Jobs
>
London

    Security Engineer - London, United Kingdom - Starling Bank

    Default job background
    Full time
    Description

    At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology.

    Engine is Starling's software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and a year ago we split out as a separate business.

    Starling Bank has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling's success.

    We draw upon our experience as knowledgeable bankers, and best in class technologists to become the chosen option for these banks, and preferred partners for leading consultancies.

    As a company, everyone is expected to roll up their sleeves to help deliver great outcomes for our clients. We are an engineering led company and we're looking for someone who will be excited by the potential for Engine's technology to transform banking in different markets around the world.

    Hybrid Working

    We have a Hybrid approach to working here at Engine - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. We don't like to mandate how much you visit the office and work from home, that's to be agreed upon between you and your manager.

    About Engineering at Engine by Starling -

    As a Security Engineer at Engine, you'll be working on helping to keep our infrastructure secure and compliant and our staff safe and productive.

    You'll be working on projects covering identity and access management, endpoint security, office infrastructure, data loss prevention, security hardening, compliance reviews, and more. It's a very varied role with lots of close interaction with the infrastructure, security engineering, cross cutting and compliance teams.

    Engine by Starling engineers are excited about helping us deliver new features, regardless of what their primary tech stack may be. Hear from the team in our latest Blog or our case studies with Women in Tech.

    We are looking for an experienced Senior/Staff level Security Engineer to join our growing Security Engineering team, working closely with the GRC & compliance team and the various Engine Technology teams to make sure security is at the heart of all our technical processes. Your place within the team will depend on your individual strengths and interests.

    This role will cover a wide array of security areas across our SaaS cloud environments, as well as corporate domains & internal infrastructure and will require a skilled individual to spearhead efforts in fortifying both infrastructure and application platforms, against potential threats.

    What you'll get to do?

  • Collaborate with stakeholders to define our Google Cloud security architecture (Cloud identity, runtime security, security posture)
  • Create security tooling to enhance our specific security landscape
  • Be part of the team responsible for safeguarding our systems, applications, and data by ensuring secure user access, authentication, and authorisation mechanisms are in place
  • Help us to stay nimble by building compliance and security control automations
  • Drive security infrastructure deployments across our growing environments
  • Perform regular security assessments, audits and architecture design reviews to identify risks and vulnerabilities, triage found risks appropriately and improvements then design controls to implement as corrective actions
  • Lead incident response efforts, including investigation and remediation of security breaches
  • Support our internal security awareness and training programs and advocating the DevSecOps mindset that we have created across our technology teams
  • Requirements

    What skills are essential:

  • You have an in-depth knowledge of security principles, technologies, and best practices, threat detection and mitigation strategies
  • Mature understanding and experience with cloud security architecture (AWS, Google Cloud) with a proven track record
  • Excellent problem-solving, communication and active listening skills with an innate passion for security
  • A proactive approach to staying updated with the latest security threats, vulnerabilities, and mitigation techniques
  • Strong programming skills, in security we write our own scripts for automation in Python, Go and other languages while contributing to open-source tools so we can utilise them
  • What skills are desirable:

  • Hands on experience taking your company through security and compliance frameworks like NIST, SOC2, ISO270001, PCI-DSS
  • Experience with Infrastructure as Code and infrastructure provisioning tools (Cloudformation, Terraform)
  • Expertise in Kubernetes, securing clusters and meshes (Cilium is preferable), networking best practices and RBAC implementation (CKA, CKS qualifications are a plus)
  • Container security knowledge including container image provenance ( Sigstore, Notary) with an in-depth knowledge of container runtimes
  • Strong understanding of network protocols & practices, firewalls, intrusion detection/prevention systems and WAFs
  • Experience securing code reviews and security approvals
  • Experience in Cryptography management & enhancements
  • Relevant security certifications such as ISC2 CC, CISSP, CCSP, CISM, AWS Security Specialist or GCP Professional Cloud Security Engineer
  • Our Interview process

    Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • Initial interview with an Engineer - ~45 minutes
  • Take home technical test to be discussed in the next interview
  • Technical interview with some Engineers - hours
  • Final interview with our CTO / deputy CTO ~45 minutes
  • Benefits

  • 33 days holiday (including public holidays, which you can take when it works best for you)
  • An extra day's holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Incentives refer a friend scheme
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
  • You may be put off applying for a role because you don't tick every box. Forget that While we can't accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren't sure if you're 100% there yet, get in touch anyway. We're on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we're proud to bring together people of all backgrounds and experiences who love working together to solve problems.

    Engine by Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.

    When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Engine by Starling and Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.


  • Maticmind S.p.A

    Security Engineer

    1 week ago


    Maticmind S.p.A United Kingdom

    Cerchiamo un Security Engineer per il nostro team di Roma. · Il/La candidato/a Il profilo ha maturato un'esperienza di almeno cinque anni, in contesti complessi ed articolati, di delivery di progetti e gestione di piattaforme di sicurezza di rete con particolare riguardo alle te ...


  • Maticmind S.p.A United Kingdom

    Siamo il System Integrator leader in Italia. · Progettiamo, integriamo e gestiamo soluzioni tecnologiche innovative, grazie a competenze specialistiche in ambito Networking, Security, Unified Communications & Collaboration, Datacenter & Cloud e Application. · Siamo nati nel 200 ...

  • Context Recruitment Limited

    IT Security Engineer

    3 weeks ago


    Context Recruitment Limited London, United Kingdom

    IT Security Engineer - up to £70,000 PA · London, Buckinghamshire or Oxfordshire, hybrid working (3 days per week WFH and 2 days at any site location), potential travel between sites may be required. · Experienced SecOps Engineer sought by a well-known and public-facing organisat ...

