Collaborate with stakeholders to define our Google Cloud security architecture (cloud identity, runtime security, security posture)
Design, document, build and maintain a secure and scalable infrastructure on GCP using Infrastructure as Code
Be part of the team responsible for safeguarding our systems, applications and data by ensuring secure user access, authentication and authorisation mechanisms are in place
Engineer and automate technical controls within GCP to ensure and demonstrate continuous compliance with stringent standards such as PCI DSS and 3DS
Drive security infrastructure deployments across our growing environments
Perform regular security assessments, audits, threat modelling and architecture design reviews to identify risks and vulnerabilities, triage found risks, identify improvements appropriately and design controls to implement as corrective actions
Lead incident response efforts, including investigation and remediation of security breaches
Support our internal security awareness and training programs, advocating the DevSecOps mindset that we have created across our technology teams
Requirements
We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. If you have an innate passion for security and care enough to find elegant solutions to difficult problems, we'd love to hear from you.
What skills are essential:
Mature understanding of cloud security architecture, with deep expertise in GCP and a proven track record
Experience creating a GCP landing zone, configuring services such as organisation policies and VPC Service Controls
A deep understanding of GCP IAM and its limitations
Experience with service-oriented architecture using containers, distributed systems and immutable infrastructure on GCP (including GKE, Compute Engine, Shared VPC and Cloud SQL)
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Expertise in Kubernetes, securing clusters (GKE) and meshes (Cilium is preferable), networking best practices and RBAC implementation (CKA, CKS qualifications are a plus)
Experience with Infrastructure as Code and infrastructure provisioning tools, particularly Terraform
Experience configuring GCP-native security posture and threat management with Security Command Center
Experience securing the software supply chain with Binary Authorization, Artifact Registry and Artifact Analysis
Experience with key and secret management on GCP — Cloud KMS, Cloud External Key Manager (EKM) and Secret Manager — including cryptographic key ceremonies
Experience with Workload Identity and Workload Identity Federation for keyless authentication of workloads and CI/CD
Experience configuring and utilising cloud-native security logging, monitoring and detection services
Strong programming skills — in security we write our own scripts for automation in Python, Go and other languages while contributing to open-source tools so we can utilise them
In-depth knowledge of security principles, technologies, best practices, and threat detection and mitigation strategies
Knowledge of common attack vectors and methodologies (OWASP Top 10, MITRE ATT&CK Framework and social engineering tactics)
The ability to identify potential threats, attack vectors and vulnerabilities in systems and applications
The ability to document security requirements from various stakeholders
Excellent problem-solving, communication and active listening skills with an innate passion for security
The ability to identify security gaps and create solutions to minimise risk and impact to us
A proactive approach to staying updated with the latest security threats, vulnerabilities and mitigation techniques
Thorough understanding of the incident response process (preparation, identification, containment, eradication, recovery, lessons learned)
What skills are desirable:
In-depth knowledge of network security, including core routing and switching concepts (TCP/IP, BGP, VPNs), security controls (firewalls, WAFs, IDS/IPS), and practical experience designing hybrid connectivity between GCP and on-premise environments
Experience with data-residency and regulated-workload controls such as Assured Workloads and Access Transparency, relevant to deploying per-market for different banks' regulators
Hands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS
Experience automating security controls and compliance checks against standards and frameworks including SOC 2, ISO 27001 and PCI DSS / 3DS
Container security knowledge including container image provenance (e.g. Sigstore, Notary) with an in-depth knowledge of container runtimes, and an understanding of integrating security into the software development lifecycle
Experience performing secure code reviews and security approvals, including the use of static and dynamic application security testing (SAST / DAST) tools
Experience in cryptography management and enhancements
Relevant security certifications such as ISC2 CC, CISSP, CCSP, CISM, AWS Security Specialty or GCP Professional Cloud Security Engineer
The main part of our tech stack is listed below. We don't ask that you have experience in all of it, but if you do, that's great!
Java, which makes up the majority of our backend codebase
GCP and AWS — we're cloud-native
Microservice-based architecture
Kubernetes (GKE on GCP, EKS on AWS)
TeamCity for CI/CD (with multiple production releases per day)
Terraform and Grafana
RDS and CloudSQL for PostgreSQL
Our Interview Process
Interviewing is a two-way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:
Initial interview with an Engineer — ~45 minutes
Take-home technical test, to be discussed in the next interview
Technical interview with some Engineers — ~1.5 hours
Final interview with our CTO / deputy CTO — ~45 minutes
Benefits
33 days holiday (including public holidays, which you can take when it works best for you)
An extra day’s holiday for your birthday
Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
16 hours paid volunteering time a year
Salary sacrifice, company enhanced pension scheme
Life insurance at 4x your salary & group income protection
Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
Generous family-friendly policies
Incentives refer a friend scheme
Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
About Us
You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.
Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.
When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Engine by Starling and Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.
We use AI tools to support various parts of our recruitment process, helping our team manage applications and assessments more efficiently. These tools are strictly used for support and do not replace human judgment with all final hiring decisions being made by our team. If you would like more information about how your data is processed, please reach out to us.
About Engine by Starling
Parent group profile
Starling Bank
Banking3700 employeesFounded 2014
UK private digital bank providing personal, business and joint current accounts to consumers and small businesses.