Senior Security Engineer - CIAM XDP

Barclays Bank PLC
London, UK
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Software Applications Software System Penetration Testing Cloud Computing Security Cryptographic Protocols Hardware Security Module Identity and Access Management Public Key Infrastructure Aws Command Line Interface (CLI)
+5 more
Customer Identity Access Management Software Coding Devsecops Vulnerability Analysis Microservices

Job description

Job OverviewSenior Security Engineer for CIAM at Barclays, responsible for developing, implementing, and maintaining cryptographic solutions, identity and access management (IAM) systems, and security controls for banking systems and sensitive information.ResponsibilitiesDevelop, implement, and maintain solutions that safeguard banking systems and sensitive information.Provide subject matter expertise on security systems and engineering patterns.Develop and implement protocols, algorithms, and software applications to protect sensitive data and systems.Manage and protect secrets, ensuring secure generation, storage, and usage.Execute audits to monitor, identify, and assess vulnerabilities in the bank’s infrastructure and software.Support response to potential security breaches.Identify advancements to support innovation and adoption of new cryptographic technologies and techniques.Collaborate with developers and security teams across the bank to align cryptographic solutions with business

Requirements

objectives, security policies, and regulatory requirements.Develop, implement, and maintain Identity and Access Management (IAM) solutions and systems.QualificationsExperience across configuration and integration with Hardware Security Module (HSM) and AWS Secrets Manager (ASM) tooling, certificate lifecycle management (e.g., rotation, revocation), and automating security workflows.Experience using GitLab CI/CD pipelines, AWS CLI or Chef.Strong experience with Cloud Security, including AWS security controls, policies and automation, CLI tools, role-based and attribute-based access controls, cryptographic protocols, secure key lifecycle management, advanced threat modeling, SOC operations, securing microservices and APIs, DevSecOps best practices, vulnerability scanning, tools, approaches, vulnerability patching, and vendor management for security.Strong experience in penetration testing and hands-on coding in at least one of: JavaScript, Java, Python.Hands-on configuration, deployment and operation of ForgeRock COTS-based IAM solutions (e.g., PingGateway, PingAM, PingIDM, PingDS) with embedded security gates, HTTP header signing, access token and data-at-rest encryption, PKI-based self-sovereign identity, or open source.Assessment of key critical skills: risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, and job-specific technical skills.LocationLondon office. #J-18808-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on apply4u.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:07 min

Transitioning architecture to microservices at Netflix

Steve Upton Steve Upton · WWC 2022

2:33 min

Defining hybrid development and no-code software paradigms

Mark Piller · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all