Bank Cyber Security Jobs: Do You Still Qualify in 2026?

10 min readBy Nathan House
The bar just moved, in finance too: JPMorgan, Wells Fargo, Stripe, Bridgewater and Coinbase logos above the shift from nice-to-have to requirement, with 37 postings, 30 employers and a $600K top salary

TL;DR — if you've only got 30 seconds

37 security postings from 30 banks, funds, fintechs and crypto firms now put AI use in the requirements, not the wishlist. JPMorgan, Wells Fargo, Amex, Morgan Stanley, Visa, Blackstone, Bridgewater among them.

Same requirement, two vocabularies. Fintechs name a frontier tool in 15 of 22 postings; banks in 5 of 15. Banks say "approved" and "validation"; fintechs say "Claude Code" and "production". Prepare for the one you're walking into.

AppSec is the widest door (14 of 37), and 12 of the 37 are base-level. This is not staff-and-above only.

Ceiling is Bridgewater Associates at $600,000, the highest in all 197 postings we track. Blackstone's CV standard: "several projects where you used AI", and you can walk through them.

The short answer

A lot of us in security assumed finance would be the last sector to move on AI. The banks are regulated, they're careful, and they don't tend to write "Claude Code" into a job advert. So when we published our FAANG piece, the question we got back was: fine for Apple and Google, but does any of this apply to a bank?

It does. We went back through our collection of AI-driven security job postings and pulled every one from a bank, a broker, a fund, a fintech or a crypto firm. That's 37 postings from 30 employers: JPMorgan, Morgan Stanley, Wells Fargo, American Express, Capital One, Visa, Blackstone, Bridgewater, Stripe, Block, Coinbase and 19 more. In every one of them, using AI sits in the requirements, not the "nice to have" list at the bottom.

So yes, the bar moved in finance too. Here's what we'll cover: what actually changed, the one genuine difference between banks and fintechs (it will change how you answer in an interview), which specialism is the widest door, and what it pays, up to the highest number in our whole collection.

One caveat before we start, because it shapes everything: a job advert tells you what a hiring manager wrote, not what the team does. Banks in particular use legally-reviewed templates. What we can measure is what they now ask for in public, and that is what you're judged against when you apply.

So let's start with what actually changed, because it's more specific than "they want AI now".

What changed: AI moved out of the "nice to have" box

If you've been reading job adverts for a couple of years, you'll have noticed AI language creeping into the bottom section, the "preferred" and "desirable" bit that nobody has to satisfy. That's where it lived, and you could ignore it.

The evidence says that's over. When we grade a posting for our jobs page, we only count it if the AI requirement sits under Responsibilities, Requirements or Qualifications, the things an employer won't hire without. Anything under "preferred" gets thrown out, however strong the wording.

Thirty-seven finance postings survived that bar. And I think the interesting part is how blunt some of them are. Visa's is probably my favourite line in the entire collection:

"AI is at the core of our work at Visa. We need you to be very proficient with AI for this role and not just use AI tools but understand how they work."

Not "familiarity with". Not "exposure to". Very proficient, and understand how they work. That's a requirement written by someone who has been let down by a candidate who said they used AI and turned out to mean they'd tried ChatGPT once.

Bridgewater's is the one that sets the ceiling, and I'll come back to the number. Their Staff AI Agentic Security Engineer is asked to:

"Design, develop, and deploy autonomous agents for threat detection, alert triage, vulnerability management, and incident response… Replace manual runbooks with intelligent agents that reason, act, and…"

Replace manual runbooks with agents. At a hedge fund. That sentence would have read as science fiction in a security job advert two years ago.

So the requirement is there. But here's what surprised us when we read all 37 side by side: banks and fintechs describe it in noticeably different language, and the difference is one you can use.

Banks vs fintechs: same requirement, two vocabularies

Read a bank's posting and a fintech's posting for what looks like the same role, and you'll spot it. Let me give you the two ends.

