At a Glance
- Tasks: Secure our cloud infrastructure and ensure compliance while collaborating with diverse teams.
- Company: Join Engine by Starling, a fast-growing fintech company with a focus on innovation.
- Benefits: Enjoy hybrid working, competitive salary, and opportunities for professional growth.
- Other info: Open culture that values collaboration and continuous learning.
- Why this job: Be at the forefront of cloud security in a dynamic and supportive environment.
- Qualifications: Experience in GCP security architecture and a passion for innovative solutions.
The predicted salary is between 63000 - 77000 £ per year.
At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology. Engine is Starling's software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and a year ago we split out as a separate business. Starling has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. The Engine technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling's success.
Our technologists are at the very heart of Engine and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be; innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture; you will find support in your team and from across the business, we are in this together!
Hybrid Working
We have a Hybrid approach to working here at Engine – our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person.
As a Security Engineer at Engine, you'll be working on helping to keep our infrastructure secure and compliant and our staff safe and productive. You'll be working on projects covering identity and access management, cloud and network security, vulnerability management, security monitoring, security hardening, compliance reviews, and more. It's a very varied role with lots of close interaction with the infrastructure, security engineering, cross-cutting and compliance teams.
We are looking for an experienced Senior / Staff level GCP Security Engineer to join our established Security Engineering team, working closely with Information Security, Infrastructure and the various Engine Technology teams to make sure security is at the heart of all our technical processes. As our subject matter expert, you will take ownership of engineering the security foundations of our Google Cloud Platform environment. This is a hands-on role for a specialist with a proven track record of designing, building, and automating security controls specifically for GCP, including hardened GKE clusters.
As a GCP Security Engineer, you will:
- Collaborate with stakeholders to define our Google Cloud security architecture (cloud identity, runtime security, security posture).
- Design, document, build and maintain a secure and scalable infrastructure on GCP using Infrastructure as Code.
- Be part of the team responsible for safeguarding our systems, applications and data by ensuring secure user access, authentication and authorisation mechanisms are in place.
- Engineer and automate technical controls within GCP to ensure and demonstrate continuous compliance with stringent standards such as PCI DSS and 3DS.
- Drive security infrastructure deployments across our growing environments.
- Perform regular security assessments, audits, threat modelling and architecture design reviews to identify risks and vulnerabilities, triage found risks, identify improvements appropriately and design controls to implement as corrective actions.
- Lead incident response efforts, including investigation and remediation of security breaches.
- Support our internal security awareness and training programs, advocating the DevSecOps mindset that we have created across our technology teams.
Requirements
We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. If you have an innate passion for security and care enough to find elegant solutions to difficult problems, we'd love to hear from you.
What skills are essential:
- Mature understanding of cloud security architecture, with deep expertise in GCP and a proven track record.
- Experience creating a GCP landing zone, configuring services such as organisation policies and VPC Service Controls.
- A deep understanding of GCP IAM and its limitations.
- Experience with service-oriented architecture using containers, distributed systems and immutable infrastructure on GCP (including GKE, Compute Engine, Shared VPC and Cloud SQL).
- Expertise in Kubernetes, securing clusters (GKE) and meshes (Cilium is preferable), networking best practices and RBAC implementation (CKA, CKS qualifications are a plus).
- Experience with Infrastructure as Code and infrastructure provisioning tools, particularly Terraform.
- Experience configuring GCP-native security posture and threat management with Security Command Center.
- Experience securing the software supply chain with Binary Authorization, Artifact Registry and Artifact Analysis.
- Experience with key and secret management on GCP — Cloud KMS, Cloud External Key Manager (EKM) and Secret Manager — including cryptographic key ceremonies.
- Experience with Workload Identity and Workload Identity Federation for keyless authentication of workloads and CI/CD.
- Experience configuring and utilising cloud-native security logging, monitoring and detection services.
- Strong programming skills — in security we write our own scripts for automation in Python, Go and other languages while contributing to open-source tools so we can utilise them.
- In-depth knowledge of security principles, technologies, best practices, and threat detection and mitigation strategies.
- Knowledge of common attack vectors and methodologies (OWASP Top 10, MITRE ATT&CK Framework and social engineering tactics).
- The ability to identify potential threats, attack vectors and vulnerabilities in systems and applications.
- The ability to identify security gaps and create solutions to minimise risk and impact to us.
- Thorough understanding of the incident response process (preparation, identification, containment, eradication, recovery, lessons learned).
What skills are desirable:
- In-depth knowledge of network security, including core routing and switching concepts (TCP/IP, BGP, VPNs), security controls (firewalls, WAFs, IDS/IPS), and practical experience designing hybrid connectivity between GCP and on-premise environments.
- Experience with data-residency and regulated-workload controls such as Assured Workloads and Access Transparency, relevant to deploying per-market for different banks' regulators.
- Hands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS.
- Experience automating security controls and compliance checks against standards and frameworks including SOC 2, ISO 27001 and PCI DSS / 3DS.
- Container security knowledge including container image provenance (e.g. Sigstore, Notary) with an in-depth knowledge of container runtimes, and an understanding of integrating security into the software development lifecycle.
- Experience performing secure code reviews and security approvals, including the use of static and dynamic application security testing (SAST / DAST) tools.
- Experience in cryptography management and enhancements.
- Relevant security certifications such as ISC2 CC, CISSP, CCSP, CISM, AWS Security Specialty or GCP Professional Cloud Security Engineer.
The main part of our tech stack is listed below. We don't ask that you have experience in all of it, but if you do, that's great!
- Java, which makes up the majority of our backend codebase.
- GCP and AWS — we're cloud-native.
- Microservice-based architecture.
- TeamCity for CI/CD (with multiple production releases per day).
- Terraform and Grafana.
- RDS and CloudSQL for PostgreSQL.
Our Interview Process:
Interviewing is a two-way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:
- Initial interview with an Engineer — ~45 minutes.
- Take-home technical test, to be discussed in the next interview.
- Technical interview with some Engineers — ~1.5 hours.
- Final interview with our CTO / deputy CTO — ~45 minutes.
Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.
When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Engine by Starling and Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal data.
Staff Cloud Security Engineer employer: Engine by Starling
At Engine by Starling, we pride ourselves on being an exceptional employer that fosters a collaborative and innovative work culture. Located in the vibrant city of London, our team enjoys a hybrid working model, generous benefits including 33 days of holiday, and ample opportunities for personal and professional growth. We are committed to diversity and inclusion, ensuring that every employee feels valued and empowered to contribute to our mission of reshaping banking for good.
StudySmarter Expert Advice🤫
We think this is how you could land Staff Cloud Security Engineer
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Engine by Starling, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Engine by Starling
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Engine by Starling. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Staff Cloud Security Engineer
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Engine by Starling insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Engine by Starling that you’re committed to staying ahead in the game.
How to prepare for a job interview at Engine by Starling
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Engine by Starling to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Engine by Starling.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.