# Information Security Engineer - Vulnerability Management

**Company**: Starling Bank
**Location**: Southampton
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Category**: IT
**Industry**: Finance

**Apply**: https://apply.workable.com/j/CE9458EF8A?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_22eebdb9-e3e

## Description

Starling Bank is seeking a highly motivated and experienced Vulnerability Management Engineer to join its Cyber Security team. The successful candidate will be responsible for managing vulnerability management tooling and improving existing processes.

Responsibilities:

- Design, build, and maintain robust vulnerability management tooling and technical solutions.

- Drive efficiency by implementing automated solutions that eliminate manual overhead and streamline operations.

- Partner with internal engineering teams and remediators to intelligently prioritise remediation activities.

- Synthesise raw vulnerability data into actionable insights, reports, and metrics to support a risk-based security posture.

- Engineer custom integrations between internal and external platforms to enhance data capture throughout the remediation lifecycle.

- Maintain strict adherence to global security standards, regulatory requirements, and industry frameworks.

- Keep at the forefront of the industry by monitoring emerging trends in vulnerability management and shifting regulatory landscapes.

- Treat security as a continuous engineering challenge to outpace the threat landscape, proactively identifying vulnerabilities and architecting technical solutions to fortify the global ecosystem.

- Develop and maintain comprehensive technical playbooks and runbooks to standardise vulnerability triage, remediation, and incident response procedures.

- Utilise pattern and trend analysis to identify 'Vulnerability Hotspots' to drive strategic risk reduction.

Requirements:

- Strong engineering and automation background with a keen interest in Vulnerability Management.

- Strong technical knowledge, including Cloud Experience (AWS, GCP), Kubernetes and Container experience, Infrastructure as code (terraform), and proficiency with at least one programming language (Java, Golang, Python, SQL).

- Strong automation skills.

- Experience with developing integrations by interacting with APIs.

- Ability and willingness to learn new technologies and adapt to evolving security landscapes.

- Capability to understand the bigger picture while effectively managing details.

- Strong written and verbal communication skills.

Additional Technical Requirements:

- Deep understanding of container & orchestration security.

- Proficiency in cloud posture management.

- Risk-Based prioritisation models.

Benefits:

- 25 days holiday (plus take your public holiday allowance).

- An extra day's holiday for your birthday.

- Annual leave is increased with length of service.

- 16 hours paid volunteering time a year.

- Salary sacrifice, company enhanced pension scheme.

- Life insurance at 4x your salary & group income protection.

- Private Medical Insurance with VitalityHealth.

- Perkbox membership.

## Skills

### Required
- Vulnerability Management
- Cloud Experience
- Kubernetes
- Container experience
- Infrastructure as code
- Programming languages
- Automation skills
- API integration

### Nice to have
- Endpoint vulnerability scanning
- Vulnerability intelligence
- AppSec vulnerability management
- Vulnerability management of cloud native workloads
- External attack surface management
- Software Bill of Materials (SBOM) management

---

Source: [Apply at apply.workable.com](https://apply.workable.com/j/CE9458EF8A?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