Wells Fargo, Senior Information Security Engineer:

"Demonstrate proficiency in using AI-assisted development and analysis tools (e.g., GitHub Copilot and approved code-centric agents)"

JPMorgan, Manager of Security Engineering:

"Experience leading teams in the safe use of enterprise-authorized AI capabilities within the work environment for security engineering workflows, including validation habits…"

Now Block (Square and Cash App), Senior Security Engineer:

"Demonstrated fluency with AI-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot, or similar agentic coding tools) in real production work"

And Gusto, Senior Staff Security Engineer:

"Operate as an AI-native engineer, using Claude Code, MCP-driven tooling, and agentic workflows as a daily force multiplier across investigation, automation, and detection engineering."
Same requirement, two vocabularies: banks and funds name a frontier tool in 5 of 15 postings and use words like approved and validation; fintech and crypto name one in 15 of 22 and say Claude Code, MCP and production

The banks say approved, authorized, safe use, validation habits, data sensitivity. The fintechs name the frontier tools and want you already fluent.

We wanted to check that wasn't just four cherry-picked quotes, so we counted. Of the 15 postings from banks, brokers and funds, 5 name a frontier tool (Claude Code, Cursor or MCP) by name. Of the 22 from fintechs and crypto firms, 15 do. A fintech posting is roughly twice as likely to tell you which tool it expects you to know.

Who names the tool: fintech and crypto postings name a frontier tool in 15 of 22 cases, banks brokers and funds in 5 of 15

I want to be careful here, because the obvious next claim is "banks say approved, fintechs don't", and that one's false. Gusto and SoFi use the word "approved" too. The honest version is narrower: fintechs are far more likely to name the tool, and banks are more likely to wrap the requirement in governance language.

Why does that matter to you? Because it's two different interview answers. At a bank, the question underneath is can you use AI inside our sanctioned toolset without leaking data or trusting bad output? Your answer should be about validation, about which tools were approved where you worked, about a time you caught the model being wrong. At a fintech, the question is are you already fluent on the tools we use? Your answer should name them and describe production work.

Same requirement. Two vocabularies. Prepare for the one you're walking into.

Two interview answers: at a bank lead with validation, approved tools and where you caught the model being wrong; at a fintech name the tools and describe production work

Which raises the practical question: which door do you actually go through?

Which door: AppSec is the way in

Of the 37 finance postings that cleared our bar, here's the split by specialism:

Which door into finance security: application security 14 postings, cloud 7, detection and SOC 7, offensive 4, architecture 2, GRC 2, network 1

AppSec is the widest door, same as it was at FAANG, and for the same reason: reviewing code, triaging findings and chasing vulnerability classes across a big estate is exactly the work an agent accelerates. Banks have enormous codebases and enormous compliance pressure on them, so it makes sense that's where the requirement lands first.

The other number worth knowing, because a lot of us assume finance only hires senior people for this: 12 of the 37 are base-level roles. No "senior", no "staff", no "principal" in the title. Ten are senior, six are staff, four are leads, and a handful are director, VP or principal. The door isn't only open to people already inside.

The 37 finance postings by level: 12 base-level engineer, 10 senior, 6 staff, 4 lead, 3 director VP or principal, 1 manager

Where they are is more spread than FAANG: New York (6), remote (6), international (7, mostly London and Canada), and a scatter across Texas, California, Arizona, Maryland and North Carolina. If you're outside the US, finance is a genuinely better bet than big tech was.

So you know the discipline and you know the split. The hard part, as ever, is proving it.

How to prove it on a CV

This is where I think most of us will find it hardest, and the finance postings are unusually specific about what they want to see.

Blackstone put it more plainly than any employer in our collection. Their Threat Intelligence Analyst role asks for candidates who have:

"Demonstrated, hands-on experience applying AI tooling (such as LLMs and coding assistants) to real work, and can clearly speak to several projects where you used AI to automate or accelerate a task"

Several projects. Clearly speak to. That's a CV standard, and it's a good one. Not "familiar with AI". Not a certificate. Several things you built or automated, that you can walk through.

