SonicJobs Logo
Left arrow iconBack to search

Enterprise Security Posture Management (ESPM) Lead

Barclays
Posted 15 days ago, valid for 16 days
Location

Jefferson, CO 80456, US

Salary

$52.08 - $62.5 per hour

info
Contract type

Full Time

Life Insurance

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The role of Enterprise Security Posture Management (ESPM) Lead at Barclays involves identifying cyber-vulnerabilities and driving effective remediation activities to ensure safety for customers and colleagues.
  • Candidates should have significant experience in cybersecurity, particularly in cloud security, API security, and vulnerability mitigation, with a preference for those from financial services or regulated sectors.
  • The position requires the development of a vulnerability management operating model and involves collaboration with various teams to assess exposure to threats and set remediation timelines.
  • The salary for this position ranges from $175,000 to $225,000, and the role is located in Whippany, NJ.
  • Successful candidates will demonstrate strong leadership skills, strategic thinking, and the ability to influence across technology and business domains.

Job Description

Purpose of the role

To keep our customers, clients, and colleagues safe by identifying cyber-vulnerabilities across the Bank, using a risk-based approach to prioritise them, and to drive effective remediation activity. 

Accountabilities

  • Allocation of the correct risk rating and remediation prioritisation to a vulnerability based on industry standards for assessment, available threat intelligence concerning exploitation, the reachability of the host (or asset) and the value of the service(s) running on the impacted host.
  • Development of vulnerability management operating model, policies and procedures to ensure consistency in vulnerability identification, remediation and reporting. Element owner of the Vulnerability Management Standard including Issues Management and Regulatory alignment.
  • Communication of vulnerabilities to relevant parties including senior stakeholders, vendors, external security partners and affect business units using reports and dashboards and provide recommendations for improvement in vulnerability management practices.
  • Collaboration with Threat intelligence and Cyber Operations teams to assess and contextualise exposure to latest threat trends and exploits and set appropriate remediation timescales.
  • Definition of requirements and acceptance criteria for the implementation and maintenance of automation tools to streamline vulnerability management processes within operating systems and applications.
  • Reporting of remediation status of Security Assurance Specialist team findings against Key Risk Indicators.

Vice President Expectations

  • To contribute or set strategy, drive requirements and make recommendations for change. Plan resources, budgets, and policies; manage and maintain policies/ processes; deliver continuous improvements and escalate breaches of policies/procedures..
  • If managing a team, they define jobs and responsibilities, planning for the department’s future needs and operations, counselling employees on performance and contributing to employee pay decisions/changes. They may also lead a number of specialists to influence the operations of a department, in alignment with strategic as well as tactical priorities, while balancing short and long term goals and ensuring that budgets and schedules meet corporate requirements..
  • If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L – Listen and be authentic, E – Energise and inspire, A – Align across the enterprise, D – Develop others..
  • OR for an individual contributor, they will be a subject matter expert within own discipline and will guide technical direction. They will lead collaborative, multi-year assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will train, guide and coach less experienced specialists and provide information affecting long term profits, organisational risks and strategic decisions..
  • Advise key stakeholders, including functional leadership teams and senior management on functional and cross functional areas of impact and alignment.
  • Manage and mitigate risks through assessment, in support of the control and governance agenda.
  • Demonstrate leadership and accountability for managing risk and strengthening controls in relation to the work your team does.
  • Demonstrate comprehensive understanding of the organisation functions to contribute to achieving the goals of the business.
  • Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategies.
  • Create solutions based on sophisticated analytical thought comparing and selecting complex alternatives. In-depth analysis with interpretative thinking will be required to define problems and develop innovative solutions.
  • Adopt and include the outcomes of extensive research in problem solving processes.
  • Seek out, build and maintain trusting relationships and partnerships with internal and external stakeholders in order to accomplish key business objectives, using influencing and negotiating skills to achieve outcomes.

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave.

We're seeking an Enterprise Security Posture Management (ESPM) Lead to establish and operationalize a strategic function within our CISO organization. This is a unique opportunity to build a program from the ground up at a global financial services organization with over 90,000 employees. You will be responsible for architecting, implementing, and continuously enhancing the organization’s security posture. This role is central to accelerating the secure modernization of Barclays’ systems and applications, ensuring that security is embedded at every stage of the technology lifecycle. Your mission is to create an integrated ESPM practice that delivers actionable insights, orchestrates remediation across organizational boundaries, and provides the executive group with clear visibility into our security posture.

To be successful as in this role, you should have experience with:

· Cybersecurity, with direct exposure to cloud security, API security, vulnerability mitigation, or threat exposure reduction

· Implementing CSPM, CNAPP, SSPM, and API security solutions in large enterprises

· Cloud architectures (AWS, Azure, GCP), attack paths, adversary emulation, and continuous validation concepts

· Developing and operationalizing risk-based prioritization models for cloud and API exposures

· Ability to influence across technology, risk, and business domains, evaluative and communication abilities, with a focus on measurable outcomes

Some other highly valued skills may include:

· Experience in financial services or other regulated sectors

· MITRE ATT&CK/CTID, CISA Secure-by-Design, NIST CSF 2.0/CRI Profile, DORA/FFIEC exposure frameworks

· Certifications such as CISSP, OSCP, or cloud security specialist credentials

· Ability to build data-driven dashboards for exposure visibility and remediation governance

You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, as well as job-specific technical skills.

This role is located in Whippany, NJ.

Minimum Salary: $ 175,000

Maximum Salary: $ 225,000

The minimum and maximum salary/rate information above include only base salary or base hourly rate. It does not include any other type of compensation or benefits that may be available.

Barclays employees are eligible for a suite of competitive and generous employee benefits, including medical, dental and vision coverage, 401(k), life insurance, and other paid leave for qualifying circumstances.

This position is eligible for an incentive award.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.