Auf einen Blick
- Aufgaben: Entwickle und verwalte Tools zur Schwachstellenverwaltung in einem dynamischen Team.
- Unternehmen: Starling, die führende digitale Bank im Vereinigten Königreich mit innovativer Kultur.
- Vorteile: 25 Tage Urlaub, flexible Arbeitszeiten, private Krankenversicherung und viele weitere Vorteile.
- Weitere Informationen: Offene Unternehmenskultur mit großartigen Entwicklungsmöglichkeiten und einem unterstützenden Team.
- Warum dieser Job: Sei Teil einer revolutionären Bank und forme die Zukunft des Bankings mit modernster Technologie.
- Qualifikationen: Erfahrung in der Softwareentwicklung und Interesse an Schwachstellenmanagement.
Das prognostizierte Gehalt liegt zwischen 46350 - 56650 € pro Jahr.
Starling is the UK's first and leading digital bank on a mission to fix banking!
Our vision is fast technology, fair service, and honest values.
All at the tap of a phone, all the time.
We are about giving customers a new way to spend, save and manage their money while taking better care of the planet which has seen us become a multi-award winning bank that now employs over 2800 across five offices in London, Cardiff, Dublin, Southampton, and Manchester.
Our journey started in 2014, and since then we have surpassed 3.5 million accounts (and four account types!) with 350,000 business customers.
We are a fully licensed UK bank but at the heart, we are a tech first company, enabling our platform to deliver brilliant products.
Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech.
We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be, innovation and collaboration will be at the core of everything you do.
Help is never far away in our open culture, you will find support in your team and from across the business, we are in this together!
The way to thrive and shine within Starling is to be a self-driven individual and be able to take full ownership of everything around you: From building things, designing, discovering, to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers.
Our purpose is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.
Hybrid Working
We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person.
In Technology, we're asking that you attend the office a minimum of 1 day per week.
About the Role
We are seeking a highly motivated and experienced Vulnerability Management Engineer to join our Cyber Security team.
As a Vulnerability Management Engineer, your primary responsibility will be to manage vulnerability management tooling, and have an active role in improving existing processes.
You will achieve this by creating automated solutions through collaboration with technical teams across Starling.
Responsibilities
- Design, build, and maintain robust vulnerability management tooling and technical solutions.
- Drive efficiency by implementing automated solutions that eliminate manual overhead and streamline operations.
- Partner with internal engineering teams and remediators to intelligently prioritise remediation activities.
- Synthesise raw vulnerability data into actionable insights, reports, and metrics to support a risk-based security posture.
- Engineer custom integrations between internal and external platforms to enhance data capture throughout the remediation lifecycle.
- Maintain strict adherence to global security standards, regulatory requirements, and industry frameworks.
- Keep at the forefront of the industry by monitoring emerging trends in vulnerability management and shifting regulatory landscapes.
- Treat security as a continuous engineering challenge to outpace the threat landscape, proactively identifying vulnerabilities and architecting technical solutions to fortify our global ecosystem.
- Develop and maintain comprehensive technical playbooks and runbooks to standardise vulnerability triage, remediation, and incident response procedures, ensuring consistent, repeatable, and efficient security operations across the team.
- Utilise pattern and trend analysis to identify "Vulnerability Hotspots" (e. g., recurring issues in specific base Images or teams) to drive strategic risk reduction rather than just individual remediation.
- Key Skills and Experience
- Strong engineering and automation background with a keen interest in Vulnerability Management
• Strong technical knowledge, including
- Cloud Experience (AWS, GCP)
- Kubernetes and Container experience
- Infrastructure as code (terraform)
- Proficiency with at least one programming language (ideally Java, Golang, Python, SQL.)
- Strong automation skills
- Experience with developing integrations by interacting with APIs
- Ability and willingness to learn new technologies and adapt to evolving security landscapes
- Capability to understand the bigger picture while effectively managing details
- Strong written and verbal communication skills to effectively collaborate with cross-functional teams and stakeholders
- Additional Technical Requirements
- Deep understanding of container & orchestration security: practical knowledge of securing containerised environments, including image scanning, runtime protection, and hardening K8s manifests.
- Proficiency in cloud posture management: familiarity with tools and frameworks to monitor cloud configuration drift and ensure adherence to security benchmarks (e. g.
CIS Benchmarks, AWS/GCP best practices).
- Risk-Based prioritisation models: proven ability to translate raw vulnerability data (CVSS scores, exploitability) into business contextualised risk insights, enabling engineering teams to prioritise remediation effectively.
- Practical experience in one or more of the vulnerability management fields would be
Desirable but not essential
- Endpoint vulnerability scanning, vulnerability intelligence, App Sec vulnerability management, vulnerability management of cloud native workloads, external attack surface management
- Experience with Software Bill of Materials (SBOM) management, specifically ingesting and correlating standard formats
- Interview process
- First stage with the Penetration Testing and Vulnerability Management Lead
- Second stage with additional members of the Vulnerability Management and Security Engineering team
- Final stage with Security Engineering Lead and Information Security Director
We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person.
In Technology, we're asking that you attend the office a minimum of 1 day per week.
Benefits
- 25 days holiday (plus take your public holiday allowance whenever works best for you)
- An extra day’s holiday for your birthday
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
- 16 hours paid volunteering time a year
- Salary sacrifice, company enhanced pension scheme
- Life insurance at 4x your salary & group income protection
- Private Medical Insurance with Vitality Health including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
- Generous family-friendly policies
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
- Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
About Us
You may be put off applying for a role because you don't tick every box.
Forget that!
While we can’t accommodate every flexible working request, we're always open to discussion.
So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway.
We’re on a mission to radically reshape banking – and that starts with our brilliant team.
Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.
Equal Opportunity
Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace.
Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.
When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice.
By submitting your application, you agree that Starling Bank will collect your personal data for recruiting and related purposes.
Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal data.
#J-18808-Ljbffr
Information Security Engineer - Vulnerability Management Arbeitgeber: Starling
Starling ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern die Möglichkeit bietet, in einem dynamischen und innovativen Umfeld zu arbeiten. Mit einer offenen Unternehmenskultur, die Zusammenarbeit und Eigenverantwortung fördert, sowie umfangreichen Vorteilen wie flexiblen Arbeitszeiten, großzügigen Urlaubsregelungen und einem starken Fokus auf persönliche Entwicklung, ist Starling der ideale Ort für Fachkräfte im Bereich Informationssicherheit, die ihre Karriere vorantreiben möchten. Zudem profitieren Mitarbeiter von einem hybriden Arbeitsmodell, das eine ausgewogene Work-Life-Balance ermöglicht und die Interaktion mit Kollegen fördert.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Information Security Engineer - Vulnerability Management erhalten könntest
✨Schau dir aktuelle Stellenmessen an!
In der Bankenbranche gibt's regelmäßig Karriere-Events und Messen. Nimm die Chance wahr, um direkt mit Unternehmen in Kontakt zu treten, die potenziell nach neuen Talenten wie dir suchen. So kannst du einen persönlichen Eindruck hinterlassen und dich vom Rest der Bewerber abheben!
✨Nutze Fachnetzwerke in der Finanzwelt
Schau dir spezielle Plattformen oder Gruppen an, die sich auf die Finanz- und Bankenbranche konzentrieren. Communities wie Xing oder relevante LinkedIn-Gruppen bieten oft Stellenangebote oder interne Empfehlungen an, die nicht auf den großen Jobbörsen zu finden sind.
✨Informiere dich über aktuelle Trends
Das Bankwesen verändert sich ständig, vor allem mit dem Aufkommen von FinTechs. Halte dich über neue Technologien und Trends auf dem Laufenden, damit du in Gesprächen mit Recruitern glänzen kannst. Es zeigt Leidenschaft und Engagement für das Feld!
✨Bewirb dich direkt über unsere Website
Hier bei StudySmarter haben wir viele wertvolle Ressourcen und Jobangebote im Bankwesen. Schau regelmäßig vorbei und bewirb dich direkt über unsere Plattform. So hast du die beste Chance auf den Job deiner Träume und bist immer auf dem neuesten Stand!
Wir glauben, dass du diese Fähigkeiten brauchst, um Information Security Engineer - Vulnerability Management mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Hebe deine Qualifikationen hervor:Im Bankwesen sind quantitative Fähigkeiten und relevante Abschlüsse von großer Bedeutung. Stelle sicher, dass du deinen Hochschulabschluss in Wirtschaft, Finanzen oder einem ähnlichen Bereich klar und ansprechend in deinem Lebenslauf präsentierst. Eventuelle Zertifikate wie CFA oder Bankwesen-spezifische Schulungen können ebenfalls einen großen Pluspunkt darstellen!
Verwende konkrete Erfolge:Wenn du bereits Erfahrung im Bankbereich hast, zögere nicht, konkrete Ergebnisse in deinem Lebenslauf zu kommunizieren. Zeige, wie du zum Beispiel die Effizienz eines bestimmten Prozesses steigern oder zur Gewinnmaximierung deines vorherigen Unternehmens beitragen konntest. Zahlen sagen mehr als Worte!
Motivation klar kommunizieren:Da dies eine Vollzeitstelle ist, solltest du in deinem Bewerbungsschreiben deutlich machen, warum du gerade bei Starling arbeiten möchtest. Erkläre, was dich an der Bank und der Position als Information Security Engineer - Vulnerability Management besonders interessiert und wie deine Ziele mit denen des Unternehmens übereinstimmen.
Netzwerk und Verbände nutzen:Im Bankwesen ist es oft hilfreich, Netzwerke zu nutzen. Erwähne in deinem Bewerbungsschreiben etwaige Verbindungen zu Branchenverbänden oder spezielle Netzwerke, zu denen du gehörst. Das zeigt nicht nur dein Engagement, sondern kann dir auch einen Vorteil verschaffen. Wenn du Begeisterung für den Sektor zeigen kannst, finden wir das super!
Wie man sich auf ein Vorstellungsgespräch bei Starling vorbereitet
✨Verstehe die Finanzinstrumente
Im Bankenbereich ist es super wichtig, ein gutes Verständnis für verschiedene Finanzinstrumente wie Aktien, Anleihen und Derivate zu haben. Bereite dich darauf vor, technische Fragen über deren Funktionsweise sowie die aktuellen Markttrends bei Starling zu beantworten.
✨Analytische Fähigkeiten zeigen
Stelle sicher, dass du deine analytischen Fähigkeiten durch konkrete Beispiele demonstrieren kannst. Bereite dich auf Fallstudien vor, die typischerweise in Interviews im Bankenbereich vorkommen. Zeige, wie du vergangene Probleme gelöst hast und welche Tools du dabei verwendet hast.
✨Erstelle ein starkes Portfolio
Auch wenn es sich um eine Vollzeitstelle handelt, kann ein Portfolio von Projekten oder Erfahrungen im Finanzbereich sehr hilfreich sein. Zeige deine theoretischen Kenntnisse und praktischen Erfahrungen, um zu zeigen, was du für Starling leisten kannst.
✨Soft Skills im Fokus
Vergiss nicht, auch über deine Soft Skills zu sprechen! Teamarbeit und Kommunikationsfähigkeit sind im Bankenwesen unerlässlich. Bereite Anekdoten vor, die zeigen, wie du im Team gearbeitet hast oder schwierige Situationen mit Kunden gemeistert hast.