Skip to main content

Date live: Sep. 01, 2025

Business Area: Chief Information Security Office

Area of Expertise: Technology

Reference Code: JR-0000061307

Contract: Permanent

Join us as an Associate Penetration Tester to contribute to the identification and remediation of security vulnerabilities across our systems and applications.

In this role, you will be part of a dedicated cybersecurity team focused on assessing and strengthening the security posture of our digital infrastructure. You will support penetration testing activities, collaborate with experienced professionals, and gain exposure to a broad range of technologies and methodologies used in offensive security. This position is well-suited for you if you who have gained practical experience in security testing environments, demonstrated growth in technical capability, and are ready to take on increasingly multi-layered tasks within a structured and supportive setting.

To be successful as an Associate Penetration Tester, you should have experience with:

  • Penetration testing of Web based applications, REST based APIs, Network/Infra and/or Web based apps
  • Experience in writing clear and concise pen test reports.
  • Solid understanding of the Web and API OWASP Top 10 security risks, at minimum.

Some other highly valued skills may include:

  • Programming / scripting skills
  • CREST/OSCP/SANS or equivalent penetration testing certifications
  • Awareness of secure software development practices and common exploitation techniques.

You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job-specific technical skill.

This role will be based in Manchester.

Purpose of the role

To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks. 

Accountabilities

  • Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders.
  • Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies.
  • Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance.
  • Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance.
  • Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing methodologies and assurance activities.

Analyst Expectations

  • To perform prescribed activities in a timely manner and to a high standard consistently driving continuous improvement.
  • Requires in-depth technical knowledge and experience in their assigned area of expertise
  • Thorough understanding of the underlying principles and concepts within the area of expertise
  • They lead and supervise a team, guiding and supporting professional development, allocating work requirements and coordinating team resources.
  • If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L – Listen and be authentic, E – Energise and inspire, A – Align across the enterprise, D – Develop others.
  • OR for an individual contributor, they develop technical expertise in work area, acting as an advisor where appropriate.
  • Will have an impact on the work of related teams within the area.
  • Partner with other functions and business areas.
  • Takes responsibility for end results of a team’s operational processing and activities.
  • Escalate breaches of policies / procedure appropriately.
  • Take responsibility for embedding new policies/ procedures adopted due to risk mitigation.
  • Advise and influence decision making within own area of expertise.
  • Take ownership for managing risk and strengthening controls in relation to the work you own or contribute to. Deliver your work and areas of responsibility in line with relevant rules, regulation and codes of conduct.
  • Maintain and continually build an understanding of how own sub-function integrates with function, alongside knowledge of the organisations products, services and processes within the function.
  • Demonstrate understanding of how areas coordinate and contribute to the achievement of the objectives of the organisation sub-function.
  • Make evaluative judgements based on the analysis of factual information, paying attention to detail.
  • Resolve problems by identifying and selecting solutions through the application of acquired technical experience and will be guided by precedents.
  • Guide and persuade team members and communicate complex / sensitive information.
  • Act as contact point for stakeholders outside of the immediate function, while building a network of contacts outside team and external to the organisation.

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.

More about working at Barclays