379,554open jobs
9,915companies
49,317added this week
Browse all
Salary
$121k – $256k per year (Estimated)
Location
In office (London)
Seniority
Architect · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Barclays is a British multinational universal bank that provides a wide range of services, including retail banking, corporate and investment banking, and wealth management. Headquartered in London with a history spanning centuries, it operates as a major financial institution with a significant presence across the United Kingdom, Europe, the Americas, Africa, and Asia. The bank focuses on delivering comprehensive financial solutions and digital banking products to millions of individual and institutional clients globally.

Job Description

Purpose of the role

To enable ‘secure by design’, supporting the bank’s change programmes, design and implement a secure systems and architecture across a broad set of security domains. These include data security, security risk management, asset security, security architecture and engineering (incl. cloud security), communications and networks, security operations, software development, security assurance testing, identity and access management (IAM).

Accountabilities

  • Control function or security guild responsible for technology change oversight and governance.
  • Execution of security risk assessments and building threat models during the change & development lifecycle in order to identify vulnerabilities within the banks IT systems, applications and infrastructure, ensuring that compensating security controls and countermeasures are embedded in order to enhance security posture and resilience against cyber threats provision of timely communication of key findings and recommendations to stakeholders.
  • Enablement of DevSecOps (and shift left), by providing engagement channels for customers and stakeholders who wish to engage early seeking security advice and input into their business plans and opportunities, or technology change designs, influencing key stakeholders in COO and CSO to create security strategies to enable business and technology evolution.
  • Support and guidance to CISO, CIO and Product Team functions providing security reviews for prospective 3rd party technology products and services.
  • Transfer of residual risks to the business/customer as required by the bank’s enterprise risk management framework.
  • Collaboration with stakeholder and IT teams to support incident response and investigations using their knowledge of the banks technology systems sharing security insights.
  • Participation in the development and maintenance of security policies, standards and procedures aligned to the banks risk tolerance, regulatory requirements and industry best practice.

Vice President Expectations

  • To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/ processes; deliver continuous improvements and escalate breaches of policies/procedures..
  • If managing a team, they define jobs and responsibilities, planning for the department’s future needs and operations, counselling employees on performance and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long term goals and ensuring that budgets and schedules meet corporate requirements..
  • If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic, E - Energise and inspire, A - Align across the enterprise, D - Develop others..
  • OR for an individual contributor, they will be a subject matter expert within own discipline and will guide technical direction. They will lead collaborative, multi-year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions..
  • Advise key stakeholders, including functional leadership teams and senior management on functional and cross functional areas of impact and alignment.
  • Manage and mitigate risks through assessment, in support of the control and governance agenda.
  • Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work your team does.
  • Demonstrate comprehensive understanding of the organisation functions to contribute to achieving the goals of the business.
  • Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategies.
  • Create solutions based on sophisticated analytical thought comparing and selecting complex alternatives. In-depth analysis with interpretative thinking will be required to define problems and develop innovative solutions.
  • Adopt and include the outcomes of extensive research in problem solving processes.
  • Seek out, build and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes.

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave.

Join us as the Cyber Tech Risk and Control Manager-- you will be the connective tissue between the security capabilities delivered by the other three pillars and the compliance evidence and assurance that GRC needs to demonstrate to regulators, auditors, and the Board. You own the design (collaboratively with the control owners), documentation, and effectiveness testing of security controls across the entire organisation.

In practical terms, this means you are the person who answers the question: “Are our security controls actually working, and can we prove it?” The Security Architecture and Engineering pillar builds the cloud security guardrails. The Product Security pillar runs the vulnerability scanning pipeline.

The role sits within GRC but works across all four pillars of the CISO team on a daily basis. You will spend significant time with cloud security engineers validating CSPM controls, with AppSec engineers reviewing pipeline security gates, with SOC analysts verifying detection rule coverage, and with the IAM engineer testing access review processes. You need enough technical fluency to understand what these controls do and how to test them, combined with the governance rigour to document findings in a way that satisfies a QSA or FCA supervisor.

If you are someone who enjoys working at the intersection of technical security and regulatory compliance - someone who can read a Terraform policy and a PCI DSS requirement and connect the two - this role will suit you well.

