Jobs
>
London

    Workplace Security Engineer - London, United Kingdom - Starling Bank

    Default job background
    Full time
    Description

    At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology.

    Engine is Starling's software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and a year ago we split out as a separate business.

    Starling Bank has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling's success.

    We draw upon our experience as knowledgeable bankers, and best in class technologists to become the chosen option for these banks, and preferred partners for leading consultancies.

    As a company, everyone is expected to roll up their sleeves to help deliver great outcomes for our clients. We are an engineering led company and we're looking for someone who will be excited by the potential for Engine's technology to transform banking in different markets around the world.

    Hybrid Working

    We have a Hybrid approach to working here at Engine - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. We don't like to mandate how much you visit the office and work from home, that's to be agreed upon between you and your manager.

    About Engineering at Engine by Starling -

    Engine by Starling engineers are excited about helping us deliver new features, regardless of what their primary tech stack may be. Hear from the team in our latest Blog or our case studies with Women in Tech.

    We are looking for engineers at all levels to join the team. We value people being engaged and caring about customers, caring about the code they write and the contribution they can make to banking around the world. People with a broad ability to apply themselves to a multitude of problems and challenges, who can work across teams do great things here at Engine, to continue changing banking for good.

    About the Role

    As a Workplace Security Engineer at Engine, you'll be working on company-facing security, helping to keep our staff safe and productive and our systems secure and compliant.

    You'll be working on projects covering identity and access management, endpoint security, office infrastructure, data loss prevention, security hardening, compliance reviews, and more. It's a very varied role with lots of close interaction with the infrastructure, security engineering, cross cutting and compliance teams.

    What you'll get to do:

  • You will be responsible for safeguarding our systems, applications, and data by ensuring secure user access, authentication, and authorisation mechanisms are in place
  • Manage IAM with Okta Identity Engine, create access control policies, ensure proper implementation of least privilege and RBAC across internal and SaaS applications
  • Manage security within Google Workspace and our email security platform, including initiatives such as establishing a secure configuration posture validating against CIS Benchmarks
  • Manage security controls across our MacOS estate, including MDM configuration profiles
  • Wherever possible, deploy and manage systems with Infrastructure as Code and other automation to minimise configuration-by-clicking
  • Work in a fast paced environment. We don't release out-of-hours, we deploy during the day using safe methods that do not cause impact
  • Perform regular security assessments and audits to identify risks and vulnerabilities, triage found risks appropriately, then design controls to implement as corrective actions
  • Work with the compliance team to conduct third party SaaS security reviews and support other compliance initiatives such as SOC 2, ISO27001 and PCI-DSS
  • Collaborate with infrastructure, security engineering, cross cutting and compliance teams on ongoing projects
  • Lead incident response efforts, including investigation and remediation of security breaches
  • Support our internal security awareness and training programs
  • Spearhead workplace security initiatives, plan projects and track their progress
  • Develop services for the future, automating and simplifying them, as well as making them more robust and secure using Infrastructure as Code where possible
  • SaaS vendors constantly release new features - you will help to keep up and preferably stay ahead with our own feature requests to them
  • Keeping abreast of new technologies and changes in the industry
  • We provide a 24x7 global service. As a SME you might be called to help in exceptional circumstances.
  • Requirements

    What skills are essential:

  • Strong understanding of identity federation (SAML, OAuth, OpenID Connect, etc.)
  • Experience with Identity and Access Management policy application and enforcement
  • Strong understanding of standard corporate IT systems such as office networks, physical security systems, email and DNS configuration, file sharing systems, etc
  • Experience designing, implementing, and managing IAM solutions
  • Experience with Infrastructure as Code and infrastructure provisioning tools (Cloudformation, Terraform).
  • Experience as an administrator of various enterprise SaaS applications
  • Experience independently managing short and long term projects
  • Experience with creating automations, using a scripting language like Python
  • Good discipline with regard to the effective and safe testing and release of changes
  • What skills are desirable:

