Senior Digital Forensics and Incident Response Analyst

Barclays Bank PLC
Knutsford, UK
about 1 month ago
Apply on jobs.theguardian.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Data Analysis Apple Mac Systems Network Analysis Cloud Computing Security Cyber Security Information Leak Prevention Linux Digital Forensics Monitoring of Systems Phishing Security Information and Event Management Traffic Analysis
+3 more
Data Logging Malware Cybercrime

Job description

Join us as a Senior DFIR (Digital Forensics and Incident Response) Analyst at Barclays, where you will play a critical role within the Security Operations Centre, protecting the organisation from cyber threats and security incidents. You will lead the investigation of complex cyber security events, applying digital forensic techniques to identify, contain, and remediate threats while helping to strengthen Barclays’ overall cyber resilience.

Working alongside cyber security, infrastructure and technology teams, you will investigate a broad range of security incidents, including phishing attacks, malware infections, endpoint compromise and external cyber threats. You will collect and analyse forensic evidence, provide technical expertise during incident response activities and support continuous improvements to Barclays’ detection and response capabilities., To monitor the performance of operational controls, implement and manage security controls and consider lessons learnt in order to protect the bank from potential cyber-attacks and respond to threats., * Management of security monitoring systems, including intrusive prevention and detection systems, to alert, detect and block potential cyber security incidents, and provide a prompt response to restore normal operations with minimised system damage.

  • Identification of emerging cyber security threats, attack techniques and technologies to detect/prevent incidents, and collaborate with networks and conferences to gain industry knowledge and expertise.
  • Management and analysis of security information and event management systems to collect, correlate and analyse security logs, events and alerts/potential threats.
  • Triage of data loss prevention alerts to identify and prevent sensitive data for being exfiltrated from the banks network.
  • Management of cyber security incidents including remediation & driving to closure.

Assistant Vice President Expectations

  • To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions/ business divisions.
  • Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes
  • If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L - Listen and be authentic, E - Energise and inspire, A - Align across the enterprise, D - Develop others.
  • OR for an individual contributor, they will lead collaborative assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will identify new directions for assignments and/ or projects, identifying a combination of cross functional methodologies or practices to meet required outcomes.
  • Consult on complex issues; providing advice to People Leaders to support the resolution of escalated issues.
  • Identify ways to mitigate risk and developing new policies/procedures in support of the control and governance agenda.
  • Take ownership for managing risk and strengthening controls in relation to the work done.
  • Perform work that is closely related to that of other areas, which requires understanding of how areas coordinate and contribute to the achievement of the objectives of the organisation sub-function.
  • Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategy.
  • Engage in complex analysis of data from multiple sources of information, internal and external sources such as procedures and practises (in other areas, teams, companies, etc).to solve problems creatively and effectively.
  • Communicate complex information. ‘Complex’ information could include sensitive information or information that is difficult to communicate because of its content or its audience.
  • Influence or convince stakeholders to achieve outcomes.

All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship - our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset - to Empower, Challenge and Drive - the operating manual for how we behave.

Requirements

  • Ability to apply digital forensic principles relating to evidence collection, preservation, and analysis.
  • Working knowledge of Windows, Linux, and Mac operating systems, with the ability to interpret system-level artefacts and support complex forensic investigations
  • Proven experience investigating and responding to cyber security incidents within large and complex enterprise environments including the ability to analyse logs, alerts, and artefacts from multiple security controls to determine the scope and impact of incidents

Some other highly valued skills may include:

  • Experience using Endpoint Detection and Response (EDR) technologies and analysing endpoint-level security telemetry during incident investigations
  • Knowledge of network analysis concepts, traffic analysis and common attack behaviours.
  • Understanding of malware analysis concepts, cloud security principles and common cloud logging sources to support investigations across hybrid enterprise environments

You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen, strategic thinking and digital and technology, as well as job-specific technical skills.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.theguardian.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:18 min

Technical roles and digitalization scale at Finance Informatic

Alexander Weißhaupt Alexander Weißhaupt +3 · World Congress 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all