At a Glance
- Tasks: Join our team to protect customers by conducting penetration tests and enhancing security measures.
- Company: Starling, the UK's leading digital bank, blending banking with innovative tech.
- Benefits: Enjoy 25 days holiday, private medical insurance, and flexible working options.
- Why this job: Make a real impact in fintech while collaborating with talented cyber security professionals.
- Qualifications: 5+ years in information security, with skills in penetration testing and cloud security.
- Other info: Dynamic work culture focused on innovation, collaboration, and personal growth.
The predicted salary is between 48000 - 72000 Β£ per year.
Starling is the UK's first and leading digital bank on a mission to fix banking. We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way. We're a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company. Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech.
As an experienced Penetration Tester, you will be working with talented cyber security professionals to protect Starling customers, company assets and systems using the latest technologies and techniques. The primary objective for this role is to collaborate with, support, and guide Starling's engineering and operation functions to ensure our services are designed, developed and operated securely.
Responsibilities:
- Scoping and performing mobile, web application, cloud, and infrastructure penetration tests.
- Automation of security testing, and development of internal tooling, to achieve continuous assurance.
- Collaboration with engineering teams to facilitate secure development.
- Review and analysis of proposed technical solutions to identify appropriate security controls.
- Input and guidance to security related technical architecture and design decisions.
- Code review of features and critical security components.
- Practical security testing.
- Advising on remediation of security issues and processes to address root causes.
- Security assurance reviews of third-party solutions.
- Identifying and implementing improvements to the team's internal processes and procedures.
- Review, analysis and reporting of external threats relevant to Starling systems and solutions.
Requirements:
- 5+ years technical information security experience.
- Experience of mobile, web application, cloud and infrastructure penetration testing.
- Strong technical knowledge in mobile security (iOS and Android), web application security, networking and associated protocols, cloud security (AWS and GCP), containers and Kubernetes.
- A desire to learn, and ability to apply technical security knowledge to new and unfamiliar areas.
- CREST, OSCP or similar industry penetration testing qualification.
- A good understanding of applied cryptographic techniques.
- Reverse engineering and exploit development capabilities.
- Experience of security testing in an agile SDLC.
- Threat modelling experience.
- Experience performing code reviews, particularly in Java and Go.
- Excellent verbal and written communication skills.
- Experience in automation of security testing, with previous development experience desirable.
Interview process:
Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you. Our interviews are conversational and we want to get the best from you, so come with questions and be curious.
Benefits:
- 25 days holiday (plus take your public holiday allowance whenever works best for you).
- An extra dayβs holiday for your birthday.
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off.
- 16 hours paid volunteering time a year.
- Salary sacrifice, company enhanced pension scheme.
- Life insurance at 4x your salary & group income protection.
- Private Medical Insurance with VitalityHealth including mental health support and cancer care.
- Generous family-friendly policies.
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks.
Starling is an equal opportunity employer, and weβre proud of our ongoing efforts to foster diversity & inclusion in the workplace.
Penetration Tester in Cardiff employer: Starling
Contact Detail:
Starling Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Penetration Tester in Cardiff
β¨Tip Number 1
Network like a pro! Reach out to current or former employees at Starling on LinkedIn. A friendly chat can give you insider info and maybe even a referral, which can really boost your chances.
β¨Tip Number 2
Prepare for the interview by brushing up on your technical skills and understanding Starling's values. Be ready to discuss how you can contribute to their mission of fixing banking while showcasing your passion for cybersecurity.
β¨Tip Number 3
Show off your problem-solving skills during the interview. Bring examples of past projects where you tackled security challenges head-on. This will demonstrate your ability to own it and aim for greatness!
β¨Tip Number 4
Donβt forget to ask questions! Show your curiosity about the team and the role. This not only helps you gauge if it's the right fit but also leaves a positive impression on the interviewers.
We think you need these skills to ace Penetration Tester in Cardiff
Some tips for your application π«‘
Tailor Your Application: Make sure to customise your CV and cover letter for the Penetration Tester role. Highlight your relevant experience in mobile, web application, and cloud security testing. We want to see how your skills align with our mission to protect Starling customers!
Show Off Your Passion: Let us know why you're excited about working at Starling! Share your enthusiasm for fintech and how you can contribute to our innovative culture. A genuine interest in our values will definitely catch our eye.
Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use clear language to describe your experiences and achievements. We appreciate a well-structured application that makes it easy for us to see your strengths.
Apply Through Our Website: We encourage you to submit your application directly through our website. Itβs the best way to ensure we receive all your details correctly. Plus, it shows youβre keen on joining our team at Starling!
How to prepare for a job interview at Starling
β¨Know Your Stuff
Make sure you brush up on your technical knowledge, especially around mobile, web application, and cloud security. Be ready to discuss specific tools and techniques you've used in your previous roles, as well as any recent trends in penetration testing.
β¨Show Your Curiosity
During the interview, donβt hesitate to ask questions about Starling's approach to security and how the team collaborates with other departments. This shows that you're genuinely interested in the role and eager to contribute to their mission.
β¨Demonstrate Problem-Solving Skills
Be prepared to walk through a real-world scenario where you had to identify and remediate a security issue. Highlight your thought process and the steps you took to resolve the problem, showcasing your ability to think critically under pressure.
β¨Cultural Fit Matters
Starling values collaboration and innovation, so be sure to express your enthusiasm for working in a fast-paced environment. Share examples of how you've taken ownership of projects and contributed to team success in previous roles.