Location
London (Hybrid model: minimum 1 day per week in office)
Hours
Full Time
Salary
Competitive salary offered
About the Role
Starling is the UK's first and leading digital bank on a mission to fix banking. We combine fast technology, fair service, and honest values to deliver a new way for customers to spend, save, and manage their money while caring for the planet. With over 3,000 employees across multiple UK and Ireland offices, we are a tech-first company focused on innovation and collaboration in fintech.
The Security Architecture team is pivotal in guiding and empowering teams across the organisation. We are seeking a mid-to-senior level Information Security Architect with a strategic focus on Cryptography and Post-Quantum Readiness. This role involves leading Starling’s Post-Quantum Cryptography (PQC) efforts, owning the design of cloud-native and on-premise cryptography roadmaps, conducting cryptographic assessments, driving crypto-agility, and defining technical strategies to protect Starling against emerging quantum threats.
Key responsibilities include leading the PQC strategy, acting as the Cryptography SME, architecting secure solutions across AWS and GCP, leading secure design reviews and threat modeling, developing proofs of concept, collaborating with engineering and security teams, and driving thought leadership within the Security Architecture team.
Experience
- Proven track record as an Information Security Architect or Senior Security Engineer designing secure, distributed systems in modern cloud environments (AWS/GCP).
- Deep expertise in symmetric/asymmetric cryptography, PKI management, digital signatures, key management systems (KMS), and Hardware Security Modules (HSMs).
- Strong knowledge of Post-Quantum Cryptography (PQC), including quantum computing threats, NIST PQC standards, hybrid key exchange, and crypto-agility strategies.
- Demonstrated ability in threat modeling complex cloud-native applications, APIs, and microservices (e.g., Kubernetes, ECS).
- Pragmatic problem solver focused on enabling engineering speed with minimal developer friction.
- Excellent written and verbal communication skills, able to translate complex cryptographic risks into clear guidance for technical teams and senior leadership.
About You
- Self-driven and collaborative with a passion for innovation and security.
- Comfortable working in a fast-paced, flat-structured environment.
- Able to mentor and guide engineering teams on cryptographic implementations and secure data management.
- Interested in staying ahead of industry trends, threat vectors, and regulatory standards.
Desirable
- Experience in fintech, banking, or highly regulated cloud environments (PCI-DSS, ISO 27001, NIST).
- Background in Security Engineering, Infrastructure Engineering, or Penetration Testing.
- Knowledge of infrastructure, application, and AI security (container security, secure code reviews, generative AI/ML integration).
- Practical experience with the SABSA framework for business-driven, risk-aligned security architectures.
- Recognised industry certifications such as SABSA, CISSP, AWS Security Specialty, or specialised cryptography credentials.
Starling







