Job Description
Purpose of the role
To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks.
Accountabilities
- Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders.
- Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies.
- Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance.
- Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance.
- Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing methodologies and assurance activities.
Assistant Vice President Expectations
- To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions/ business divisions.
- Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes
- If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic, E - Energise and inspire, A - Align across the enterprise, D - Develop others.
- OR for an individual contributor, they will lead collaborative assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will identify new directions for assignments and/ or projects, identifying a combination of cross functional methodologies or practices to meet required outcomes.
- Consult on complex issues; providing advice to People Leaders to support the resolution of escalated issues.
- Identify ways to mitigate risk and developing new policies/procedures in support of the control and governance agenda.
- Take ownership for managing risk and strengthening controls in relation to the work done.
- Perform work that is closely related to that of other areas, which requires understanding of how areas coordinate and contribute to the achievement of the objectives of the organisation sub-function.
- Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategy.
- Engage in complex analysis of data from multiple sources of information, internal and external sources such as procedures and practises (in other areas, teams, companies, etc).to solve problems creatively and effectively.
- Communicate complex information. 'Complex' information could include sensitive information or information that is difficult to communicate because of its content or its audience.
- Influence or convince stakeholders to achieve outcomes.
All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave.
Embark on a transformative journey as a Red Team Analyst - AVP. At Barclays, our vision is clear -to redefine the future of banking and help craft innovative solutions. In this role, you’ll leverage industry-leading tools, explore emerging techniques, and execute operations across a wide range of domains, including cyber, physical, human, process, and technology. As a member of the Red Team, you’ll participate in full-scope adversary emulation exercises spanning cyber operations, physical security assessments, social engineering engagements, and everything in between, testing the resilience of our defenses under realistic conditions. You’ll identify vulnerabilities and control gaps, then work closely with stakeholders to help strengthen our security posture. This is a highly hands-on role, ideal for someone who thrives on tackling complex challenges, developing offensive security capabilities, and operating against sophisticated targets. You’ll have dedicated time to research emerging tradecraft, evaluate new tools and techniques, and collaborate with a team of skilled, highly motivated operators. Success in this role requires good technical expertise, practical security testing experience, creativity in problem-solving, and the ability to work effectively across teams to achieve meaningful security outcomes.
To be successful as a Red Team Analyst - AVP, you should have experience:
Executing full-scope Red Team engagements aligned to clearly defined adversarial objectives across cyber, physical, social engineering, and process attack surfaces
Designing and delivering end-to-end phishing and social engineering campaigns, including building and managing supporting infrastructure (domains, redirectors, email services, and landing pages), developing realistic pretexts, and creating payloads that accurately emulate real-world threat actor techniques
Deploying, operating, and optimizing Command and Control (C2) frameworks, such as Cobalt Strike, Nighthawk, or similar platforms, to support adversary emulation activities spanning initial access, post-exploitation, persistence, and lateral movement
Assessing the effectiveness of security controls by simulating advanced attacker behaviors and identifying opportunities to strengthen organizational defenses
Collaborating with security teams and stakeholders to translate findings into actionable recommendations and measurable security improvements
Other highly valued skills include:
Developing and enhancing custom tooling, offensive tradecraft, and defense-evasion techniques to emulate sophisticated threat actors and evaluate the effectiveness of security controls, detection, and response capabilities
Research, prototype, and execute innovative attack methodologies that advance adversary emulation capabilities and align with the evolving threat landscape
Demonstrate expertise in Red Team operations through hands-on security testing, offensive security research, any of these industry-recognized certifications such as OSCP, OSEP, CRTO, CRTP, CREST, CCSAS, CCRTS, are a plus
Leverage programming and scripting skills to build, customize, and automate tools that improve operational efficiency and support complex Red Team engagements
Apply considerable analytical thinking, creativity, and problem-solving skills to navigate technical challenges, adapt to dynamic environments, and deliver impactful security testing outcomes
You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, as well as job-specific technical skills.
This role is a Work from Home (WFH) opportunity.
Minimum Salary: $115,000
Maximum Salary: $155,000
The minimum and maximum salary/rate information above include only base salary or base hourly rate. It does not include any other type of compensation or benefits that may be available.
Barclays employees are eligible for a suite of competitive and generous employee benefits, including medical, dental and vision coverage, 401(k), life insurance, and other paid leave for qualifying circumstances.
This position is eligible for an incentive award.

