At a Glance
- Tasks: Join our team to protect customers by conducting penetration tests and enhancing security measures.
- Company: Starling Bank, the UK's leading digital bank with a tech-driven culture.
- Benefits: Enjoy 25 days holiday, private medical insurance, and flexible working options.
- Why this job: Make a real impact in fintech while working with cutting-edge technology and a supportive team.
- Qualifications: 5+ years in information security, with skills in penetration testing and cloud security.
- Other info: Dynamic environment with opportunities for growth and collaboration.
The predicted salary is between 36000 - 60000 Β£ per year.
Starling is the UK's first and leading digital bank on a mission to fix banking. We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way. We're a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company. Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech.
As an experienced Penetration Tester you will be working with talented cyber security professionals to protect Starling customers, company assets and systems using the latest technologies and techniques. The primary objective for this role is to collaborate with, support, and guide Starling's engineering and operation functions to ensure our services are designed, developed and operated securely.
Responsibilities:
- Scoping and performing mobile, web application, cloud, and infrastructure penetration tests.
- Automation of security testing, and development of internal tooling, to achieve continuous assurance.
- Collaboration with engineering teams to facilitate secure development.
- Review and analysis of proposed technical solutions to identify appropriate security controls.
- Input and guidance to security related technical architecture and design decisions.
- Code review of features and critical security components.
- Practical security testing.
- Advising on remediation of security issues and processes to address root causes.
- Security assurance reviews of third-party solutions.
- Identifying and implementing improvements to the team's internal processes and procedures.
- Review, analysis and reporting of external threats relevant to Starling systems and solutions.
Requirements:
- 5+ years technical information security experience.
- Experience of mobile, web application, cloud and infrastructure penetration testing.
- Strong technical knowledge in mobile security (iOS and Android), web application security, networking and associated protocols, cloud security (AWS and GCP), containers and Kubernetes.
- A desire to learn, and ability to apply technical security knowledge to new and unfamiliar areas.
- CREST, OSCP or similar industry penetration testing qualification.
- A good understanding of applied cryptographic techniques.
- Reverse engineering and exploit development capabilities.
- Experience of security testing in an agile SDLC.
- Threat modelling experience.
- Experience performing code reviews, particularly in Java and Go.
- Excellent verbal and written communication skills.
- Experience in automation of security testing, with previous development experience desirable.
Interview process:
Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you. Our interviews are conversational and we want to get the best from you, so come with questions and be curious.
Benefits:
- 25 days holiday (plus take your public holiday allowance whenever works best for you).
- An extra dayβs holiday for your birthday.
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off.
- 16 hours paid volunteering time a year.
- Salary sacrifice, company enhanced pension scheme.
- Life insurance at 4x your salary & group income protection.
- Private Medical Insurance with VitalityHealth including mental health support and cancer care.
- Generous family-friendly policies.
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks.
Starling is an equal opportunity employer, and weβre proud of our ongoing efforts to foster diversity & inclusion in the workplace.
Penetration Tester in Southampton employer: Starling
Contact Detail:
Starling Recruiting Team
StudySmarter Expert Advice π€«
We think this is how you could land Penetration Tester in Southampton
β¨Tip Number 1
Get to know Starling's culture and values before your interview. This will help you align your answers with what they care about, like innovation and collaboration. Show them you're not just a tech whiz but also a team player who fits right in!
β¨Tip Number 2
Prepare some thoughtful questions for your interviewers. This shows you're genuinely interested in the role and the company. Ask about their latest projects or how they tackle security challenges β itβll make you stand out as someone who's engaged and curious.
β¨Tip Number 3
Practice your technical skills and be ready to discuss your past experiences in detail. They want to see how you approach problems and your thought process during penetration tests. Be prepared to share specific examples that highlight your expertise and creativity.
β¨Tip Number 4
Donβt forget to showcase your passion for continuous learning! Starling values individuals who are eager to grow and adapt. Share any recent courses, certifications, or personal projects that demonstrate your commitment to staying on top of the latest security trends.
We think you need these skills to ace Penetration Tester in Southampton
Some tips for your application π«‘
Tailor Your Application: Make sure to customise your CV and cover letter for the Penetration Tester role. Highlight your relevant experience in mobile, web application, and cloud security testing. We want to see how your skills align with our mission to protect Starling customers!
Show Off Your Passion: Let us know why you're excited about working at Starling! Share your enthusiasm for fintech and how you can contribute to our innovative culture. A genuine interest in our values will definitely catch our eye.
Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use clear language to describe your experiences and achievements. We appreciate a well-structured application that makes it easy for us to see your strengths.
Apply Through Our Website: We encourage you to submit your application directly through our website. Itβs the best way to ensure we receive all your details correctly. Plus, it shows youβre keen on joining our team at Starling!
How to prepare for a job interview at Starling
β¨Know Your Stuff
Make sure you brush up on your technical knowledge, especially around mobile, web application, and cloud security. Be ready to discuss specific tools and techniques you've used in your previous roles, as well as any recent trends in penetration testing.
β¨Ask Questions
Interviews are a two-way street! Prepare thoughtful questions about Starling's approach to security, their tech stack, and how the penetration testing team collaborates with other departments. This shows your genuine interest and helps you gauge if it's the right fit for you.
β¨Show Your Problem-Solving Skills
Be prepared to walk through your thought process when tackling security challenges. Use examples from your past experiences to illustrate how youβve identified vulnerabilities and implemented solutions. This will demonstrate your analytical skills and ability to think on your feet.
β¨Embrace the Culture
Starling values innovation and collaboration, so highlight your experience working in fast-paced environments and your ability to take ownership of projects. Share examples of how you've contributed to team success and fostered a supportive atmosphere in previous roles.