  • eFinancialCareers

    Security Engineer

    4 weeks ago


    eFinancialCareers London, United Kingdom

    TEKsystems is currently engaged with a financial services company to source a Security Engineer. · **Role Responsibilities & Key Accountabilities**: · - Monitors and assesses threats, dealing with escalations for more complex threats, and taking appropriate action or escalating a ...

  • Berkeley Square IT

    Security Engineer

    3 weeks ago


    Berkeley Square IT London, United Kingdom

    **Security Engineer - Compliance - London - Salary Negotiable ** This amazing opportunity offers some exceptional rumination packages, the best I have ever seen · My client is looking for curious, innovative, passionate, and creative Security Compliance Engineers to join our quic ...

  • Precise Placements

    IT Security Engineer

    4 weeks ago


    Precise Placements Shoreditch, United Kingdom

    **IT Security Engineer - CISSP, CEH, NIST, ISO27001, SIEM** · A midsized law firm client of ours are currently looking to take on a new IT Security Engineer (CISSP, CEH, NIST, ISO27001, SIEM) to join their team on a permanent basis. They are a firm of 800 users globally but a sma ...


  • Kite Human Capital London, United Kingdom

    **Cyber Security Engineer - Malware Protection - McAfee - London** · Cyber Security Engineer with excellent Malware Protection experience is required by my client, a leading Financial Services company. · This is a permanent opportunity offering flexible hybrid working with 1 day ...


  • Jefferson Frank London, United Kingdom

    Cloud Security Engineer (AWS) - £65-80K - Multiple locations - Financial Services/Banking · Cloud Security Engineer (AWS) - £65-80K - Multiple locations - Financial Services/Banking · Our banking client, one of the world's largest and most respected financial institutions, is on ...


  • Computappoint London, United Kingdom

    **Job Title: **Security Engineer (ArcSight SME) · **Day Rate**: Excellent Day Rate - Inside IR35 · **IR35 Status**: Inside IR35 · **Contract Length**: Initial 6-months (likely to be extended multiple times). · **Hybrid Location**:2 days per week in Central London, 3 days remote. ...


  • Berkeley Square IT London, United Kingdom

    **Network Security Engineer** · **Permanent** · **Up to £200k** · **London/Hybrid** · Our Client, a Global Algorithmic Financial Trading company is looking for a ** Network Security Engineer** to join their team in their London office. A security product heavy background is essen ...


  • Camden Council London, United Kingdom

    **Cyber Security Engineer** · **_Are you an ambitious or aspiring Cyber Security Engineer looking for a new challenge?_** · - Camden Councilis building somewhere everyone can thrive, by making our borough the best place to live, work, study, and visit. Because we are not just hom ...


  • Search Consultancy Camden, United Kingdom

    **Security Service Engineer (Static - London)** · **£40,000** · **London (Site Based)** · A unique opportunity for a Security Service Engineer (CCTV / Access / Intruder) looking for a **Static / site based role in London. - University.** · As a Site Based - Security Service Engin ...


  • BCT Resourcing London, United Kingdom

    **Network Security Engineer** · **6 month contract** · **£500 - £550 per day** · One of our clients, an international banking group is looking for a Network Security Engineer to join their team in central London. · You'll be responsible for implementing, configuring, maintaining ...


  • Trust In Soda London, United Kingdom

    Senior Security Engineer · Contract: 6 months initially · Outside IR35 · Location - Remote · **Experience**: · - Understanding of Threat modelling and risk assessments · - Knowledge of secure coding principles (OWASP and OWASP mobile, SANS) · - Cloud Security Architecture of publ ...


  • Hays Specialist Recruitment Limited London, United Kingdom

    Cyber Security Engineer | London (Hybrid) · **Are you an ambitious or aspiring Cyber Security Engineer looking for a new challenge?** · Camden Council is building somewhere everyone can thrive, by making our borough the best place to live, work, study, and visit. Because we are n ...


  • Berkeley Square IT London, United Kingdom

    **Security Engineer - Flexible Working - Salary Flexible (depending on experience) - London** · This exciting opportunity offers the most lucrative rumination packages I have ever seen · My client is looking for someone who has at least 5 years of experience working in cyber secu ...


  • Pontoon London, United Kingdom

    **Mobile Security Engineer** (Contract)** · **Day Rate: £ Dependent on experience)** · **Duration: 6 Months (Possibility for extension)** · **Location: Hybrid/London (One day in office fortnightly)** · We are looking for a Mobile Application Security SME that is passionate in App ...


  • Huntress London, United Kingdom

    maintaining the Network and Security life cycle ensuring operational efficiency. You will plan and implement · security measures to protect all systems from cyber-attacks, hacking attacks, intrusion, infiltration, and · natural disasters. You will report directly to the IT Team L ...


  • eFinancialCareers London, United Kingdom

    Barclays is one of the world's largest and most respected financial institutions, with 329 years of success, quality, and innovation behind us. We offer careers that provide endless opportunity - helping millions of individuals and businesses thrive and creatingfinancial and digi ...


  • Client Server Ltd. Shoreditch, United Kingdom

    **Cyber Security Engineer / Tester (RedTeam OSCP) Hybrid WFH to £60k** · Are you a bright, ambitious STEM graduate with commercial Cyber Security experience? · You could be progressing your career at a rapidly expanding scale-up software house that is developing a highly complex ...