At a Glance
- Tasks: Lead proactive security initiatives to identify and reduce cyber vulnerabilities.
- Company: Join a leading bank's Proactive Defence team focused on cybersecurity.
- Benefits: Competitive salary, health benefits, and opportunities for professional growth.
- Other info: Dynamic work environment with strong career advancement potential.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: Experience in attack surface management and risk prioritisation is essential.
The predicted salary is between 70000 - 90000 £ per year.
Join our Proactive Defence team as an Enterprise Security Posture Management SME, leading capabilities across Attack Surface Management (ASM), Attack Path Management (APM), and Breach & Attack Simulation (BAS) within the CISO organization. You will drive a proactive, threat-informed approach to exposure management, helping the bank identify, prioritise, and reduce exploitable security risk through greater visibility, attack path analysis, and continuous control validation.
This role is critical to shifting from reactive vulnerability management to proactive exposure reduction by providing continuous visibility of the attack surface, mapping how attackers can move through the environment, and validating security controls through adversary simulation. In doing so, you will help the organization identify, prioritise, and reduce exploitable security risk in a way that is threat-informed, measurable, and directly tied to business impact.
To be successful in this role, you should have experience with:
- Attack surface discovery and asset attribution: ability to continuously identify internet-facing assets, shadow IT, domains, subdomains, certificates, cloud services, APIs, SaaS exposures, third-party-hosted assets, and assets with unclear ownership.
- Risk-based exposure prioritisation: ability to prioritise the most material exposures by combining exploitability, business criticality, asset ownership, threat intelligence, vulnerability data, and likelihood of attack.
- Threat-informed attack surface analysis: ability to enrich attack surface findings with attacker techniques, active exploitation trends, KEV data, offensive security teams findings, and sector-specific threat intelligence.
Highly Valued Skills For This Role Include:
- Hands-on experience with EASM/ASM platforms and using tools such as external attack surface management, CAASM, vulnerability management, cloud posture, and exposure management platforms.
- Cloud, identity, SaaS, CI/CD and API exposure knowledge: understanding of common attack surface risks across AWS, Azure, GCP, Entra ID, Active Directory, Kubernetes, APIs, internet gateways, and exposed management interfaces.
- Understanding of Breach and Attack Simulation techniques: ability to use BAS outputs to validate whether identified exposures are exploitable, test control effectiveness, simulate attacker behaviours, and support evidence-based prioritisation.
Location: Knutsford.
Purpose of the role: To keep our customers, clients, and colleagues safe by identifying cyber-vulnerabilities across the Bank, using a risk-based approach to prioritise them, and to drive effective remediation activity.
Accountabilities:
- Allocation of the correct risk rating and remediation prioritisation to a vulnerability based on industry standards for assessment, available threat intelligence concerning exploitation, the reachability of the host (or asset) and the value of the service(s) running on the impacted host.
- Development of vulnerability management operating model, policies and procedures to ensure consistency in vulnerability identification, remediation and reporting. Element owner of the Vulnerability Management Standard including Issues Management and Regulatory alignment.
- Communication of vulnerabilities to relevant parties including senior stakeholders, vendors, external security partners and affected business units using reports and dashboards and provide recommendations for improvement in vulnerability management practices.
- Collaboration with Threat intelligence and Cyber Operations teams to assess and contextualise exposure to latest threat trends and exploits and set appropriate remediation timescales.
- Definition of requirements and acceptance criteria for the implementation and maintenance of automation tools to streamline vulnerability management processes within operating systems and applications.
- Reporting of remediation status of Security Assurance Specialist team findings against Key Risk Indicators.
Vice President Expectations:
- To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/processes; deliver continuous improvements and elevate breaches of policies/procedures.
- When managing a team, define jobs and responsibilities, plan for the department’s future needs and operations, counsel employees on performance and contribute to employee pay decisions/changes. Lead a number of specialists to influence the operations of a department, in alignment with strategic and tactical priorities, while balancing short and long-term goals and ensuring that budgets and schedules meet corporate requirements.
- Demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver consistently excellent standards: Listen and be authentic, Energise and inspire, Align across the enterprise, Develop others.
- As an individual contributor, act as a subject-matter expert within own discipline and guide technical direction. Guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments, and train and coach less experienced specialists while providing information affecting long-term profits, organisational risks and strategic decisions.
- Advise key stakeholders, including functional leadership teams and senior management on functional and cross-functional areas of impact and alignment.
- Manage and mitigate risks through assessment, in support of the control and governance agenda.
- Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work your team does.
- Demonstrate comprehensive understanding of the organisation functions to contribute to achieving the goals of the business.
- Collaborate with other areas of work, for business-aligned support areas to keep up to speed with business activity and its strategies.
- Create solutions based on sophisticated analytical thought, comparing and selecting complex alternatives. Perform in-depth analysis with interpretative thinking to define problems and develop innovative solutions.
- Adopt and include the outcomes of extensive research in problem-solving processes.
- Seek out, build and maintain trusting relationships and partnerships with internal and external stakeholders to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes.
All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.
Enterprise Security Posture Management SME in Knutsford employer: hackajob
At Barclays, we pride ourselves on fostering a dynamic and inclusive work environment that empowers our employees to thrive. As an Enterprise Security Posture Management SME in Knutsford, you will benefit from a culture of continuous learning and professional development, alongside competitive remuneration and comprehensive benefits. Join us to make a meaningful impact in cybersecurity while collaborating with talented professionals dedicated to excellence and innovation.
StudySmarter Expert Advice🤫
We think this is how you could land Enterprise Security Posture Management SME in Knutsford
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just grab a coffee with someone who works in security. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Show off your skills! Create a portfolio or a personal project that highlights your expertise in attack surface management or breach simulation. This can really set you apart from other candidates when you're chatting with potential employers.
✨Tip Number 3
Prepare for interviews by brushing up on common questions related to security posture management. Think about how you can demonstrate your experience with risk-based exposure prioritisation and threat-informed analysis. Practice makes perfect!
✨Tip Number 4
Don't forget to apply through our website! We love seeing applications directly from passionate candidates. Make sure to tailor your application to highlight your relevant experience and how it aligns with our proactive defence approach.
We think you need these skills to ace Enterprise Security Posture Management SME in Knutsford
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Enterprise Security Posture Management role. Highlight your experience with attack surface management, risk prioritisation, and any relevant tools you've used. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about proactive defence and how your background makes you a perfect fit for our team. Don't forget to mention specific experiences that relate to the job description.
Showcase Your Technical Skills:In your application, be sure to showcase your hands-on experience with EASM/ASM platforms and any other relevant technologies. We love seeing candidates who can demonstrate their technical prowess and understanding of cloud and API exposure risks.
Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you'll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at hackajob
✨Know Your Stuff
Make sure you brush up on your knowledge of Attack Surface Management, Attack Path Management, and Breach & Attack Simulation. Be ready to discuss specific tools and platforms you've used, as well as any relevant experience with cloud services and APIs.
✨Showcase Your Problem-Solving Skills
Prepare to share examples of how you've identified and prioritised vulnerabilities in the past. Use the STAR method (Situation, Task, Action, Result) to structure your answers and demonstrate your analytical thinking and decision-making process.
✨Understand the Business Impact
Be ready to explain how your work in security posture management ties back to business objectives. Highlight your ability to communicate risks and remediation strategies to stakeholders, showing that you understand the bigger picture.
✨Ask Insightful Questions
Prepare thoughtful questions about the company's approach to security and how they measure success in this role. This shows your genuine interest and helps you assess if the company aligns with your values and career goals.