Lumin Digital has the harshest single bar we've seen anywhere, in two separate postings:

"At least 1 year of production experience with at least 2 agentic coding tools, such as Claude Code, Gemini, Cursor, Codex, AMP, or OpenCode."

A year. Two tools. In production. That's a clock, and it started for some people in 2024.

And Ridgeline names the thing that, to be honest, I think matters most:

"Hands-on, daily use of AI/LLM tooling, and the judgment to validate its output for correctness and risk. This is essential to the role."

The judgment to validate its output. Every serious posting in this set asks for that in some form, and it's the thing you can only get from having been let down by a model.

So, practically, three things:

Have several projects, and be able to walk through them. Blackstone's standard. "Built an agent that triages our SAST findings against exploitability criteria, cut the weekly review from a day to an hour" is a project. "Used Copilot" is not.

Match the vocabulary to the employer. At a bank, lead with validation and governance: which tools were sanctioned, how you checked the output, what you wouldn't let it touch. At a fintech, name the tools and describe production use.

Name where it failed. Ridgeline's "judgment to validate" is the same thing Netflix asked for in our FAANG piece. An engineer who can say "we tried agents for X and it was worse, here's why" is demonstrably more useful than one who claims it works everywhere.

I'll give you ours, because the "judgment to validate" part isn't theoretical for us, and it's the story a bank interviewer actually wants to hear.

What that looks like in practice: our own receipts

StationX runs on an AI infrastructure platform we built called HAL: 1,400+ skills and commands, 1,281 utility scripts, 20 servers across six cloud providers, 27 categories of persistent memory. It's seven months of compounding work and it's the execution layer for most of the business.

On the security side we run a WordPress bug-bounty pipeline through the same setup, and that's where the honest half of the story lives, because it's the "judgment to validate" part that finance is asking for:

We deep-read a finding, logged it, put it on a dashboard, then discovered it was CVE-2025-12752, already patched in the version we'd read. A two-second duplicate check first would have killed it. The rule now is dupe-check before anyone reads code.

We proved a genuine unauthenticated SQL injection in a plugin with 300 installs. Real bug, real proof of concept, worth £0, below the install threshold that pays. The bug was never the constraint; the target selection was.

Agents are structurally blind to some bug classes. Missing-authorization flaws are 56% of the recent CVEs in our own mirror, and taint scanners cannot see them at all; they hunt dangerous sinks reached by dirty data, not checks that should exist and don't. We only found those by asking a different question, by hand.

That last one is exactly what Ridgeline means. The agent didn't replace the judgment about where to point it, and knowing where your tooling is blind is what separates someone who uses AI from someone who just runs it. If you're interviewing at a bank, that's the story they want.

And it's being paid for, in finance more than almost anywhere.

What it pays

Of the 37 finance postings, 24 publish a salary band. Split by sub-sector, the median top-of-band is about $200,000 at banks, brokers and funds, $225,000 at fintechs and $210,000 in crypto.

What it pays by sub-sector: Bridgewater ceiling $600K, fintech median $225K, crypto median $210K, banks and funds median $200K

The ceiling is Bridgewater Associates at $450,000 to $600,000 for that Staff AI Agentic Security Engineer, the one replacing manual runbooks with agents. It's the highest figure in our entire collection of 197 postings across 132 employers, higher than Anthropic, higher than Netflix. A hedge fund.

Below that, Block's platform security role tops out at $327,000, Gusto at $270,000, JPMorgan's senior lead at $260,000, Ridgeline's staff role at $256,000. The medians are a touch below FAANG's $227,000, but the spread is wider, and the top is a long way above.

All of which rests on us having read these properly, so here's what we did and where it's weakest.

How we know

Everything above comes from the actual adverts, so here's the method, and one limit I want to be straight about.

