Skip to Main Content
Location icon
London

Information Security Engineer - Vulnerability Management

Starling
Facilities & Security
Facilities & Security
Negotiable
Company logo image
Description

Location
London (Hybrid working with a minimum of 1 day per week in the office)

Hours
Full Time

Salary
Competitive salary

About the Role
Starling is the UK's first and leading digital bank on a mission to fix banking by delivering fast technology, fair service, and honest values. With over 3.5 million accounts and 350,000 business customers, Starling combines a tech-first approach with a customer-centric vision. Our Cyber Security team is seeking a highly motivated and experienced Vulnerability Management Engineer to manage and improve vulnerability management tooling and processes. You will design, build, and maintain automated solutions, collaborate with engineering teams to prioritise remediation, and synthesise vulnerability data into actionable insights. Your role will involve engineering custom integrations, maintaining compliance with security standards, and developing technical playbooks to standardise security operations. You will proactively identify vulnerabilities and architect solutions to strengthen Starling’s security posture, driving strategic risk reduction through pattern and trend analysis. This role offers the opportunity to work in a fast-paced, innovative environment with a flat structure that empowers ownership and collaboration.

Requirements

Experience
- Strong engineering and automation background with a keen interest in Vulnerability Management
- Cloud experience (AWS, GCP)
- Kubernetes and container experience
- Infrastructure as code (Terraform)
- Proficiency in at least one programming language (ideally Java, Golang, Python, SQL)
- Strong automation skills
- Experience developing integrations via APIs
- Deep understanding of container and orchestration security including image scanning, runtime protection, and Kubernetes manifest hardening
- Proficiency in cloud posture management and security benchmarks (e.g. CIS Benchmarks, AWS/GCP best practices)
- Ability to translate vulnerability data into business contextualised risk insights for prioritisation
- Practical experience in vulnerability management fields is advantageous

About you
- Ability and willingness to learn new technologies and adapt to evolving security landscapes
- Capability to understand the bigger picture while managing details effectively
- Strong written and verbal communication skills to collaborate with cross-functional teams and stakeholders
- Self-driven with a proactive approach to ownership and problem solving

Qualifications
- No specific formal qualifications required, but relevant technical knowledge and practical experience are essential
- Desirable but not essential: experience with endpoint vulnerability scanning, vulnerability intelligence, AppSec vulnerability management, cloud native workload vulnerability management, external attack surface management, and Software Bill of Materials (SBOM) management

Expiry date: 15/08/2026
Information Security Engineer - Vulnerability Management
Company:
Starling
Job Type:
Full-time
Location:
London