• Build and support security tooling and infrastructure spanning AWS and GCP that supports internal operations and interfaces with other teams.
• Take a hands-on, builder-focused approach to writing clean, scalable code that automates away manual gates.
• Develop internal tools, guardrails, and services that empower engineering teams to ship securely without sacrificing speed.
📋 Job Requirements
• Demonstrate the ability to architect secure, distributed systems with a focus on programmatic IAM and automated, API-driven PKI management.
• Have extensive experience with Infrastructure as Code in Terraform and a deep commitment to writing clean, maintainable, production-grade code, ideally in Golang.
• Bring a test-first mentality toward security, with experience building unit and integration tests into CI/CD pipelines to ensure security guardrails are as reliable as the features they protect.
• Have a strong conceptual grasp of cryptographic primitives and hands-on experience securing containerised workloads and service meshes within ECS and Kubernetes.
• Hold a track record of taking end-to-end ownership of complex technical projects, from initial design docs and RFCs through to deployment and observability.
• Believe that if it isn't tested it's broken, and proactively identify and fix vulnerabilities by treating security as a continuous engineering challenge.
🌟 Nice-to-have
🎯 Responsibilities
• Lead the design and implementation of critical security services, with a heavy focus on building robust IAM systems and automated, API-driven certificate management workflows.
• Develop and maintain high-quality, scalable security tooling and middleware within ECS and Kubernetes environments, ensuring security logic is integrated directly into the deployment pipeline.
• Serve as a technical authority in cross-functional code reviews, acting as an engineering peer who helps teams bake security into their services from the first line of code to the final pull request.
• Stay ahead of the evolving threat landscape by proactively identifying vulnerabilities and architecting technical solutions to fortify the global ecosystem.
About Starling Bank
😃 What Starling Bank offers
• Get 25 days holiday plus flexible public holidays, with an extra day off for your birthday.
• Earn additional annual leave with length of service, and choose to buy or sell up to five extra days.
• Receive 16 hours paid volunteering time a year.
• Access Private Medical Insurance with VitalityHealth including mental health support and cancer care.
• Receive life insurance at 4x salary and group income protection.
• Benefit from generous family-friendly policies.
• Access Cycle to Work, Salary Sacrificed Gym partnerships, and Electric Vehicle leasing.
• Enjoy a salary sacrifice, company enhanced pension scheme.
• Attend the office a minimum of 1 day per week with hybrid flexibility.
💖 What makes Starling Bank unique
Starling is the UK's first and leading digital bank on a mission to fix banking. Built as a new kind of bank because technology has the power to help people save, spend, and manage their money in a transformative way. Starling is a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company, employing more than 3,000 people across London, Southampton, Cardiff, and Manchester offices. The Security Engineering team is passionate about building secure and resilient systems, making security a seamless part of the development lifecycle.
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.