Security Consultant

Company: Barclays
Apply for the Security Consultant
Location: Glasgow
Job Description:

Overview

In this role you will help secure Barclays’ AI-driven solutions and broader technology stack. You will design and review secure-by-design architectures, focusing on Gen AI, cloud and data protection, while collaborating with cross-functional teams to strengthen risk posture. You will drive security governance, incident readiness, and change oversight to enable secure innovation across transformative initiatives. This is a hands-on role at the frontier of AI, cloud security and risk management with impact on the bank’s digital ecosystem.

Responsibilities

  • Conduct security risk assessments and threat modeling across change lifecycles to identify vulnerabilities and embed compensating controls.
  • Provide security input early in business plans and technology change designs to enable DevSecOps and shift-left practices.
  • Perform security reviews of prospective 3rd party products and services in collaboration with CISO/CIO and product teams.
  • Transfer residual risks to the business as required by the risk framework and support incident response and investigations with security insights.
  • Contribute to the development and maintenance of security policies, standards, and procedures in line with risk tolerance and regulatory requirements.
  • Lead or contribute to complex analysis using data from multiple sources and communicate complex information to stakeholders.
  • Model and influence decision-making, policy development and governance in security-related change programs.
  • Demonstrate leadership behaviours where applicable, coaching teams to improve security controls and risk management.

Key requirements

  • Strong knowledge of AI security architecture and secure-by-design implementation
  • Understanding of Gen AI, LLM threats (prompt injection, data leakage, model misuse)
  • Expertise in cloud security, SaaS and data protection across modern platforms
  • Experience in AI governance and risk management frameworks
  • Exposure to conversational AI, contact center tech or digital channels
  • Awareness of AI observability, monitoring and assurance practices
  • Collaborative and cross-functional communication
  • Influencing stakeholders to adopt secure designs
  • Analytical and problem-solving mindset
  • AI security architecture
  • Security reviews and governance for AI systems
  • Cloud security (across platforms)

Posted: September 17th, 2026