Enterprise Security Posture Management (espm) Lead

Barclays

Whippany, NJ, US
Base: $175,000 - $225,000; bonus/equity: eligible ...
On-site
Cybersecurity
Cloud security
Api security
Barclays is seeking an Enterprise Security Posture Management (ESPM) Lead to enhance its cyber defense capabilities by identifying and addressing vulnerabilities across its systems. This role involves developing a strategic function within the CISO organization, focusing on modernizing security practices and ensuring compliance with industry standards

Job Summary

  • Establish and operationalize a strategic Enterprise Security Posture Management (ESPM) function within the CISO organization.
  • Architect, implement, and continuously enhance the organization’s security posture, embedding security throughout the technology lifecycle.
  • Create an integrated ESPM practice delivering actionable insights, orchestrating remediation, and providing executive visibility into security posture.

Matching Summary

Match Score: 85

Barclays is seeking an Enterprise Security Posture Management (ESPM) Lead to enhance its cyber defense capabilities by identifying and addressing vulnerabilities across its systems. This role involves developing a strategic function within the CISO organization, focusing on modernizing security practices and ensuring compliance with industry standards.

Salary

Base: $175,000 - $225,000; Bonus/Equity: Eligible for incentive award; Benefits: Medical, dental, vision, 401(k), life insurance, paid leave

Skills & Requirements

Must-have

  • Cybersecurity
  • Cloud security
  • API security
  • Vulnerability mitigation
  • Threat exposure reduction
  • Risk-based prioritization models
  • Actionable insights
  • Remediation orchestration

Nice-to-have

  • Financial services experience
  • MITRE ATT&CK/CTID
  • CISA Secure-by-Design
  • NIST CSF 2.0/CRI Profile
  • DORA/FFIEC exposure frameworks
  • Data-driven dashboards

Key Requirements

  • Experience implementing CSPM, CNAPP, SSPM, and API security solutions
  • Experience with cloud architectures (AWS, Azure, GCP)
  • Experience with attack paths, adversary emulation, and continuous validation
  • CISSP, OSCP, or cloud security specialist credentials

Work Rights

Not specified

Tailored Resume

Cover Letter