To be successful as a Cyber Tech Risk and Control Manager-, you must have the following essential skills;

  • Demonstrable experience in IT controls, security assurance, IT audit, or technology risk management
  • Experience designing and documenting controls mapped to regulatory frameworks, ideally mapping a single control to multiple requirements simultaneously
  • Understanding of control testing methodologies: inquiry, observation, inspection, and re-performance
  • Familiarity with PCI DSS requirements and how they translate into technical controls
  • Sufficient technical fluency to understand and test controls in a cloud-native environment
  • Excellent documentation skills. Control descriptions, testing procedures, and evidence packages must be clear, precise, and comprehensible to someone who was not present when the work was done
  • Ability to work across technical and non-technical teams
  • Attention to detail and organisational discipline
  • Understanding of at least one common control or assurance framework: NIST CSF, ISO 27001, COBIT, or COSO
  • Experience with GRC tooling or platforms for control management (e.g., Drata, Vanta, ServiceNow GRC, Archer, OneTrust, or equivalent)

Some other highly valued skills may include;

  • CISA (Certified Information Systems Auditor) certification - the most directly relevant qualification for this role, demonstrating competence in IT audit, control, and assurance
  • CRISC (Certified in Risk and Information Systems Control) or ISO 27001 Lead Auditor certification
  • PCI DSS Internal Security Assessor (ISA) qualification, or experience working directly with a QSA during PCI DSS assessments
  • Experience in financial services, payments, or fintech IT audit or controls. Understanding the regulatory landscape (FCA, PCI SSC) from a controls perspective is a significant advantage
  • Familiarity with cloud-native technologies (AWS or GCP, Kubernetes, Terraform) from a controls perspective - understanding what can go wrong and how controls prevent, detect, or correct it
  • Experience with DORA (Digital Operational Resilience Act) requirements, particularly the ICT risk management and resilience testing provisions that translate into specific control requirements
  • Experience with FCA operational resilience requirements (PS21/3) and the mapping of impact tolerances to control frameworks
  • Experience with continuous compliance or continuous control monitoring approaches - where control effectiveness data is gathered automatically from tooling rather than through periodic manual testing
  • Understanding of the FAIR (Factor Analysis of Information Risk) methodology or similar quantitative risk frameworks, and how control effectiveness feeds into risk quantification
  • Previous experience in a Big 4 or mid-tier consultancy IT audit or technology risk practice - this background provides strong foundational skills in control assessment methodology

You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job-specific technical skills

The successful candidate will be based in London. Our offices are located at 7 Westferry Circus (new BPL office).

This role is 3 days per week office-based presence expected.

Barclays’ payments acceptance business provides critical infrastructure to the UK economy, processing billions of pounds of payments annually for both small businesses and domestic and international corporate clients.

In April 2025, we announced a long-term partnership with Brookfield Asset Management to grow and transform the payments acceptance business by broadening the range of services offered, enhancing the experience for both existing and prospective clients. Leveraging extensive client relationships and deep experience of UK payments, we will create an environment of continuous innovation - activated by Brookfield’s global private equity expertise in payments, technology, operational transformation and corporate carve-outs - to ensure the business is strategically positioned for long-term growth.

Barclays will invest approximately £400m in the new business, the majority of which will be incurred during the first three years. Performance-linked incentives will drive greater alignment between the partners, underpinning the long-term commitment to the transformation. Barclays and Brookfield will work to create a standalone entity over time, continuing to use the Barclaycard Payments (BPL) brand and acting as the sole payments acceptance services provider to Barclays’ clients for a minimum of ten years.

