Location
London (Hybrid working with a minimum of 1 day per week in the office)
Hours
Full Time
Salary
Competitive salary (details not specified)
About the Role
Starling, the UK's first and leading digital bank, is on a mission to fix banking by delivering fast technology, fair service, and honest values. We are seeking a highly motivated and experienced Vulnerability Management Analyst to join our team. In this role, you will enable remediation groups and engineers to address and resolve outstanding vulnerabilities within agreed timeframes by triaging and prioritising findings using a risk-based approach. You will ensure all assets within the scope of vulnerability management are scanned on schedule and maintain a wide range of vulnerability management tools to ensure their effectiveness.
You will partner with engineering and product teams to translate complex security findings into clear, actionable tasks, coordinate timely remediation efforts, and maintain documentation aligned with compliance requirements and industry best practices such as ISO 27000, PCI-DSS, and NIST. You will build and maintain our vulnerability ecosystem across cloud-native stacks and endpoint security, leveraging automation to reduce manual overhead. Additionally, you will process vulnerability data to provide insightful reports and develop integrations with internal and external tools to streamline the remediation process.
This role requires staying current with the latest trends in vulnerability management, security standards, and emerging threats, acting as a subject matter expert to evolve the team’s defensive strategy alongside the wider security organisation.
Key Responsibilities
- Develop and maintain vulnerability management tooling for cloud-native and on-premise environments
- Lead automation initiatives to reduce manual remediation efforts
- Prioritise vulnerability management activities with internal remediators
- Provide reports, insights, and metrics to support risk-based vulnerability management
- Develop integrations for tools capturing remediation data
- Ensure compliance with relevant security standards and frameworks
- Stay updated on emerging threats and evolving security landscape
- Act as a subject matter expert within the team
What You Can Expect
- Work alongside highly skilled professionals with opportunities for learning and growth
- Supportive and creative environment encouraging initiative and experimentation
- Strong mentorship from senior members and peers
- Collaboration across the wider security organisation and technical teams fostering knowledge sharing
Experience
- Demonstrated vulnerability management experience in roles such as vulnerability analyst, specialist, or engineer
- Strong technical knowledge of cloud platforms (AWS, GCP) and cloud-native security architecture
- Experience with Kubernetes and container security principles
- Security knowledge specific to AWS and GCP
- Basic scripting skills for automation (Python, Go, Bash, etc.)
- Proven ability to develop integrations by interacting with APIs
- Excellent analytical and problem-solving skills to identify vulnerabilities and assess impact
- Strong written and verbal communication skills to collaborate across cross-functional teams
- Adaptability to learn new technologies and evolve with the security landscape
About You
- Self-driven and able to take full ownership of your work
- Collaborative with a passion for innovation and continuous improvement
- Comfortable working in a fast-paced, technology-driven environment
- Enthusiastic about sharing knowledge and supporting team success
Qualifications
Desirable
- Knowledge of CI/CD pipeline management including TeamCity and Jenkins
- Understanding of external attack surface management
- Proficiency in infrastructure as code, specifically Terraform
- Competence in at least one programming language (e.g. Java, Golang, Python) for automation purposes
Interview Process
Our interview process is conversational and designed to be a two-way discussion, allowing you to get to know us as much as we get to know you. Following an initial chat with our Talent Team, you can expect:
- Stage 1: 45 minutes with Information Security Lead
- Stage 2: 60 minutes with two vulnerability team members
- Stage 3: Final interview with Information Security Director and Information Security Lead
Starling











