Jobs Companies Starling Senior Cloud Security Engineer (GCP) - Engine by Starling

Sobre este puesto de Senior Cloud Security Engineer (GCP) - Engine by Starling en Starling

Starling · Presencial · London, England, United Kingdom

At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology. 

Engine is Starling's software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and a year ago we split out as a separate business. 

Starling has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. The Engine technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling's success.

Our technologists are at the very heart of Engine and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be, innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture, you will find support in your team and from across the business, we are in this together!

The way to thrive and shine within Engine is to be a self-driven individual and be able to take full ownership of everything around you: From building things, designing, and discovering to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers. Our purpose is underpinned by five values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a Hybrid approach to working here at Engine – our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. 

About Engineering at Engine by Starling — https://enginebystarling.com/careers/engineering/

As a Security Engineer at Engine, you'll be working on helping to keep our infrastructure secure and compliant and our staff safe and productive. You'll be working on projects covering identity and access management, cloud and network security, vulnerability management, security monitoring, security hardening, compliance reviews, and more. It's a very varied role with lots of close interaction with the infrastructure, security engineering, cross-cutting and compliance teams.

We are looking for an experienced Senior level GCP Security Engineer to join our established Security Engineering team, working closely with Information Security, Infrastructure and the various Engine Technology teams to make sure security is at the heart of all our technical processes. As our subject matter expert, you will take ownership of engineering the security foundations of our Google Cloud Platform environment. This is a hands-on role for a specialist with a proven track record of designing, building, and automating security controls specifically for GCP, including hardened GKE clusters.

Engine by Starling engineers are excited about helping us deliver new features, regardless of what their primary tech stack may be. Hear from the team in our latest Blog or our case studies with Women in Tech.

As a GCP Security Engineer, you will:

  • Collaborate with stakeholders to define our Google Cloud security architecture (cloud identity, runtime security, security posture)
  • Design, document, build and maintain a secure and scalable infrastructure on GCP using Infrastructure as Code
  • Be part of the team responsible for safeguarding our systems, applications and data by ensuring secure user access, authentication and authorisation mechanisms are in place
  • Engineer and automate technical controls within GCP to ensure and demonstrate continuous compliance with stringent standards such as PCI DSS and 3DS
  • Drive security infrastructure deployments across our growing environments
  • Perform regular security assessments, audits, threat modelling and architecture design reviews to identify risks and vulnerabilities, triage found risks, identify improvements appropriately and design controls to implement as corrective actions
  • Lead incident response efforts, including investigation and remediation of security breaches
  • Support our internal security awareness and training programs, advocating the DevSecOps mindset that we have created across our technology teams

Requirements

We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. If you have an innate passion for security and care enough to find elegant solutions to difficult problems, we'd love to hear from you.

What skills are essential:

  • Mature understanding of cloud security architecture, with deep expertise in GCP and a proven track record
  • Experience creating a GCP landing zone, configuring services such as organisation policies and VPC Service Controls
  • A deep understanding of GCP IAM and its limitations
  • Experience with service-oriented architecture using containers, distributed systems and immutable infrastructure on GCP (including GKE, Compute Engine, Shared VPC and Cloud SQL)
  • Expertise in Kubernetes, securing clusters (GKE) and meshes (Cilium is preferable), networking best practices and RBAC implementation (CKA, CKS qualifications are a plus)
  • Experience with Infrastructure as Code and infrastructure provisioning tools, particularly Terraform
  • Experience configuring GCP-native security posture and threat management with Security Command Center
  • Experience securing the software supply chain with Binary Authorization, Artifact Registry and Artifact Analysis
  • Experience with key and secret management on GCP — Cloud KMS, Cloud External Key Manager (EKM) and Secret Manager — including cryptographic key ceremonies
  • Experience with Workload Identity and Workload Identity Federation for keyless authentication of workloads and CI/CD
  • Experience configuring and utilising cloud-native security logging, monitoring and detection services
  • Strong programming skills — in security we write our own scripts for automation in Python, Go and other languages while contributing to open-source tools so we can utilise them
  • In-depth knowledge of security principles, technologies, best practices, and threat detection and mitigation strategies
  • Knowledge of common attack vectors and methodologies (OWASP Top 10, MITRE ATT&CK Framework and social engineering tactics)
  • The ability to identify potential threats, attack vectors and vulnerabilities in systems and applications
  • The ability to document security requirements from various stakeholders
  • Excellent problem-solving, communication and active listening skills with an innate passion for security
  • The ability to identify security gaps and create solutions to minimise risk and impact to us
  • A proactive approach to staying updated with the latest security threats, vulnerabilities and mitigation techniques
  • Thorough understanding of the incident response process (preparation, identification, containment, eradication, recovery, lessons learned)

What skills are desirable:

