> Markdown version of [/jobs/ext/69921-senior-security-engineer-ciam-xdp](https://www.wearedevelopers.com/jobs/ext/69921-senior-security-engineer-ciam-xdp). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - CIAM XDP - **Company:** Barclays Bank PLC - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Software Applications, Software System Penetration Testing, Cloud Computing Security, Cryptographic Protocols, Hardware Security Module, Identity and Access Management, Public Key Infrastructure, Aws Command Line Interface (CLI), Customer Identity Access Management, Software Coding, Devsecops, Vulnerability Analysis, Microservices - **Published:** May 31, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/37812966/ ## About the Role objectives, security policies, and regulatory requirements.Develop, implement, and maintain Identity and Access Management (IAM) solutions and systems.QualificationsExperience across configuration and integration with Hardware Security Module (HSM) and AWS Secrets Manager (ASM) tooling, certificate lifecycle management (e.g., rotation, revocation), and automating security workflows.Experience using GitLab CI/CD pipelines, AWS CLI or Chef.Strong experience with Cloud Security, including AWS security controls, policies and automation, CLI tools, role-based and attribute-based access controls, cryptographic protocols, secure key lifecycle management, advanced threat modeling, SOC operations, securing microservices and APIs, DevSecOps best practices, vulnerability scanning, tools, approaches, vulnerability patching, and vendor management for security.Strong experience in penetration testing and hands-on coding in at least one of: JavaScript, Java, Python.Hands-on configuration, deployment and operation of ForgeRock COTS-based IAM solutions (e.g., PingGateway, PingAM, PingIDM, PingDS) with embedded security gates, HTTP header signing, access token and data-at-rest encryption, PKI-based self-sovereign identity, or open source.Assessment of key critical skills: risk and controls, change and transformation, business acumen, strategic thinking, digital and technology, and job-specific technical skills.LocationLondon office. #J-18808-Ljbffr ## Description Job OverviewSenior Security Engineer for CIAM at Barclays, responsible for developing, implementing, and maintaining cryptographic solutions, identity and access management (IAM) systems, and security controls for banking systems and sensitive information.ResponsibilitiesDevelop, implement, and maintain solutions that safeguard banking systems and sensitive information.Provide subject matter expertise on security systems and engineering patterns.Develop and implement protocols, algorithms, and software applications to protect sensitive data and systems.Manage and protect secrets, ensuring secure generation, storage, and usage.Execute audits to monitor, identify, and assess vulnerabilities in the bank's infrastructure and software.Support response to potential security breaches.Identify advancements to support innovation and adoption of new cryptographic technologies and techniques.Collaborate with developers and security teams across the bank to align cryptographic solutions with business ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)