At a Glance
- Tasks: Manage vulnerability tools and create automated solutions to enhance security processes.
- Company: Join Starling, the UK's leading digital bank on a mission to revolutionise banking.
- Benefits: Enjoy 25 days holiday, private medical insurance, and flexible working options.
- Other info: Collaborative culture with excellent career growth opportunities and a focus on diversity.
- Why this job: Be part of a tech-first company making a real impact in the fintech space.
- Qualifications: Strong knowledge in cloud, Kubernetes, and programming languages like Go or Java.
The predicted salary is between 58500 - 71500 £ per year.
Starling is the UK's first and leading digital bank on a mission to fix banking! Our vision is fast technology, fair service, and honest values. We are about giving customers a new way to spend, save and manage their money while taking better care of the planet. Our journey started in 2014, and since then we have surpassed 3.5 million accounts with 350,000 business customers. We are a fully licensed UK bank but at the heart, we are a tech-first company, enabling our platform to deliver brilliant products.
We are seeking a highly motivated and experienced Vulnerability Management Engineer to join our Cyber Security team. As a Vulnerability Management Engineer, your primary responsibility will be to manage vulnerability management tooling and have an active role in improving existing processes. You will achieve this by creating automated solutions through collaboration with technical teams across Starling.
Responsibilities:
- Design, build, and maintain robust vulnerability management tooling and technical solutions.
- Drive efficiency by implementing automated solutions that eliminate manual overhead and streamline operations.
- Partner with internal engineering teams and remediators to intelligently prioritise remediation activities.
- Synthesise raw vulnerability data into actionable insights, reports, and metrics to support a risk-based security posture.
- Engineer custom integrations between internal and external platforms to enhance data capture throughout the remediation lifecycle.
- Maintain strict adherence to global security standards, regulatory requirements, and industry frameworks.
- Keep at the forefront of the industry by monitoring emerging trends in vulnerability management and shifting regulatory landscapes.
- Treat security as a continuous engineering challenge to outpace the threat landscape, proactively identifying vulnerabilities and architecting technical solutions to fortify our global ecosystem.
- Develop and maintain comprehensive technical playbooks and runbooks to standardise vulnerability triage, remediation, and incident response procedures.
- Utilise pattern and trend analysis to identify "Vulnerability Hotspots" to drive strategic risk reduction.
Requirements:
- Strong technical knowledge, including:
- Cloud Experience (AWS, GCP)
- Kubernetes and Container experience
- Infrastructure as code (terraform)
- Proficiency with either Go or Java programming languages
- Strong engineering and automation background with a keen interest in Vulnerability Management
- Experience with developing integrations by interacting with APIs
- Ability and willingness to learn new technologies and adapt to evolving security landscapes
- Capability to understand the bigger picture while effectively managing details
- Strong written and verbal communication skills to effectively collaborate with cross-functional teams and stakeholders
Additional Technical Requirements:
- Deep understanding of container & orchestration security.
- Proficiency in cloud posture management.
- Risk-based prioritisation models.
- Practical experience in one or more of the vulnerability management fields would be desirable but not essential.
Interview process:
Interviewing is a two-way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you!
Benefits:
- 25 days holiday (plus take your public holiday allowance whenever works best for you).
- An extra day’s holiday for your birthday.
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off.
- 16 hours paid volunteering time a year.
- Salary sacrifice, company enhanced pension scheme.
- Life insurance at 4x your salary & group income protection.
- Private Medical Insurance with VitalityHealth including mental health support and cancer care.
- Generous family-friendly policies.
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks.
Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace.
Software Engineer - Vulnerability Management employer: Starling Bank
Starling Bank is an exceptional employer that champions a culture-first approach, fostering creativity and innovation in a dynamic environment. With a competitive benefits package, including generous leave and private medical insurance, employees are supported in their personal and professional growth. Located in Greater London, the bank promotes diversity and inclusion, making it a rewarding place for those looking to make a meaningful impact in the financial sector.