  • In-depth knowledge of network security, including core routing and switching concepts (TCP/IP, BGP, VPNs), security controls (firewalls, WAFs, IDS/IPS), and practical experience designing hybrid connectivity between GCP and on-premise environments
  • Experience with data-residency and regulated-workload controls such as Assured Workloads and Access Transparency, relevant to deploying per-market for different banks' regulators
  • Hands-on experience taking a company through security and compliance frameworks like NIST, SOC 2, ISO 27001 and PCI DSS
  • Experience automating security controls and compliance checks against standards and frameworks including SOC 2, ISO 27001 and PCI DSS / 3DS
  • Container security knowledge including container image provenance (e.g. Sigstore, Notary) with an in-depth knowledge of container runtimes, and an understanding of integrating security into the software development lifecycle
  • Experience performing secure code reviews and security approvals, including the use of static and dynamic application security testing (SAST / DAST) tools
  • Experience in cryptography management and enhancements
  • Relevant security certifications such as ISC2 CC, CISSP, CCSP, CISM, AWS Security Specialty or GCP Professional Cloud Security Engineer

The main part of our tech stack is listed below. We don't ask that you have experience in all of it, but if you do, that's great!

  • Java, which makes up the majority of our backend codebase
  • GCP and AWS — we're cloud-native
  • Microservice-based architecture
  • Kubernetes (GKE on GCP, EKS on AWS)
  • TeamCity for CI/CD (with multiple production releases per day)
  • Terraform and Grafana
  • RDS and CloudSQL for PostgreSQL

Our Interview Process:

Interviewing is a two-way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • Initial interview with an Engineer — ~45 minutes
  • Take-home technical test, to be discussed in the next interview
  • Technical interview with some Engineers — ~1.5 hours
  • Final interview with our CTO / deputy CTO — ~45 minutes

Benefits

  • 33 days holiday (including public holidays, which you can take when it works best for you)
  • An extra day’s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Incentives refer a friend scheme
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

About Us

You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.

Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. 

When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Engine by Starling and Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.

We use AI tools to support various parts of our recruitment process, helping our team manage applications and assessments more efficiently. These tools are strictly used for support and do not replace human judgment with all final hiring decisions being made by our team. If you would like more information about how your data is processed, please reach out to us.

¿Listo para postularte en Starling?
Postúlate en Starling

Sobre Starling

Join our team

We’re on a mission to radically reshape banking – and that starts with our brilliant team. We know that our bank is only as good as the people who build it. From customer support and engineering to marketing and business development, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.


What to expect

Creativity and collaboration

We’re growing fast – and no two days here at Starling are quite the same. We care about getting stuff done, not process, and our culture is decidedly entrepreneurial in spirit (you’ll be encouraged to pitch your ideas, however big or bold!). It’s a fast-paced, exciting and creative place to work where there’s plenty of collaboration and ownership of your own projects.

Great tech

As you’d expect from a technology company, we’ll make sure you have all the tools you need to get your job done – and that they’re the very best in the business. We work on MacBooks and you’ll receive anything else you might need on request.

An open approach

Lots of companies talk about transparency – but it’s something we really care about. We communicate and collaborate through Slack, including a channel dedicated to updates from the leadership team.

But wait... there’s more

It’s important to us there’s more to life here than just work, so get to know your colleagues at socials, cheese & wine nights or learning lunches. Enjoy fresh fruit and coffee every day, free breakfasts and Perkbox, through which we offer the Cycle to Work scheme and salary-sacrificed gym memberships. We also offer private health insurance for all employees.

We offer 33 days holiday (including public hols), plus an extra day on your birthday; you also get 16 hours of paid leave a year to do voluntary work.


Ready to come on board?

Browse our current openings below.

Ver todos los empleos en Starling →

Empleos similares

Roblox
Senior Security Engineer, Detection and Response
Roblox
⚡ Postúlate pronto London, England, United Kingdo... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 15h
Starling
Staff Cloud Security Engineer (GCP) - Engine by Starling
Starling
⚡ Postúlate pronto London, England, United Kingdo... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 22h
xAI
Sr. Security Engineer - GRC Fintech & Financial Services EU/UK
xAI
⚡ Postúlate pronto Dublin, Ireland; London, Engla... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 2d
xAI
Infrastructure Security Engineer
xAI
⚡ Postúlate pronto Palo Alto, CA; Austin, TX; Lo... Presencial $100,000–$258,000
● Nuevo 👁 Visto ✓ Postulado hace 2d
Appvia
Network Engineer - Active UK Government Security Clearance Required
Appvia
⚡ Postúlate pronto London, England, United Kingdo... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 3d
Anduril Industries
Senior Product Security Engineer
Anduril Industries
⚡ Postúlate pronto London, England, United Kingdo... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 3d
Anduril Industries
Staff Product Security Engineer
Anduril Industries
⚡ Postúlate pronto London, England, United Kingdo... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 3d
Appvia
Senior Cloud Network Engineer - Active UK Government Security Clearance Required
Appvia
⚡ Postúlate pronto London, England, United Kingdo... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 1sem
Solirius Reply
Senior Data Engineer - Security Cleared
Solirius Reply
⚡ Postúlate pronto London, England, United Kingdo... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 1sem

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Starling

Ver todos los empleos en Starling →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis