Skip to Main Content
Location icon
London

Information Security Analyst - SecOps Response

Starling
Facilities & Security
Facilities & Security
Negotiable
Company logo image
Description

Location
London (Hybrid working with a minimum of 1 day per week in the office)

Hours
Full Time

Salary
Competitive salary (not specified)

About the Role
Starling is the UK's first and leading digital bank on a mission to fix banking. We combine fast technology, fair service, and honest values to give customers a new way to spend, save, and manage their money while taking better care of the planet. With over 3.5 million accounts and 350,000 business customers, we are a multi-award winning, fully licensed UK bank with a tech-first culture. Our technologists thrive in a fast-paced environment focused on innovation, collaboration, and ownership.

We are seeking a passionate and skilled Incident Responder to join our growing Security Operations team and proactively defend Starling’s customers, assets, and systems against emerging threats. This role supports our 24/7 operational capabilities via an on-call rota. Reporting to the Information Security Lead - SecOps Response, your main responsibilities will include:
- Conducting incident response activities to investigate and contain cybersecurity incidents
- Developing and maintaining incident response and readiness processes
- Analysing logs from various sources (cloud, endpoint, network) to identify root cause and determine next steps for containment, eradication, and recovery
- Planning and participating in Tabletop Exercises
- Documenting notes, analysis findings, containment steps, and causes for each security incident
- Collaborating with other teams to analyse, contain, eradicate, and recover from incidents
- Presenting investigation findings to both technical and non-technical audiences
- Supporting the wider SecOps team with detection engineering and threat hunting

Requirements

Experience
- Minimum 3 years in cyber incident response and digital forensics
- Handling cybersecurity incidents
- Cloud forensics (GCP, AWS)
- Endpoint and server forensics (Windows, MacOS, Linux)
- Network forensics
- Forensics data acquisition, disk forensics, and memory forensics
- Supporting and planning Tabletop Exercises
- Understanding of network, cloud, and operating system security controls
- Excellent verbal and written communication skills, able to explain technical concepts to technical and non-technical audiences
- Demonstrated teamwork and collaboration in multi-functional teams
- Strong time management, problem-solving, and interpersonal skills
- Eagerness to learn and apply knowledge to new security challenges
- Willingness to share knowledge and mentor colleagues

About you
Self-driven, proactive, and passionate about cybersecurity. You thrive in a collaborative environment and take full ownership of your work. You enjoy working in a fast-paced, innovative tech-first company and are motivated to protect customers and assets from emerging threats.

Qualifications
Preferred but not essential:
- Experience with programming or scripting languages such as Python, Go, or Bash
- Experience with container security
- Experience conducting proactive threat hunting, defining hypotheses, and developing hunting methodologies
- Understanding of malware analysis techniques
- Relevant certifications such as GIAC Certified Forensic Analyst (GCFA), GIAC Cloud Forensics Responder (GCFR), GIAC iOS and macOS Examiner (GIME), or 13cubed training in Windows, MacOS, or Linux DFIR
- Other similar training and certifications in digital forensics and incident response

Expiry date: 26/09/2026
Information Security Analyst - SecOps Response
Company:
Starling
Job Type:
Full-time
Location:
London