Barclays logo

Penetration Tester

Barclays Manchester, England, United Kingdom

onsitefull-time
Posted Feb 3, 2026
  • Role & seniority

    • Penetration Tester (Senior/AVP-aligned expectations; team contributor with potential leadership involvement)
  • Stack/tools

    • End-to-end penetration testing across web, network, and mobile

    • CREST qualification (or working toward it)

    • Stakeholder engagement, SoWs, and clear security reporting

    • Exposure to scripting/programming; interest in AI security testing (nice-to-have)

  • Top 3 responsibilities

    • Perform comprehensive penetration tests (web, network, mobile) and identify vulnerabilities

    • Develop assessments, threat models, and remediation guidance; produce senior-level reports

    • Engage stakeholders and IT teams; refine testing methodologies and update security controls

  • Must-have skills

    • CREST qualification (or in progress) and proven end-to-end pentesting across multiple domains

    • Strong ability to communicate complex findings clearly to stakeholders

    • Experience delivering actionable security reports and remediation guidance

  • Nice-to-haves

    • Active participation in security community (CTFs, bug bounties, hackathons)

    • Experience with client or thick application testing; adherence to project timelines

    • Interest in AI security testing; familiarity with scripting

  • Location & work type

    • Location: Manchester, UK

    • Work type: not explicitly stated; role is based in Manchester with collaboration across stakeholders and teams

Full Description

Job Description Purpose of the role To identify potential vulnerabilities within the banks IT systems using penetration testing tools and techniques to ensure security of computer systems, applications, servers, and networks. Accountabilities Development and execution of assessments, audits, and threat models to identify vulnerabilities within the banks systems, applications and servers using penetration tools and techniques, and communicate key findings and recommendations to stakeholders. Collaboration with stakeholders and IT teams to identify emerging cyber-attack techniques, tools and technologies and to support the development of penetration testing methodologies. Development and maintenance of comprehensive documents and reports for senior stakeholders on penetration test findings, and remediation guidance. Collaboration with stakeholders to understand their security requirements and controls in business processes, application/services, to enhance overall security posture and assurance. Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing methodologies and assurance activities. Assistant Vice President Expectations To advise and influence decision making, contribute to policy development and take responsibility for operational effectiveness. Collaborate closely with other functions/ business divisions. Lead a team performing complex tasks, using well developed professional knowledge and skills to deliver on work that impacts the whole business function. Set objectives and coach employees in pursuit of those objectives, appraisal of performance relative to objectives and determination of reward outcomes If the position has leadership responsibilities, People Leaders are expected to demonstrate a clear set of leadership behaviours to create an environment for colleagues to thrive and deliver to a consistently excellent standard. The four LEAD behaviours are: L – Listen and be authentic, E – Energise and inspire, A – Align across the enterprise, D – Develop others. OR for an individual contributor, they will lead collaborative assignments and guide team members through structured assignments, identify the need for the inclusion of other areas of specialisation to complete assignments. They will identify new directions for assignments and/ or projects, identifying a combination of cross functional methodologies or practices to meet required outcomes. Consult on complex issues; providing advice to People Leaders to support the resolution of escalated issues. Identify ways to mitigate risk and developing new policies/procedures in support of the control and governance agenda. Take ownership for managing risk and strengthening controls in relation to the work done. Perform work that is closely related to that of other areas, which requires understanding of how areas coordinate and contribute to the achievement of the objectives of the organisation sub-function. Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategy. Engage in complex analysis of data from multiple sources of information, internal and external sources such as procedures and practises (in other areas, teams, companies, etc).to solve problems creatively and effectively. Communicate complex information. 'Complex' information could include sensitive information or information that is difficult to communicate because of its content or its audience. Influence or convince stakeholders to achieve outcomes. All colleagues will be expected to demonstrate the Barclays Values of Respect, Integrity, Service, Excellence and Stewardship – our moral compass, helping us do what we believe is right. They will also be expected to demonstrate the Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave. Join us as a Penetration Tester, to help protect our organisation and clients by identifying, validating, and clearly communicating security vulnerabilities before they can be exploited. This role sits within a collaborative security testing team and focuses on delivering high‑quality web, network, mobile, and client application assessments across a range of projects, while working closely with stakeholders to turn findings into meaningful action. To be successful as a Penetration Tester, you should have experience with: Holding a CREST qualification (or equivalent), or working towards one. Delivering end‑to‑end penetration testing across web, network, and mobile environments. Engaging with stakeholders, contributing to Statements of Work (SoW), and producing clear, actionable security reports. Some other highly valued skills may include: Participation in the penetration testing or wider security community (for example bug hunting, Hack The Box, CTFs, or hackathons). Exposure to client or thick application testing and experience working to agreed project timelines. An interest in emerging areas such as AI security testing, and familiarity with scripting or programming (no specific languages required). You may be assessed on the key critical skills relevant for success in role, such as risk and controls, change and transformation, business acumen strategic thinking and digital and technology, as well as job-specific technical skills. This role will be based in Manchester. Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self-disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the #1 Top Workplace in the area.

Penetration TestingVulnerability IdentificationThreat ModelingCyber-attack TechniquesSecurity ReportingStakeholder CollaborationRisk MitigationControl StrengtheningWeb TestingNetwork TestingMobile TestingClient Application AssessmentsCREST QualificationBug HuntingCTFsAI Security Testingmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.