Security Operations (SOC) Engineer - Engine by Starling in Cardiff

Security Operations (SOC) Engineer - Engine by Starling in Cardiff

Cardiff Full-Time 50000 - 65000 £ / year (est.) No working from home possible
S

At a Glance

  • Tasks: Join our SecOps team to develop and operate innovative security capabilities.
  • Company: Engine by Starling, a forward-thinking company reshaping banking.
  • Benefits: 33 days holiday, private medical insurance, and flexible working options.
  • Other info: Dynamic team culture with a focus on diversity and inclusion.
  • Why this job: Make a real impact in cybersecurity while leveraging AI and automation.
  • Qualifications: 3+ years in SOC or SecOps, strong Python skills, and cloud experience.

The predicted salary is between 50000 - 65000 £ per year.

Hybrid Working

We have a Hybrid approach to working here at Engine – our preference is that you’re located within a commutable distance of one of our offices so that we can interact and collaborate in person.

About The Role

To support our rapid growth, we are looking for talented engineers to join our foundational in‑house SecOps team. This is a “Full‑Stack” security role: you will move beyond traditional monitoring to develop and operate our security capabilities. We are looking for engineers who are masters of automation but remain grounded in analyst fundamentals. You should have a keen interest in leveraging AI and Large Language Models (LLMs) to reduce SOC toil – using AI to summarise complex alerts, auto‑generate YARA‑L detections, or build intelligent playbooks to stay ahead of modern threats.

Responsibilities

  • Active Monitoring: Monitor security alerts and events generated by the SecOps platform and integrated cloud security tools.
  • Triage & Analysis: Perform deep‑dive analysis of security incidents and anomalies, accurately distinguishing between true positives and false positives.
  • Prioritisation: Manage the incident queue, prioritising alerts based on severity, potential impact, and business criticality.
  • Detection Engineering & Automation (IaC):
    • Detection as Code: Design and maintain sophisticated detection logic using YARA‑L. Manage the lifecycle of these rules and configurations using IaC principles for version control.
    • SOAR Extension: Lead the automation of response playbooks. You will write and extend SOAR capabilities using Python, creating custom integrations and "Managers" to connect SecOps with internal APIs.
    • Tool Optimisation: Identify opportunities for automation to streamline operations and contribute to the continuous tuning and maintenance of SOC tools.
  • Incident Response & Investigation:
    • End‑to‑End Investigation: Investigate incidents thoroughly, leveraging logs from platforms, endpoints, and applications mapped to the Unified Data Model (UDM).
    • Incident Lifecycle: Lead containment, eradication, and recovery efforts in collaboration with Security and Technology teams.
    • Documentation: Maintain comprehensive records of incident details, findings, and remediation steps to ensure a high standard of auditability.
  • Collaboration & Threat Intelligence:
    • Group Collaboration: Work closely with the Group SOC team to align on global security standards and coordinate response efforts during cross‑entity incidents.
    • Threat Hunting: Stay informed about the latest cyber threats and cloud‑specific vulnerabilities, conducting proactive threat‑hunting activities using available telemetry.

Requirements

  • 3+ years of experience in a SOC or SecOps Engineering role, with a strong background in both alert triage and security engineering.
  • Proficiency in Python: Ability to write clean code to automate workflows or interact with security APIs.
  • Cloud Fluency: Experience with security monitoring and incident response in cloud environments (AWS/GCP/Azure).
  • Infrastructure as Code: Familiarity with managing security configurations through Git‑based workflows.
  • Framework Knowledge: Strong understanding of attack vectors and the MITRE ATT&CK framework.
  • Education: A degree in a cyber‑related field or relevant certifications (e.g. CompTIA Security+, CySA+, GCIH) is beneficial.

Interview process

Interviewing is a two‑way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • Stage 1 – 45 mins with BISO
  • Stage 2 – 60 min with Team Members
  • Stage 3 – Final with CTO

Benefits

  • 33 days holiday (including public holidays, which you can take when it works best for you)
  • An extra day’s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care.
  • Partner benefits include discounts with Waitrose, Mr & Mrs Smith and Peloton
  • Generous family‑friendly policies
  • Incentives refer a friend scheme
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

About Us

You may be put off applying for a role because you don’t tick every box. Forget that! While we can’t accommodate every flexible working request, we’re always open to discussion. So, if you’re excited about working with us, but aren’t sure if you’re 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems. Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace.

Security Operations (SOC) Engineer - Engine by Starling in Cardiff employer: Starling

Engine by Starling is an exceptional employer that champions a hybrid working model, allowing for flexibility while fostering collaboration in a vibrant office environment. With a strong focus on employee growth, we offer extensive benefits including generous holiday allowances, private medical insurance, and opportunities for professional development, all within a diverse and inclusive culture that values every team member's contributions. Join us to be part of a forward-thinking team dedicated to reshaping the banking landscape through innovation and teamwork.

S

Contact Details:

Starling Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Operations (SOC) Engineer - Engine by Starling in Cardiff

Tip Number 1

Get your networking game on! Connect with folks in the industry, especially those already at Engine. LinkedIn is a goldmine for this – drop them a message, ask about their experience, and see if they can give you the inside scoop.

Tip Number 2

Prepare for those interviews like a pro! Research common SOC Engineer questions and practice your answers. But don’t just rehearse – think of questions to ask them too. Show that you’re genuinely interested in their work and culture.

Tip Number 3

Show off your skills! If you’ve got any projects or contributions to open-source security tools, make sure to highlight them. It’s a great way to demonstrate your hands-on experience and passion for security.

Tip Number 4

Don’t hesitate to apply through our website! Even if you feel you don’t tick every box, we want to hear from you. Your unique background could be just what we need to shake things up at Engine!

We think you need these skills to ace Security Operations (SOC) Engineer - Engine by Starling in Cardiff

Active Monitoring
Triage & Analysis
Incident Response
Detection Engineering
Automation
Python Programming
Cloud Security (AWS/GCP/Azure)

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Security Operations Engineer role. Highlight your experience with automation, incident response, and any relevant projects that showcase your skills in Python and cloud security.

Show Your Passion for Security:Let us see your enthusiasm for cybersecurity! Mention any personal projects, certifications, or ongoing learning that demonstrate your commitment to staying updated on the latest threats and technologies in the field.

Be Clear and Concise:When writing your application, keep it straightforward. Use bullet points where possible to make your achievements stand out, and avoid jargon unless it's relevant to the role. We want to see your skills without wading through unnecessary fluff!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen to join our team at Engine by Starling!

How to prepare for a job interview at Starling

Know Your Tech

Make sure you brush up on your technical skills, especially in Python and cloud security. Be ready to discuss how you've used automation in your previous roles and how it can streamline SOC operations.

Understand the Role

Familiarise yourself with the responsibilities of a Security Operations Engineer. Be prepared to talk about your experience with incident response, alert triage, and detection engineering, and how these relate to the job description.

Ask Smart Questions

Interviews are a two-way street! Prepare thoughtful questions about the team dynamics, the tools they use, and their approach to threat hunting. This shows your genuine interest and helps you gauge if it's the right fit for you.

Showcase Your Curiosity

Demonstrate your passion for cybersecurity by discussing recent trends or threats you've been following. Mention any personal projects or learning experiences that highlight your proactive approach to staying updated in the field.