Talent.com
Starling
Information Security Engineer - Vulnerability ManagementStarling • Southampton, England, GB
No longer accepting applications
Information Security Engineer - Vulnerability Management

Information Security Engineer - Vulnerability Management

Starling • Southampton, England, GB
30+ days ago
Job type
  • Full-time
  • Quick Apply
Job description

Starling is the UK's first and leading digital bank on a mission to fix banking! Our vision is fast technology, fair service, and honest values. All at the tap of a phone, all the time.

We are about giving customers a new way to spend, save and manage their money while taking better care of the planet which has seen us become a multi-award winning bank that now employs over 2800 across five offices in London, Cardiff, Dublin, Southampton, and Manchester. Our journey started in 2014, and since then we have surpassed 3.5 million accounts (and four account types!) with 350,000 business customers. We are a fully licensed UK bank but at the heart, we are a tech first company, enabling our platform to deliver brilliant products.

Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be, innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture, you will find support in your team and from across the business, we are in this together!

The way to thrive and shine within Starling is to be a self-driven individual and be able to take full ownership of everything around you: From building things, designing, discovering, to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers. Our purpose is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. In Technology, we're asking that you attend the office a minimum of 1 day per week.

About the Role

We are seeking a highly motivated and experienced Vulnerability Management Engineer to join our Cyber Security team. As a Vulnerability Management Engineer, your primary responsibility will be to manage vulnerability management tooling, and have an active role in improving existing processes. You will achieve this by creating automated solutions through collaboration with technical teams across Starling.

Responsibilities

  • Design, build, and maintain robust vulnerability management tooling and technical solutions.
  • Drive efficiency by implementing automated solutions that eliminate manual overhead and streamline operations.
  • Partner with internal engineering teams and remediators to intelligently prioritise remediation activities.
  • Synthesise raw vulnerability data into actionable insights, reports, and metrics to support a risk-based security posture.
  • Engineer custom integrations between internal and external platforms to enhance data capture throughout the remediation lifecycle.
  • Maintain strict adherence to global security standards, regulatory requirements, and industry frameworks.
  • Keep at the forefront of the industry by monitoring emerging trends in vulnerability management and shifting regulatory landscapes.
  • Treat security as a continuous engineering challenge to outpace the threat landscape, proactively identifying vulnerabilities and architecting technical solutions to fortify our global ecosystem.
  • Develop and maintain comprehensive technical playbooks and runbooks to standardise vulnerability triage, remediation, and incident response procedures, ensuring consistent, repeatable, and efficient security operations across the team.
  • Utilise pattern and trend analysis to identify "Vulnerability Hotspots" (e.g., recurring issues in specific base Images or teams) to drive strategic risk reduction rather than just individual remediation.

Requirements

Requirements

  • Strong engineering and automation background with a keen interest in Vulnerability Management
  • Strong technical knowledge, including:
  • Cloud Experience (AWS, GCP)
  • Kubernetes and Container experience
  • Infrastructure as code (terraform)
  • Proficiency with at least one programming language (ideally Java, Golang, Python, SQL.)
  • Strong automation skills
  • Proven experience deploying enterprise-scale, cloud-native Vulnerability Management (VM) platforms across complex cloud estatesI ahv
  • Experience with developing integrations by interacting with APIs
  • Ability and willingness to learn new technologies and adapt to evolving security landscapes
  • Capability to understand the bigger picture while effectively managing details
  • Strong written and verbal communication skills to effectively collaborate with cross-functional teams and stakeholders

Additional Technical Requirements

  • Deep understanding of container & orchestration security: practical knowledge of securing containerised environmets, including image scanning, runtime protection, and hardening K8s manifests.
  • Proficiency in cloud posture management: familiarity with tools and frameworks to monitor cloud configuration drift and ensure adherence to security benchmarks (e.g. CIS Benchmarks, AWS/GCP best practices)
  • Riskbased prioritisation models: proven ability to translate raw vulnerability data (CVSS scores, exploitability) into business contextualised risk insights, enabling engineering teams to prioritise remediation effectively.
  • Practical experience in one or more of the vulnerability management fields would be desirable but not essential:
    • Endpoint vulnerability scanning
    • Vulnerability intelligence,
    • AppSec vulnerability management
    • Vulnerability management of cloud native workloads
    • External attack surface management
  • Experience with Software Bill of Materials (SBOM) management, specifically ingesting and correlating standard format

Interview process

Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • First stage with our Information Security Lead
  • Second stage - Take home task
  • Third stage with additional members of the Vulnerability Management and Security Engineering team
  • Final stage with Security Engineering Lead and Information Security Director

Benefits

We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. In Technology, we're asking that you attend the office a minimum of 1 day per week.

  • 25 days holiday (plus take your public holiday allowance whenever works best for you)
  • An extra day’s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

About Us

You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.

Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.

When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.

Create a job alert for this search

Information Security Engineer - Vulnerability Management • Southampton, England, GB

Similar jobs

Principal/Lead Systems Engineer (Security)

LeonardoSouthampton, England, GB
Part-time +1

Principal/Lead Security Systems Engineer.Leonardo – Southampton, England, United Kingdom.Are you a Systems Engineer who loves contributing to the UK’s Defence Industry and making impactful change? ... Show more

 • Promoted • New!

