Overview
In this role you will help secure Barclays’ AI-driven solutions and broader technology stack. You will design and review secure-by-design architectures, focusing on Gen AI, cloud and data protection, while collaborating with cross-functional teams to strengthen risk posture. You will drive security governance, incident readiness, and change oversight to enable secure innovation across transformative initiatives. This is a hands-on role at the frontier of AI, cloud security and risk management with impact on the bank’s digital ecosystem.
Responsibilities
- Conduct security risk assessments and threat modeling across change lifecycles to identify vulnerabilities and embed compensating controls.
- Provide security input early in business plans and technology change designs to enable DevSecOps and shift-left practices.
- Perform security reviews of prospective 3rd party products and services in collaboration with CISO/CIO and product teams.
- Transfer residual risks to the business as required by the risk framework and support incident response and investigations with security insights.
- Contribute to the development and maintenance of security policies, standards, and procedures in line with risk tolerance and regulatory requirements.
- Lead or contribute to complex analysis using data from multiple sources and communicate complex information to stakeholders.
- Model and influence decision-making, policy development and governance in security-related change programs.
- Demonstrate leadership behaviours where applicable, coaching teams to improve security controls and risk management.
Key requirements
- Strong knowledge of AI security architecture and secure-by-design implementation
- Understanding of Gen AI, LLM threats (prompt injection, data leakage, model misuse)
- Expertise in cloud security, SaaS and data protection across modern platforms
- Experience in AI governance and risk management frameworks
- Exposure to conversational AI, contact center tech or digital channels
- Awareness of AI observability, monitoring and assurance practices
- Collaborative and cross-functional communication
- Influencing stakeholders to adopt secure designs
- Analytical and problem-solving mindset
- AI security architecture
- Security reviews and governance for AI systems
- Cloud security (across platforms)
…
