Information Security Lead - Vulnerability Management

Information Security Lead - Vulnerability Management

Full-Time 60000 - 80000 £ / year (est.) No working from home possible
Starling Bank Limited

At a Glance

  • Tasks: Lead a team to analyse and manage emerging vulnerabilities in a dynamic tech environment.
  • Company: Join Starling Bank, a forward-thinking company prioritising diversity and innovation.
  • Benefits: Enjoy 33 days holiday, private medical insurance, and flexible working options.
  • Other info: Hybrid working model with excellent career growth opportunities.
  • Why this job: Make a real impact on security while collaborating with diverse teams.
  • Qualifications: Proven leadership in vulnerability management and strong communication skills required.

The predicted salary is between 60000 - 80000 £ per year.

We are seeking a highly motivated and experienced Vulnerability Manager to lead a vulnerability management team. A successful candidate will work with the team to analyse emerging vulnerabilities provided by threat intelligence sources and penetration testing. The vulnerability manager will collaborate with various technology and engineering teams to share vulnerability findings, provide guidance, and assist through the remediation process. This person will help present this information in a simple digestible format, and coordinate remediation and mitigation efforts with teams across remote and office locations. There will be opportunities to guide continual improvement of the vulnerability management process.

Hybrid working

We have a hybrid approach to working here at Starling - our preference is that you’re located within a commutable distance of one of our offices so that we’re able to interact and collaborate in person. In Technology, we’re asking that you attend the office a minimum of 1 day per week.

Responsibilities

  • Assessing and investigating emerging vulnerabilities, drawing from threat intelligence sources and internal software and infrastructure scans, providing comprehensive guidance based on findings.
  • Collaborating with relevant technology teams, including security, engineering, workplace technology, data, and infrastructure, to ensure the timely resolution of identified issues.
  • Tracking and reporting on the progress of mitigation efforts and resolutions to pertinent audiences.
  • Overseeing the vulnerability management and policy compliance lifecycle, which encompasses scanning, prioritisation, reporting, and remediation governance.
  • Promote vulnerability management standards, procedures & guidelines, and best practices outside the security functions.
  • Identify trends and themes in issues which occur and work collaboratively with wider teams to develop process and procedure improvements.
  • Conducting hands‑on vulnerability analysis across infrastructure, cloud environments, and applications.
  • Ensuring compliance with internal security policies and regulatory requirements.
  • Providing reporting, key performance indicators (KPIs), and executive visibility on the organisation’s vulnerability posture.
  • Supporting audits, risk assessments, and responses to emerging vulnerabilities.
  • Active involvement in internal and external audits, and experience in managing audit relationships.

Qualifications

  • Proven experience in a similar leadership role, guiding and motivating a team of subject matter experts.
  • Strong understanding of Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS), threat intelligence, and remediation workflows.
  • Knowledge of common vulnerabilities, attack vectors, and mitigation techniques.
  • Familiarity with application development platforms.
  • Excellent written and verbal communication skills for effective collaboration with cross functional teams and stakeholders.
  • Ability to understand the larger context while effectively managing complex details.
  • Willingness and capability to learn new technologies and adapt to evolving security landscapes.
  • Practical experience in the following fields of vulnerability management: Endpoint Vulnerability Scanning, Vulnerability Intelligence, Application Security (AppSec) Vulnerability Management, Vulnerability Management for cloud native workloads.

Desirable technical knowledge includes:

  • Cloud services (AWS, GCP)
  • Containers
  • MacOS and Windows environments
  • Data analysis and SQL

Interview process

  • First stage with the Penetration Testing and Vulnerability Management Lead.
  • Second stage with additional members of the Vulnerability Management team.
  • Final stage with InfoSec Director and CISO.

Benefits

  • 33 days holiday (including public holidays, which you can take when it works best for you).
  • An extra day’s holiday for your birthday.
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off.
  • 16 hours paid volunteering time a year.
  • Salary sacrifice, company enhanced pension scheme.
  • Life insurance at 4x your salary & group income protection.
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care.
  • Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton.
  • Generous family‑friendly policies.
  • Incentives – refer a friend scheme.
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks.
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing.

Equal Employment Opportunity

Starling Bank is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.

Information Security Lead - Vulnerability Management employer: Starling Bank Limited

Starling Bank is an exceptional employer that prioritises employee well-being and professional growth, offering a hybrid working model that fosters collaboration while allowing flexibility. With generous benefits such as 33 days of holiday, enhanced pension schemes, and a strong commitment to diversity and inclusion, employees are empowered to thrive in a supportive environment that values their contributions and encourages continual improvement in the field of information security.

Starling Bank Limited

Contact Details:

Starling Bank Limited Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Lead - Vulnerability Management

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for those interviews! Research the company, understand their vulnerability management processes, and be ready to discuss how your experience aligns with their needs. Practice common interview questions and have your own questions ready to show your interest.

Tip Number 3

Show off your skills! If you’ve got hands-on experience with vulnerability analysis or remediation, be sure to highlight that in conversations. Share specific examples of how you’ve tackled vulnerabilities in the past to demonstrate your expertise.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Starling.

We think you need these skills to ace Information Security Lead - Vulnerability Management

Vulnerability Management
Threat Intelligence
Penetration Testing
Common Vulnerabilities and Exposures (CVE)
Common Vulnerability Scoring System (CVSS)
Application Security (AppSec)
Endpoint Vulnerability Scanning

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in vulnerability management. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!

Showcase Your Communication Skills:Since this role involves collaborating with various teams, it’s crucial to demonstrate your written communication skills. Use clear and concise language in your application to reflect how you can present complex information simply.

Highlight Your Technical Knowledge:Don’t forget to mention your familiarity with CVE, CVSS, and other technical aspects of vulnerability management. We’re looking for someone who knows their stuff, so be specific about your experience with tools and processes.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy to do!

How to prepare for a job interview at Starling Bank Limited

Know Your Vulnerabilities

Before the interview, brush up on your knowledge of Common Vulnerabilities and Exposures (CVE) and the Common Vulnerability Scoring System (CVSS). Be prepared to discuss specific vulnerabilities you've encountered in past roles and how you approached their remediation.

Showcase Your Collaboration Skills

Since this role involves working with various technology and engineering teams, think of examples where you've successfully collaborated across departments. Highlight your communication skills and how you can present complex information in a digestible format.

Demonstrate Continuous Improvement Mindset

Be ready to talk about how you've contributed to process improvements in vulnerability management. Share specific instances where you've identified trends or themes in vulnerabilities and how you worked with teams to enhance procedures.

Prepare for Technical Questions

Expect technical questions related to vulnerability analysis, cloud environments, and application security. Brush up on your practical experience in these areas and be ready to discuss tools and techniques you've used in your previous roles.