  • Experience with SaaS security (Google Workspace, Atlassian, etc.)
  • Experience with Zero Trust security (MTLS, SCEP)
  • Hands-on experience as an administrator on some or all of the following types of tools: EDR, MDM, SIEM, Okta, Google Workspace, EntraID solutions
  • Knowledge of security and compliance frameworks like NIST, SOC2, ISO270001, PCI-DSS
  • Experience performing risk assessments, gap assessments, and threat modelling
  • A strong understanding of networking concepts, application security, authentication & authorization and cloud security best practice
  • Strong knowledge of overall security concepts and best practices
  • Experience with cloud platforms such as AWS, GCP, Azure
  • Relevant security certifications such as Okta Certified Professional, Security+, ISC2 Certified in Cybersecurity preferred but not required
  • Interview process

    Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • Initial interview - ~45 minutes
  • Technical interview - 1 hours
  • Final Interview ~45 minutes
  • Benefits

  • 33 days holiday (including public holidays, which you can take when it works best for you)
  • An extra day's holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Incentives refer a friend scheme
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
  • You may be put off applying for a role because you don't tick every box. Forget that While we can't accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren't sure if you're 100% there yet, get in touch anyway. We're on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we're proud to bring together people of all backgrounds and experiences who love working together to solve problems.

    Engine by Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.

    When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Engine by Starling and Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.


  • Maticmind S.p.A

    Security Engineer

    3 weeks ago


    Maticmind S.p.A United Kingdom

    Cerchiamo un Security Engineer per il nostro team di Roma. · Il/La candidato/a Il profilo ha maturato un'esperienza di almeno cinque anni, in contesti complessi ed articolati, di delivery di progetti e gestione di piattaforme di sicurezza di rete con particolare riguardo alle te ...

  • eFinancialCareers

    Security Engineer

    2 weeks ago


    eFinancialCareers London, United Kingdom

    Our client are a leading London trading and clearing house looking for a security engineer to join them within the cyber security team. Our client maintain critical national infrastructure and you will be responsible for engineering and maintaining an effectiveand modern cyber se ...

  • eFinancialCareers

    Security Engineer

    3 weeks ago


    eFinancialCareers London, United Kingdom

    **Contract Length**: Initially 6 months · **Working Style**:Hybrid · - 2 days a week on site · **Key Experience Required**: · - Automation experience using technologies such as Ansible Tower · - 5 years relevant experience in IT security, including direct experience within a Secu ...

  • Jefferson Frank

    Security Engineer

    2 weeks ago


    Jefferson Frank London, United Kingdom

    _**Security Engineer - £70,000 - London (Hybrid)**_ · We have partnered with a leading financial services organisation that has an established hybrid environment with both AWS and On-Prem. They are looking for a Security Engineer to join a well established team. · This organisati ...

  • Yolk Recruitment Ltd

    Security Engineer

    3 weeks ago


    Yolk Recruitment Ltd London, United Kingdom

    **Security Engineer | Cardiff | Hybrid (2 days per week in office) | Up to £100,000 | Challenger Bank** · Yolk Recruitment are working with a disrupting fintech organisation based in Cardiff looking to expand their Cyber Security function. Their tech team operate a hybrid working ...

  • Arthur

    Security Engineer

    1 week ago


    Arthur London, United Kingdom

    Security Engineer / Architect - London - 1 day a week in offcie - Azure, VM Ware, (Python, Golang, Rust, Perl, Bash, PowerShell, etc.), Linux, Windows · We are a newly formed function who has an exciting future in helping shape the digital strategy for the international business ...

  • Arthur

    Security Engineer

    3 weeks ago


    Arthur London, United Kingdom

    Security Engineer - London - Remote - Azure, VM Ware, (Python, Golang, Rust, Perl, Bash, PowerShell, etc.), Linux, Windows · We are a newly formed function who has an exciting future in helping shape the digital strategy for the international business whilst working closely with ...

  • Mpro Recruitment Limited

    Security Engineer

    3 weeks ago


    Mpro Recruitment Limited London, United Kingdom Full time

    Job Details · We are recruiting for a Security Engineer/Technician to join our extensive network of clients looking for Security Engineers in South East London · We are looking for someone with a strong background in installing and servicing CCTV, Access Control and Intruder Alar ...

