• Enable remediation groups and engineers to address and resolve outstanding findings within agreed timeframes.
• Effectively triage and prioritise vulnerabilities using a risk-based approach.
• Ensure all assets within the scope of vulnerability management are scanned within agreed time frames.
• Build and maintain the vulnerability ecosystem from cloud-native stacks to endpoint security, using automation to reduce manual overhead.
📋 Job Requirements
• Have demonstrated vulnerability management experience in a role such as vulnerability analyst, specialist, or engineer.
• Have strong technical knowledge of cloud platforms including AWS and GCP and cloud-native security architecture.
• Have experience with Kubernetes and container security principles.
• Have basic scripting skills for automation purposes in Python, Go, Bash, or similar.
• Have proven ability to develop integrations by interacting with APIs.
• Demonstrate excellent analytical and problem-solving skills to identify vulnerabilities and assess potential impact.
• Have strong written and verbal communication skills to foster collaboration across cross-functional teams and stakeholders.
• Show adaptability to learn new technologies and evolve alongside the security landscape.
🌟 Nice-to-have
• Have knowledge of CI/CD pipelines management including TeamCity and Jenkins.
• Have knowledge of external attack surface management.
• Be proficient in infrastructure as code, specifically Terraform.
• Be competent in at least one programming language such as Java, Golang, or Python for automation.
🎯 Responsibilities
• Partner with engineering and product teams to bridge the gap between security discovery and resolution, turning complex findings into clear, actionable tasks.
• Utilise a risk-based approach to prioritise vulnerabilities based on their potential impact and exploitability.
• Coordinate with resolver groups to ensure timely and efficient remediation of identified vulnerabilities.
• Maintain and update a wide range of Vulnerability Management tools including Build Phase VM, CWPP, Endpoint VM, and VM Intelligence.
• Review and update Vulnerability Management related documentation to align with internal and external compliance requirements and industry best practices such as ISO 27000, PCI-DSS, and NIST.
• Build and maintain the vulnerability ecosystem from cloud-native stacks to endpoint security, using automation to reduce manual overhead.
• Process vulnerability data to provide reports, insights, and metrics that aid in the risk-based approach to vulnerability management.
• Develop integrations for internal and external tools to capture data relevant to the vulnerability remediation process.
• Lead the shift towards automated remediation by implementing integrations that reduce manual toil for engineering teams.
• Act as a subject matter expert, staying ahead of emerging threats and evolving the team's defensive strategy alongside the wider security organisation.
About Starling Bank
😃 What Starling Bank offers
• Get 25 days holiday plus flexible public holidays, with an extra day off for your birthday.
• Earn additional annual leave with length of service, and choose to buy or sell up to five extra days.
• Receive 16 hours paid volunteering time a year.
• Access Private Medical Insurance with VitalityHealth including mental health support and cancer care.
• Receive life insurance at 4x salary and group income protection.
• Benefit from generous family-friendly policies.
• Access Cycle to Work, Salary Sacrificed Gym partnerships, and Electric Vehicle leasing.
• Enjoy a salary sacrifice, company enhanced pension scheme.
• Attend the office a minimum of 1 day per week with hybrid flexibility.
💖 What makes Starling Bank unique
Starling is the UK's first and leading digital bank on a mission to fix banking. Built as a new kind of bank because technology has the power to help people save, spend, and manage their money in a transformative way. Starling is a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company, employing over 2,800 people across London, Southampton, Cardiff, Dublin, and Manchester offices.
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.