Jobs

Information Security Lead - Vulnerability Management

Starling is the UK’s first and leading digital bank on a mission to fix banking! We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way.

We’re a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company. We’re a bank, but better: fairer, easier to use and designed to demystify money for everyone. We employ more than 3,000 people across our London, Southampton, Cardiff and Manchester offices.

Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be, innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture, you will find support in your team and from across the business, we are in this together!

The way to thrive and shine within Starling is to be a self-driven individual and be able to take full ownership of everything around you: From building things, designing, discovering, to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers. Our purpose is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. We don't like to mandate how much you visit the office and work from home, that's to be agreed upon between you and your manager. 

About the Role

We are seeking a highly motivated and experienced Vulnerability Manager to lead a growing vulnerability management team. A successful candidate will work with the team to analyse emerging vulnerabilities provided by threat intelligence sources and penetration testing. The vulnerability manager will collaborate with various technology and engineering teams to share vulnerability findings, provide guidance, and assist through the remediation process. This person will help present this information in a simple digestible format, and coordinate remediation and mitigation efforts with teams across remote and office locations. There will be opportunities to guide continual improvement of the vulnerability management process.

Responsibilities

  • Lead a team of information security professionals to:
    • Assess, investigate and provide guidance on emerging vulnerabilities, incorporating information from threat intelligence sources, internal software and infrastructure scans.
    • Collate and prioritise applicable vulnerabilities based on Starling Bank’s environmental factors and risk frameworks
    • Collaborate with relevant technology (security, engineering, workplace technology, data, infrastructure) teams to ensure resolution of findings within agreed timeframes.
    • Track and report on progress of mitigations/resolutions to relevant audiences
  • Identify trends and themes in issues which occur and work collaboratively with wider teams to develop process and procedure improvements. 
  • Understand the assets and/or applications at risk from a vulnerability and be able to articulate the potential threat to the Bank in a way anyone in the business could understand.
  • Alignment of risk assessment approach for vulnerabilities to the Bank's risk appetite, operational and information risk frameworks.
  • Promote vulnerability management standards, procedures & guidelines, and best practices outside the security functions.
  • Drive continuous improvement of the vulnerability management approach to ensure prioritisation of tasks is continually effective and mitigating risk to the Bank ongoing.
  • Contribute to the development and enhancement of the Bank’s information risk framework.

Requirements

    • Experience in a similar role leading, developing and motivating a team of subject matter experts
    • Strong written and verbal communication skills to effectively collaborate with cross-functional teams and stakeholders
    • Capability to understand the bigger picture while effectively managing details
    • Ability and willingness to learn new technologies and adapt to evolving security landscapes
    • Practical experience in Vulnerability Management fields, including:
      • Endpoint Vulnerability Scanning
      • Vulnerability Intelligence
      • AppSec Vulnerability Management
      • Vulnerability Management of cloud native workloads
      • External Attack Surface Management
    • Technical knowledge in the following areas is desirable:
      • Cloud (AWS, GCP)
      • Containers
      • MacOS and Windows
      • Data analysis and SQL

Interview process

  • Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:
    • Introductory video call - ~45 minutes
    • Technical video interview - ~1.5 hours
    • Final Interview ~45 minutes

Interview process

Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • Introductory video call - ~45 minutes
  • Technical video interview - ~1.5 hours
  • Final Interview ~45 minutes

Benefits

  • 33 days holiday (including public holidays, which you can take when it works best for you)
  • An extra day’s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Incentives refer a friend scheme
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

About us

You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.

Starling Bank is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice.

By submitting your application, you agree that Starling Bank may collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we may process, where we may process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.

Cyber Security Jobs by Category

Cyber Security Salaries