  • eFinancialCareers

    Security Engineer

    3 weeks ago


    eFinancialCareers London, United Kingdom

    You will have a solid background working within a busy IT team; experience in designing and implementing technical solutions around security, supporting all aspect of the Security mainframe, SOC, monitoring tools and future developments. · KEY REQUIREMENTS: · - Be familiar with N ...

  • Net2Source Global Workforce Solutions Ltd

    Security Engineer

    3 days ago


    Net2Source Global Workforce Solutions Ltd London, United Kingdom

    **Role · - Security Engineer(DevSecOps)** · **Duration · - 6 Months (Extendable)** · **Location: London (hybrid working contractor expected 2 days per week minimum)** · **_JD :_** · Work in a cross-functional team of skilled engineers building software to manage infrastructure, l ...

  • Berkeley Square IT

    Security Engineer

    2 days ago


    Berkeley Square IT London, United Kingdom

    **Security Engineer - Compliance - London - Salary Negotiable ** This amazing opportunity offers some exceptional rumination packages, the best I have ever seen · My client is looking for curious, innovative, passionate, and creative Security Compliance Engineers to join our quic ...

  • eFinancialCareers

    Security Engineer

    1 week ago


    eFinancialCareers London, United Kingdom

    TEKsystems is currently engaged with a financial services company to source a Security Engineer. · **Role Responsibilities & Key Accountabilities**: · - Monitors and assesses threats, dealing with escalations for more complex threats, and taking appropriate action or escalating a ...

  • Nigel Frank International

    Security Engineer

    3 days ago


    Nigel Frank International London, United Kingdom

    Security Engineer - Sentinel/O365 - London - Up to £100k · My client is a global investment management company who have offices across the UK & America. Over the last decade, they've grown from being a company of 2, into now, a company which proudly employees 30 people across the ...


  • Context Recruitment Limited London, United Kingdom

    IT Security Engineer - up to £70,000 PA · London, Buckinghamshire or Oxfordshire, hybrid working (3 days per week WFH and 2 days at any site location), potential travel between sites may be required. · Experienced SecOps Engineer sought by a well-known and public-facing organisat ...


  • Precise Placements Shoreditch, United Kingdom

    **IT Security Engineer - CISSP, CEH, NIST, ISO27001, SIEM** · A midsized law firm client of ours are currently looking to take on a new IT Security Engineer (CISSP, CEH, NIST, ISO27001, SIEM) to join their team on a permanent basis. They are a firm of 800 users globally but a sma ...


  • Understanding Recruitment London, United Kingdom

    **Cloud Security Engineer** · A new and exciting opportunity has arisen for an experienced Cloud Security Engineer to join a public sector organisation based in London with a hybrid working environment. You will have the opportunity to come into the organisation and grow and deve ...


  • Circle Recruitment London, United Kingdom

    **Network Security Engineer - Central London - Hybrid** · **Paloalto - Palo alto - Fortinet - Extreme Networks - Cato - Network - Security - Engineer - Administrator - Network Engineer - Network Administrator - Network Security - Firewall - WAN - LAN - Wireless** · This role offe ...


  • Comtecs Ltd London, United Kingdom

    Information Security Engineer / Information Security SME - Network Security, Perimeter Defences, Palo Alto Firewalls, Azure / AWS Cloud, SIEM, DLP, IPS/IDS, WAF; NIST, CSA, HIPAA; CISM, CISSP. Permanent, London/Remote (Hybrid, 3/2). £75k - £80k +Bonus +Benefits · Information Secu ...


  • GerrardWhite London, United Kingdom

    **Security Engineer Lead - Global Insurance Organisation - MS/Azure Env - City/Hybrid - Perm** · Join a leading global insurance organisation as a Security Engineering Lead during a time of extensive transformation which includes the development and deployment of a new Azure Infr ...


  • Search Consultancy London, United Kingdom

    **Fire & Security Engineer** · **£40,000** · **London** · £40,000 is on offer for a Fire & Security Engineer located in London to provide Installation on Fire Alarms, Intruder Alarms, CCTV and Access Control within the M25 area. · As a Fire & Security Engineer you will be joining ...