For more information on our partnership with Brookfield, please visit Barclays.com.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
379,554 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
London
$166k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Chicago
Python
Java
Java
Apache Tomcat
Databases
OpenSearch
Oracle
DevOps
Amazon CloudWatch
Ansible
AWS
CI/CD
CloudFormation
Docker
GCP
Grafana
Istio
Jenkins
Kubernetes
Nginx
Prometheus
Terraform
Apply
AI / ML Engineer 1 hour ago
$31k – $79k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Hyderabad
Node JS
Python
JavaScript
Python
Django
FastAPI
Flask
Databases
DynamoDB
MySQL
Neo4j
PostgreSQL
AI/ML
AI Agents
Copilot
CrewAI
Embeddings
Function Calling
LLM
Prompt Engineering
RAG
Frontend
Next.js
React.js
Tailwind CSS
Vite
DevOps
AWS
Azure
Azure DevOps
CI/CD
Docker
GCP
GitHub
GitHub Actions
Jenkins
Kubernetes
Vector
Design
Figma
Apply
$52k – $94k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Augusta
JavaScript
SQL
TypeScript
Databases
MySQL
Oracle
PostgreSQL
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
Apply
In office • Full-Time • Pune
JavaScript
SQL
TypeScript
AI/ML
Claude
Claude Code
Copilot
Frontend
Angular
Angular Material
Lighthouse
RxJS
Mobile
Dependency Injection
JUnit
DevOps
AppDynamics
AWS
Azure
CI/CD
Docker
Dynatrace
Git
GitLab
GitLab CI
Grafana
Jenkins
Kibana
Kubernetes
OpenShift
Rest API
Self-Healing
Splunk
QA
Cucumber
Cypress
Playwright
Postman
Rest-Assured
Selenium
Swagger
TestNG
Apply
$58k – $105k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • Gaithersburg
C++
Java
Python
SQL
DevOps
AWS
Azure
CI/CD
Docker
Git
GitHub
GitHub Actions
GitLab
GitLab CI
Harbor
Jenkins
Kubernetes
Apply
In office • Full-Time • Pune
Apex
DevOps
Git
Marketing
Salesforce
Apply
$27k – $56k per year (Estimated) • In office • Full-Time • Pune
SQL
DevOps
CI/CD
Management
Confluence
Apply
$16k – $62k per year (Estimated) • In office • Full-Time • Chennai
Java
Python
SQL
Databases
Databricks
Snowflake
Analytics
ETL/ELT
Apply
In office • Full-Time • Pune
JavaScript
SQL
TypeScript
AI/ML
Claude
Claude Code
Copilot
Frontend
Angular
Angular Material
Lighthouse
RxJS
Mobile
Dependency Injection
JUnit
DevOps
AppDynamics
AWS
Azure
CI/CD
Docker
Dynatrace
Git
GitLab
GitLab CI
Grafana
Jenkins
Kibana
Kubernetes
OpenShift
Rest API
Self-Healing
Splunk
QA
Cucumber
Cypress
Playwright
Postman
Rest-Assured
Selenium
Swagger
TestNG
Apply
$75k per year • In office • Full-Time • Park
Java
Java
Spring Boot
AI/ML
Prompt Engineering
DevOps
CI/CD
Rest API
Apply
$93k – $168k per year (Estimated) • In office • Full-Time • 5+ years exp • London
C#
C++
Python
AI/ML
Fine-tuning
Mobile
State Management
Game Dev
Unity
Management
Outlook
Apply
Data Architect 1 hour ago
$100k – $239k per year (Estimated) • In office • Full-Time • London
Java
Python
Scala
DevOps
Azure
Apply
$122k – $221k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • London
Java
DevOps
Azure
Azure DevOps
Shift-Left
Cybersecurity
GDPR
Shift-Left Security
Management
Jira
Marketing
Salesforce
QA
BrowserStack
JMeter
k6
Postman
Rest-Assured
Selenium
Apply
$87k – $174k per year (Estimated) • In office • Full-Time • 10+ years exp • London
Bash
Go
Python
Ruby
DevOps
Ansible
AWS
Azure
Chef
CI/CD
Docker
Docker Compose
Dynatrace
GCP
GitHub
GitHub Actions
Grafana
Helm
Jenkins
Kubernetes
Prometheus
Splunk
Terraform
Apply
$106k – $193k per year (Estimated) • In office • Full-Time • London • Manchester
Python
SQL
TypeScript
Python
pySpark
AI/ML
Spark
Analytics
ETL/ELT
Management
Slack
Apply
See all jobs
This is one of many
379,554 more open roles from verified company boards, updated every day.