Quality Engineer

Job Board DirectAndover, ENG, GB
Full-time +1

Job type: Permanent, full-time.Salary: £45-55k dependent on experience.Hours of work: Monday to Thursday 08:00 to 17:00 & Friday 08:00 to 14:30, all days with a half hour lunch break.Qual... Show more

 • Promoted

OT Security Engineer

National GridLee-on-the-Solent, England, GB
Full-time

Help secure the systems powering the UK's energy future.Help secure the systems powering the UK's energy future.At National Grid Interconnectors, you'll play a vital role in protecting and maintain... Show more

 • Promoted

Security Engineer - £40,000 - £45,000 A Year

Group IT ServicesBasingstoke And Deane, United Kingdom Of Great Britain And Northern Ireland, UK
Full-time

Were looking for a Security Engineer to come on board to join our team to lead the technical security function within Group IT Services, ensuring robust protection of systems, data and users.You wi... Show more

 • Promoted

Gas Service and Repair Engineer

PH JonesNewport, ENG, GB
Full-time +1

We're so much more than an energy company.We're a family of brands revolutionising how we power the planet.One team of 21,000 colleagues that's energising a greener, fairer future by cr... Show more

 • Promoted

Security Engineer - Local Patch, Growth & Training

Chubb Fire & Security Ltd.Andover, England, GB
Full-time

Security Engineer to cover the Andover region.The role involves conducting routine inspections, performing maintenance on security systems, and providing technical advice to customers.With a base s... Show more

 • Promoted

Cyber Security Starter Course (Southampton)

ITonlinelearning RecruitmentSouthampton, ENG, GB
Part-time

Trainee Cyber Security Course Programme – Job Guarantee Included.Complete online training designed to take you from zero experience to your first Cyber Security role.Study part-time, build fu... Show more

 • Promoted

Principal Engineer, Offshore Structures

Kintec Recruitment LimitedEast End, Hampshire, GB
Permanent

Principal Engineer, Offshore Structures.You could be just the right applicant for this job Read all associated information and make sure to apply.Hybrid working with strong remote flexibility.Inter... Show more

 • Promoted

Security Engineer (CCTV)

Rise Technical RecruitmentThatcham, England, GB
Permanent

Security Engineer (CCTV) — £30,000 - £35,000 DOE + Pension + Holiday + Vehicle + Overtime + Training • Maidenhead.Are you an engineer with experience in the installation, service and maintenance of... Show more

 • Promoted

Engineer - ES Service

Chubb Fire & Security Ltd.Andover, England, GB
Full-time

Engineer - ES ServiceApplylocations: Chubb South Coast, Unit 3, Fulcrum 4, Solent Way, Whiteley, Fareham, Hampshire, PO15 7FT, UK.Full timeposted on: Posted Todayjob requisition id: JR4000517... Show more

 • Promoted

Information Security Engineer - Vulnerability Management

StarlingSouthampton, England, GB
Full-time

Starling is the UK's first and leading digital bank on a mission to fix banking! Our vision is fast technology, fair service, and honest values.All at the tap of a phone, all the time.We are about ... Show more

 • Promoted

Security Engineer - £40,000 - £50,000 A Year

Southern Communications LtdBasingstoke And Deane, United Kingdom Of Great Britain And Northern Ireland, UK
Full-time

Were looking for a Security Engineer to come on board to join our team to lead the technical security function within Group IT Services, ensuring robust protection of systems, data and users.You wi... Show more

 • Promoted

Azure Infrastructure Engineer - Security & Cloud Ops (Remote)

Newsquest Media GroupSouthampton, England, GB
Remote
Full-time

A leading local media publisher in Southampton seeks an associate to design and manage infrastructure services in a remote-first environment.The successful candidate will work with Microsoft Azure,... Show more

 • Promoted

Senior Product Security Engineer — Defence Cyber Resilience

LeonardoSouthampton, England, GB
Full-time

Leonardo UK is hiring a Senior Product Security Engineer to lead product security activities across the engineering lifecycle, collaborating with Electronic Warfare and FCAS teams.The role requires... Show more

 • Promoted

Atlassian Technical Engineer

Stealth IT Consulting LimitedNewport, ENG, GB
Full-time

Telford (2 days/month in office).BPSS + SC eligible required UK National.We are seeking an experienced Atlassian Technical Engineer to configure, maintain and optimise Atlassian tooling, ensuring t... Show more

 • Promoted

Technical Security Engineer

Virgin Media O2Andover, England, GB
Full-time

Location: Andover Job Family: Corporate Functions Job Type: Full Time Posted Date: 22-Jun-2026 Ref #: 73006 Overview As a key member of our Government Security team, you will be at the heart of pro... Show more

 • Promoted

Infrastructure & Technology Cybersecurity Remediation Engineer Professional Hursley, GB

IBMHursley, England, GB
Full-time

The CISO Remediation Team is looking to add a cybersecurity Remediation Engineer as part of the overall Cyber Defense organization.In this role, you will contribute to and, over time, drive the tec... Show more

 • Promoted

Security-Cleared Infrastructure Engineer (Hybrid)

CBSbutler Holdings Limited trading as CBSbutlerRomsey, England, GB
Full-time

CBSbutler Holdings Limited trading as CBSbutler seeks a Hardware Engineer to design, deploy and support secure hardware and infrastructure for mission-critical programmes in a hybrid role (Hampshir... Show more

 • Promoted

Systems Verification & Qualification Engineer

Omega Resource GroupNewtown, Hampshire, GB
Full-time

Systems Verification & Qualification Engineer.Applying for this role is straight forward Scroll down and click on Apply to be considered for this position.Competitive Salary + Bonus + Private Healt... Show more

 • Promoted

Engineer - Electrical

Speedy HireNewport, ENG, GB
Full-time

Speedy are the UKs leading hire provider with the widest range of tools, specialist hire equipment, plant and support services everything for every job!.For us to help you on your journey to succes... Show more