be a subject matter expert within own discipline and will guide technical direction. They will lead collaborative, multi-year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions..
  • Advise key stakeholders, including functional leadership teams and senior management on functional and cross functional areas of impact and alignment.
  • Manage and mitigate risks through assessment, in support of the control and governance agenda.
  • Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work your team does.
  • Demonstrate comprehensive understanding of the organisation functions to contribute to achieving the goals of the business.
  • Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategies.
  • Create solutions based on sophisticated analytical thought comparing and selecting complex alternatives. In-depth analysis with interpretative thinking will be required to define problems and develop innovative solutions.
  • Adopt and include the outcomes of extensive research in problem solving processes.
  • Seek out, build and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes.

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.

Barclays welcomes applications from all candidates and is committed to ensuring reasonable adjustments (accommodations) are put in place to allow for a fair and inclusive recruitment process. For more information and how to request one, please review Adjustments to the recruitment process.

We’re a global, vital and highly respected financial organisation with an inspiring Purpose. Operating in 39 countries and employing around 100,000 people across the world, we help communities, individuals and businesses thrive. And we’ve created financial solutions and technology that the world now takes for granted. A career with us can offer incredible variety, depth and breadth of experience, and the chance to learn from some of the best minds in technology and finance.

To find out more about Barclays' strategy please click here.

We are an equal opportunity employer and opposed to discrimination on any grounds. It is the policy of Barclays to ensure equal employment opportunity without discrimination or harassment on the basis of race, colour, creed, religion, national origin, alienage or citizenship status, age, sex, sexual orientation, gender identity or expression, marital or domestic/civil partnership status, disability, veteran status, genetic information, or any other basis protected by law.

Barclays is required by law to confirm that you have the Legal Right to Work in any role that you apply for. If you currently hold a work visa sponsored by Barclays, or you would require sponsorship from Barclays, you must declare this as part of your application. Sponsored visas are role and entity specific and any changes must be reviewed. It is important that you ensure you are working on the correct visa at all times. Failure to accurately disclose your visa status or Legal Right to Work may result in your application or any employment offer being withdrawn at any time.

This role may be subject to enhanced governance arrangements. If successful, you may be required to comply with additional regulatory and compliance obligations, such as disclosure of personal trading activities and external interest/affiliations.

Further information on these requirements will be provided at a later stage of the process.

Who succeeds in
Tech at Barclays?

For a career with us, you need to be prepared to take big steps forward, curious to face the challenges ahead, and driven to focus on the outcomes. We need people with the Barclays mindset to make it happen here.

Qualities we look for:motivator, supporter, connector, driver, communicator, transformer, maker, observer

What you'll get in return

Competitive holiday allowance
Life assurance
Private medical care
Pension contribution

Our technology

Supporting our 48 million customers and clients worldwide takes a lot of forward thinking. It means harnessing technology to support the economy. It means making a difference to people’s lives. And it requires the maintenance and development of a global, technological infrastructure. At Barclays, technology helps us keep transactions moving, manages data, and protects our customers. Join a world where your work creates unique moments of impact. Make it happen here.

This is Barclays London

Our global HQ is in Canary Wharf, at the heart of London’s financial district. There are over 10,000 colleagues here – a hugely diverse workforce made up of the world’s best financial and tech talent. If you love the buzz of city life, this is the place to be.

Cycle or run to work? We’ve got everything you need – from cycle hire and parking areas to new showering and changing facilities.

CoSpace is our drop-in co-working space, where networks are built, problems are solved collectively and our community is strengthened.

Our Wellness Suite includes a well-equipped gym and exercise studios, and provides personal training sessions and massage therapy.

Our new trading floors enhance communication, integrate sustainability, and support health and wellbeing through innovative design and British-sourced furniture.

This is Barclays London

Our global HQ is in Canary Wharf, at the heart of London’s financial district. There are over 10,000 colleagues here – a hugely diverse workforce made up of the world’s best financial and tech talent. If you love the buzz of city life, this is the place to be.

Supporting active commuters

Cycle or run to work? We’ve got everything you need – from cycle hire and parking areas to new showering and changing facilities.

Time to connect

CoSpace is our drop-in co-working space, where networks are built, problems are solved collectively and our community is strengthened.

Wellbeing in focus

Our Wellness Suite includes a well-equipped gym and exercise studios, and provides personal training sessions and massage therapy.

Advanced trading floors

Our new trading floors enhance communication, integrate sustainability, and support health and wellbeing through innovative design and British-sourced furniture.

Barclays

Working flexibly

We’re committed to providing a supportive and inclusive culture and environment for you to work in. This environment recognises and supports your personal needs, alongside the professional needs of our business. If you'd like to explore flexible working arrangements, please discuss this with the hiring manager. Your request will be reviewed in-line with the requirements of the role/business needs of the team.

Hybrid working

We have a structured approach to hybrid working, where colleagues work at an onsite location on fixed, ‘anchor’, days, as set by the business area. Please discuss the working pattern requirements for the role you are applying for with the hiring manager. Please note that working arrangements may be subject to change on reasonable notice to ensure we meet the needs of our business.

Barclays is built on an international scale.

Our geographic reach, our wide variety of functions, businesses, roles and locations reflect the rich diversity of our worldwide customer base. All of which means we offer incredible variety, depth and breadth of experience. And the chance to learn from a globally diverse mix of colleagues, including some of the very best minds in banking, finance, technology and business. Throughout, we’ll encourage you to embrace mobility, exploring every part of our operations as you build your career.

Find more information

Make it happen at Barclays

Our teams are always evolving - creating new solutions that make a real difference for customers and clients. Watch the video to hear how our colleagues describe their careers at Barclays and imagine where yours could take you.

Application process

1

Your application

We’ll ask for information about you, your CV and cover letter.

2

Your assessment

Covering your behaviours and ability at work.

3

Your interview

Exploring your past experiences and skills.

4

Next step

We’ll request additional information so that you can complete our screening process.

Related content

Related Jobs


Data Solution Designer

London (United Kingdom)

01 Sep
Low Latency Developer

London (United Kingdom)

31 Aug
AI Ops Platform Engineer

London (United Kingdom)

31 Aug
Identity & Access Lead - BPL

London (United Kingdom)

28 Aug
Senior Developer - QIS Technology

London (United Kingdom)

27 Aug
Tooling and Engineering Capability Execution Lead

London (United Kingdom), Knutsford (United Kingdom), Northampton (United Kingdom)

27 Aug
Senior AI Platform Engineer

London (United Kingdom)

25 Aug
Viva Insights Administrator and Data Engineer - 12 Months Fixed Term Contract

London (United Kingdom), Northampton (United Kingdom)

24 Aug
Head of Digital Engineering

London (United Kingdom), Glasgow (United Kingdom)

21 Aug
AI Platform Engineer

London (United Kingdom)

21 Aug