At a Glance
- Tasks: Manage vulnerability tools and create automated solutions to enhance security processes.
- Company: Join Starling, the UK's leading digital bank on a mission to revolutionise banking.
- Benefits: Enjoy 25 days holiday, private medical insurance, and flexible working options.
- Other info: Collaborative culture with excellent career growth opportunities and a commitment to diversity.
- Why this job: Be part of a tech-first company making a real impact in the fintech space.
- Qualifications: Strong technical skills in cloud, programming, and automation are essential.
The predicted salary is between 54000 - 66000 £ per year.
Starling is the UK's first and leading digital bank on a mission to fix banking! Our vision is fast technology, fair service, and honest values. We are about giving customers a new way to spend, save and manage their money while taking better care of the planet. Our journey started in 2014, and since then we have surpassed 3.5 million accounts with 350,000 business customers. We are a fully licensed UK bank but at the heart, we are a tech-first company, enabling our platform to deliver brilliant products.
We are seeking a highly motivated and experienced Vulnerability Management Engineer to join our Cyber Security team. As a Vulnerability Management Engineer, your primary responsibility will be to manage vulnerability management tooling and have an active role in improving existing processes. You will achieve this by creating automated solutions through collaboration with technical teams across Starling.
Responsibilities
- Design, build, and maintain robust vulnerability management tooling and technical solutions.
- Drive efficiency by implementing automated solutions that eliminate manual overhead and streamline operations.
- Partner with internal engineering teams and remediators to intelligently prioritise remediation activities.
- Synthesise raw vulnerability data into actionable insights, reports, and metrics to support a risk-based security posture.
- Engineer custom integrations between internal and external platforms to enhance data capture throughout the remediation lifecycle.
- Maintain strict adherence to global security standards, regulatory requirements, and industry frameworks.
- Keep at the forefront of the industry by monitoring emerging trends in vulnerability management and shifting regulatory landscapes.
- Treat security as a continuous engineering challenge to outpace the threat landscape, proactively identifying vulnerabilities and architecting technical solutions to fortify our global ecosystem.
- Develop and maintain comprehensive technical playbooks and runbooks to standardise vulnerability triage, remediation, and incident response procedures.
- Utilise pattern and trend analysis to identify "Vulnerability Hotspots" to drive strategic risk reduction.
Requirements
- Strong technical knowledge, including:
- Cloud Experience (AWS, GCP)
- Kubernetes and Container experience
- Infrastructure as code (terraform)
- Proficiency with either Go or Java programming languages
- Strong engineering and automation background with a keen interest in Vulnerability Management
- Experience with developing integrations by interacting with APIs
- Ability and willingness to learn new technologies and adapt to evolving security landscapes
- Capability to understand the bigger picture while effectively managing details
- Strong written and verbal communication skills to effectively collaborate with cross-functional teams and stakeholders
Additional Technical Requirements
- Deep understanding of container & orchestration security.
- Proficiency in cloud posture management.
- Risk-based prioritisation models.
- Practical experience in one or more of the vulnerability management fields would be desirable but not essential.
- Experience with Software Bill of Materials (SBOM) management.
Interview process
Interviewing is a two-way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious.
Benefits
- Hybrid working approach.
- 25 days holiday plus public holiday allowance.
- An extra day's holiday for your birthday.
- Annual leave increased with length of service.
- 16 hours paid volunteering time a year.
- Salary sacrifice, company enhanced pension scheme.
- Life insurance at 4x your salary & group income protection.
- Private Medical Insurance with VitalityHealth.
- Generous family-friendly policies.
- Perkbox membership.
- Access to initiatives like Cycle to Work and Electric Vehicle (EV) leasing.
About Us
We are proud to bring together people of all backgrounds and experiences who love working together to solve problems. Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace.
Software Engineer - Vulnerability Management in Manchester employer: Starling
Starling is an exceptional employer that fosters a culture of collaboration and innovation, making it an ideal place for engineers to thrive. With a hybrid working model, employees enjoy flexibility while benefiting from comprehensive support for professional growth and development. The positive work environment, coupled with a commitment to clean coding practices, ensures that team members are empowered to tackle complex challenges and contribute meaningfully to the future of banking.
StudySmarter Expert Advice🤫
We think this is how you could land Software Engineer - Vulnerability Management in Manchester
✨Join Local Tech Meetups
Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at Starling or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!
✨Contribute to Open Source Projects
Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to Starling.
✨Tap into Online Developer Communities
Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like Starling.
✨Explore Job Boards Specifically for Tech Roles
Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like Starling that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!
We think you need these skills to ace Software Engineer - Vulnerability Management in Manchester
Some tips for your application 🫡
Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.
Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at Starling.
Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at Starling and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!
Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!
How to prepare for a job interview at Starling
✨Brush Up on Your Coding Skills
For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.
✨Know Your Tools and Frameworks
Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If Starling uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.
✨Showcase Your Projects
Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.
✨Prepare for Behavioural Questions
While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.