Every posting is on our jobs page with the original text, the salary, a screenshot where we captured one, and an archive.org snapshot where one exists. Thirty-five of the 37 have a screenshot. We graded each by hand against where the AI language sits: Responsibilities, Requirements or Qualifications counts; "preferred", "desirable" or "nice to have" doesn't, even when the wording is strong.

The limit: these were found, not measured. For our FAANG piece we swept all five careers boards and could tell you we'd read 403 of 743 listed postings. We didn't do that for finance. These 37 came from our general collector, which watches boards and aggregators for AI-driven security roles across every sector. So I can tell you every one of these is real, verbatim and current at capture. I can't tell you what fraction of all finance security postings they represent, and I won't pretend to.

What the 37 do establish is that at 30 named financial employers, for some teams, AI use has crossed from wish to requirement. That's a floor. Twenty-five of the 30 employers appear once, which tells you the pattern is broad rather than deep at any single firm, and I'd rather you knew that than inferred a company-wide policy from one advert.

What to do this week

If you want one of these roles:

  1. Work out which vocabulary you're walking into. Bank or fund: validation, sanctioned tools, data handling. Fintech or crypto: name the frontier tools, describe production use.
  2. Aim at AppSec if you're choosing a direction: 14 of 37, the widest door.
  3. Get to "several projects". Blackstone's bar. Build one thing that does real security work, measure it, and be able to walk through it.
  4. Write down where it failed. Ridgeline's "judgment to validate its output". Almost nobody includes it, and every serious posting asks for it.

Every finance listing quoted here, plus the other 160 from 102 more employers, is on our AI-Driven Cyber Security Jobs page, with the original advert text and archived snapshots, so you can read the requirements yourself rather than taking our word for the quotes.

Frequently asked questions

Do banks really require AI skills for cyber security jobs now?

Some teams do, in writing. Of 37 finance-sector security postings we hold from 30 employers, every one places AI use under Requirements, Responsibilities or Qualifications rather than "nice to have". That includes JPMorgan, Wells Fargo, American Express, Morgan Stanley, Visa, Blackstone and Bridgewater. It is not every security job at every bank, and 25 of the 30 employers appear once, so read it as a floor, not a company-wide policy.

Will AI replace cyber security jobs in banking?

Nothing in these adverts suggests replacement. Every posting still wants the fundamentals, cloud, application security, threat detection, incident response, and adds AI use on top. The requirement is being extended, not swapped. Bridgewater is advertising up to $600,000 for an engineer to build agents that replace manual runbooks; that is a job being created, not removed.

Is a fintech different from a bank for these roles?

Same requirement, different vocabulary. Fintech and crypto postings name a frontier tool (Claude Code, Cursor, MCP) in 15 of 22 cases; bank, broker and fund postings do so in 5 of 15. Banks are more likely to wrap it in governance language: "approved", "enterprise-authorized", "validation habits". Prepare for the interview you are walking into: validation and sanctioned tools at a bank, named tools and production use at a fintech.

Which cyber security specialism has the most AI-driven roles in finance?

Application security, with 14 of the 37. Cloud security and detection and SOC follow with 7 each, then offensive security with 4. Same pattern as at FAANG, and for the same reason: reviewing code and triaging findings across a large estate is where agentic tooling helps first.

Do I need to be senior to get one of these finance roles?

No. Of the 37 postings, 12 are base-level engineer roles with no "senior", "staff" or "principal" in the title. Ten are senior, six staff, four lead, and a handful are director, VP or principal. The door is not only open to people already inside.

What do AI-driven cyber security jobs in finance pay?

Of the 37 postings, 24 publish a band. Median top-of-band is about $200,000 at banks and funds, $225,000 at fintechs and $210,000 in crypto. The ceiling is Bridgewater Associates at $450,000 to $600,000 for a Staff AI Agentic Security Engineer, the highest figure across all 197 postings we track from 132 employers.

About the Author

Nathan House

Nathan House, Founder & CEO of StationX

Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.