Location
London (Hybrid working with a minimum of 1 day per week in the office)
Hours
Full Time
Salary
Competitive salary
About the Role
Starling is the UK's first and leading digital bank on a mission to fix banking by delivering fast technology, fair service, and honest values. With over 3.5 million accounts and 350,000 business customers, Starling combines a tech-first approach with a customer-centric vision. Our Cyber Security team is seeking a highly motivated and experienced Vulnerability Management Engineer to manage and improve vulnerability management tooling and processes. You will design, build, and maintain automated solutions, collaborate with engineering teams to prioritise remediation, and synthesise vulnerability data into actionable insights. Your role will involve engineering custom integrations, maintaining compliance with security standards, and developing technical playbooks to standardise security operations. You will proactively identify vulnerabilities and architect solutions to strengthen Starling’s security posture, driving strategic risk reduction through pattern and trend analysis. This role offers the opportunity to work in a fast-paced, innovative environment with a flat structure that empowers ownership and collaboration.
Experience
- Strong engineering and automation background with a keen interest in Vulnerability Management
- Cloud experience (AWS, GCP)
- Kubernetes and container experience
- Infrastructure as code (Terraform)
- Proficiency in at least one programming language (ideally Java, Golang, Python, SQL)
- Strong automation skills
- Experience developing integrations via APIs
- Deep understanding of container and orchestration security including image scanning, runtime protection, and Kubernetes manifest hardening
- Proficiency in cloud posture management and security benchmarks (e.g. CIS Benchmarks, AWS/GCP best practices)
- Ability to translate vulnerability data into business contextualised risk insights for prioritisation
- Practical experience in vulnerability management fields is advantageous
About you
- Ability and willingness to learn new technologies and adapt to evolving security landscapes
- Capability to understand the bigger picture while managing details effectively
- Strong written and verbal communication skills to collaborate with cross-functional teams and stakeholders
- Self-driven with a proactive approach to ownership and problem solving
Qualifications
- No specific formal qualifications required, but relevant technical knowledge and practical experience are essential
- Desirable but not essential: experience with endpoint vulnerability scanning, vulnerability intelligence, AppSec vulnerability management, cloud native workload vulnerability management, external attack surface management, and Software Bill of Materials (SBOM) management
Starling











