Security Operations (SOC) Engineer - Engine by Starling

Security Operations (SOC) Engineer - Engine by Starling

Full-Time 60000 - 75000 € / year (est.) No home office possible
Starling Bank

At a Glance

  • Tasks: Join our SecOps team to develop and operate cutting-edge security capabilities.
  • Company: Engine by Starling, a fast-growing tech company transforming banking.
  • Benefits: 33 days holiday, private medical insurance, and flexible working options.
  • Other info: Diverse and inclusive workplace with excellent career growth opportunities.
  • Why this job: Be part of a mission to reshape banking with innovative technology.
  • Qualifications: 3+ years in SOC or SecOps, strong Python skills, and cloud experience.

The predicted salary is between 60000 - 75000 € per year.

At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology. Engine is Starling's software-as-a-service (SaaS) business, the technology that was built to power Starling, and two years ago we split out as a separate business. Starling has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling's success.

We draw upon our experience as knowledgeable bankers, and best in class technologists to become the chosen option for these banks, and preferred partners for leading consultancies. As a company, everyone is expected to roll up their sleeves to help deliver great outcomes for our clients. We are an engineering led company and we’re looking for someone who will be excited by the potential for Engine’s technology to transform banking in different markets around the world.

Hybrid Working

We have a Hybrid approach to working here at Engine - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person.

About the Role

To support our rapid growth, we are looking for talented engineers to join our foundational in-house SecOps team. This is a "Full-Stack" security role: you will move beyond traditional monitoring to develop and operate our security capabilities. We are looking for engineers who are masters of automation but remain grounded in analyst fundamentals. You should have a keen interest in leveraging AI and Large Language Models (LLMs) to reduce SOC toil - using AI to summarise complex alerts, auto-generate YARA-L detections, or build intelligent playbooks to stay ahead of modern threats.

Responsibilities

  • Security Monitoring & Alert Triage
    • Active Monitoring: Monitor security alerts and events generated by the SecOps platform and integrated cloud security tools.
    • Triage & Analysis: Perform deep-dive analysis of security incidents and anomalies, accurately distinguishing between true positives and false positives.
    • Prioritisation: Manage the incident queue, prioritising alerts based on severity, potential impact, and business criticality.
  • Detection Engineering & Automation (IaC)
    • Detection as Code: Design and maintain sophisticated detection logic using YARA-L. Manage the lifecycle of these rules and configurations using IaC principles for version control.
    • SOAR Extension: Lead the automation of response playbooks. You will write and extend SOAR capabilities using Python, creating custom integrations and "Managers" to connect SecOps with internal APIs.
    • Tool Optimisation: Identify opportunities for automation to streamline operations and contribute to the continuous tuning and maintenance of SOC tools.
  • Incident Response & Investigation
    • End-to-End Investigation: Investigate incidents thoroughly, leveraging logs from platforms, endpoints, and applications mapped to the Unified Data Model (UDM).
    • Incident Lifecycle: Lead containment, eradication, and recovery efforts in collaboration with Security and Technology teams.
    • Documentation: Maintain comprehensive records of incident details, findings, and remediation steps to ensure a high standard of auditability.
  • Collaboration & Threat Intelligence
    • Group Collaboration: Work closely with the Group SOC team to align on global security standards and coordinate response efforts during cross-entity incidents.
    • Threat Hunting: Stay informed about the latest cyber threats and cloud-specific vulnerabilities, conducting proactive threat-hunting activities using available telemetry.

Qualifications

  • 3+ years of experience in a SOC or SecOps Engineering role, with a strong background in both alert triage and security engineering.
  • Proficiency in Python: Ability to write clean code to automate workflows or interact with security APIs.
  • Cloud Fluency: Experience with security monitoring and incident response in cloud environments (AWS/GCP/Azure).
  • Infrastructure as Code: Familiarity with managing security configurations through Git-based workflows.
  • Framework Knowledge: Strong understanding of attack vectors and the MITRE ATT&CK framework.
  • Education: A degree in a cyber-related field or relevant certifications (e.g., CompTIA Security+, CySA+, GCIH) is beneficial.

Interview process

Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • Stage 1 - 45 mins with BISO
  • Stage 2 - 60 min with Team Members
  • Stage 3 - Final with CTO

Benefits

  • 33 days holiday (including public holidays, which you can take when it works best for you)
  • An extra day’s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care.
  • Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Incentives refer a friend scheme
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

About Us

You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems. Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace.

Security Operations (SOC) Engineer - Engine by Starling employer: Starling Bank

Engine by Starling is an exceptional employer that fosters a collaborative and innovative work culture, where every team member is encouraged to contribute to transformative banking solutions. With a strong focus on employee growth, we offer extensive benefits including generous holiday allowances, private medical insurance, and opportunities for professional development, all within a hybrid working environment that promotes work-life balance. Join us in our mission to reshape the banking landscape while enjoying a supportive atmosphere that values diversity and inclusion.

Starling Bank

Contact Detail:

Starling Bank Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Operations (SOC) Engineer - Engine by Starling

Tip Number 1

Get to know the company inside out! Research Engine by Starling, their tech, and their mission. This will help you tailor your conversations during interviews and show that you're genuinely interested in being part of their journey.

Tip Number 2

Practice makes perfect! Prepare for common interview questions related to SOC roles and be ready to discuss your experience with Python, cloud security, and incident response. The more you rehearse, the more confident you'll feel!

Tip Number 3

Don’t forget to ask questions! Interviews are a two-way street, so come armed with queries about the team, projects, and company culture. This shows you're engaged and helps you figure out if it's the right fit for you.

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re proactive and keen to join the Engine by Starling family. Let’s get you on board!

We think you need these skills to ace Security Operations (SOC) Engineer - Engine by Starling

Security Monitoring
Alert Triage
Incident Response
Detection Engineering
Automation
Python Programming
Cloud Security (AWS/GCP/Azure)

Some tips for your application 🫡

Tailor Your CV:Make sure your CV reflects the skills and experiences that align with the SOC Engineer role. Highlight your experience in security monitoring, alert triage, and automation, as these are key aspects of what we're looking for.

Craft a Compelling Cover Letter:Use your cover letter to tell us why you're excited about the opportunity at Engine by Starling. Share specific examples of how your background in SecOps can contribute to our mission of transforming banking technology.

Showcase Your Technical Skills:Don’t forget to mention your proficiency in Python and any experience you have with cloud environments like AWS or Azure. We want to see how you can leverage your technical skills to enhance our security capabilities.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows your enthusiasm for joining our team!

How to prepare for a job interview at Starling Bank

Know Your Tech

Make sure you brush up on your knowledge of security monitoring tools and cloud environments like AWS, GCP, or Azure. Be ready to discuss how you've used these technologies in past roles, especially in relation to alert triage and incident response.

Showcase Your Automation Skills

Since this role emphasises automation, come prepared with examples of how you've used Python to automate workflows or enhance security processes. If you have experience with IaC principles, be sure to highlight that too!

Understand the Threat Landscape

Familiarise yourself with current cyber threats and vulnerabilities, particularly those relevant to the banking sector. Being able to discuss recent incidents or trends will show your proactive approach to threat hunting and incident management.

Ask Thoughtful Questions

Interviews are a two-way street! Prepare some insightful questions about Engine's technology, team dynamics, or future projects. This not only shows your interest but also helps you gauge if the company is the right fit for you.