Skip to Main Content
Location icon
London

Information Security Analyst - SecOps Detection

Starling
Facilities & Security
Facilities & Security
Negotiable
Company logo image
Description

Location
London (Hybrid working with a minimum of 1 day per week in the office)

Hours
Full Time

Salary
Competitive salary offered

About the Role
Starling is the UK's first and leading digital bank on a mission to fix banking by delivering fast technology, fair service, and honest values. With over 3.5 million accounts and 350,000 business customers, we are a multi-award winning, tech-first company focused on innovation and collaboration.

We are seeking a passionate and skilled Detection Engineer and Threat Hunter to join our growing Security Operations team. Reporting to the Information Security Lead - Detection, you will proactively defend Starling’s customers, assets, and systems against emerging threats. Your key responsibilities will include developing, tuning, and maintaining detection rules, conducting intelligence-driven threat hunts, and collaborating in Purple Team exercises to identify and mitigate risks before they impact the bank.

You will work closely with the wider Security Operations team and other stakeholders to uplift Starling's security posture, improve detective controls, and maintain clear documentation for detection rules, hunting playbooks, and processes. This role offers the opportunity to work in a fast-paced, innovative environment where ownership, collaboration, and continuous learning are highly valued.

Requirements

Experience
- Minimum 3 years in a technical security role such as detection engineering, threat hunting, incident response, or threat intelligence.
- Practical experience analysing attacker behavior with strong understanding and application of threat analysis models like MITRE ATT&CK.
- Hands-on experience with SIEM platforms (e.g., Splunk, Google SecOps, Elastic, Sentinel) for rule/query creation and analytics.
- Proven experience conducting proactive threat hunts, defining hypotheses, and developing hunting methodologies.
- Solid knowledge of cloud security risks and detection strategies for AWS, GCP, and Azure.
- Experience with EDR tools such as Crowdstrike, SentinelOne, Cortex XDR.
- Good understanding of OS internals (macOS, Linux, Windows) and network security principles.

About you
- Excellent analytical, problem-solving, and communication skills.
- Self-starter with the ability to lead projects and work collaboratively.
- Eagerness to learn and apply knowledge to new security challenges.
- Strong team player who thrives in a fast-paced, innovative environment.

Qualifications
Preferred but not essential:
- Experience with at least one programming or scripting language (e.g., Python, Go, Bash) for security automation or analysis.
- Experience with container security monitoring (Docker, Kubernetes).
- Experience with Detection-as-Code.
- Experience with SOAR platforms.
- Knowledge of digital forensics and incident response procedures.
- Understanding of malware analysis techniques.
- Relevant certifications such as GIAC Certified Forensic Analyst (GCFA), GIAC Cloud Threat Detection (GCTD), or GIAC iOS and macOS Examiner (GIME) are advantageous.

Expiry date: 26/09/2026
Information Security Analyst - SecOps Detection
Company:
Starling
Job Type:
Full-time
Location:
London