Overview

At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology. 

Engine is Starling’s software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and a year ago we split out as a separate business. 

Starling Bank has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling’s success.

We draw upon our experience as knowledgeable bankers, and best in class technologists to become the chosen option for these banks, and preferred partners for leading consultancies.

As a company, everyone is expected to roll up their sleeves to help deliver great outcomes for our clients. We are an engineering led company and we’re looking for someone who will be excited by the potential for Engine’s technology to transform banking in different markets around the world.

Hybrid Working

We have a Hybrid approach to working here at Engine – our preference is that you’re located within a commutable distance of one of our offices so that we’re able to interact and collaborate in person. We don’t like to mandate how much you visit the office and work from home, that’s to be agreed upon between you and your manager. 

About Engineering at Engine by Starling – https://www.enginebystarling.com/ 

Engine by Starling engineers are excited about helping us deliver new features, regardless of what their primary tech stack may be. Hear from the team in our latest Blog or our case studies with Women in Tech.

We are looking for engineers at all levels to join the team. We value people being engaged and caring about customers, caring about the code they write and the contribution they can make to banking around the world. People with a broad ability to apply themselves to a multitude of problems and challenges, who can work across teams do great things here at Engine, to continue changing banking for good.

About the Role

As a Workplace Security Engineer at Engine, you’ll be working on company-facing security, helping to keep our staff safe and productive and our systems secure and compliant.

You’ll be working on projects covering identity and access management, endpoint security, office infrastructure, data loss prevention, security hardening, compliance reviews, and more.  It’s a very varied role with lots of close interaction with the infrastructure, security engineering, cross cutting and compliance teams.

What you’ll get to do:

  • You will be responsible for safeguarding our systems, applications, and data by ensuring secure user access, authentication, and authorisation mechanisms are in place
  • Manage IAM with Okta Identity Engine, create access control policies, ensure proper implementation of least privilege and RBAC across internal and SaaS applications
  • Manage security within Google Workspace and our email security platform, including initiatives such as establishing a secure configuration posture validating against CIS Benchmarks
  • Manage security controls across our MacOS estate, including MDM configuration profiles
  • Wherever possible, deploy and manage systems with Infrastructure as Code and other automation to minimise configuration-by-clicking
  • Work in a fast paced environment. We don’t release out-of-hours, we deploy during the day using safe methods that do not cause impact
  • Perform regular security assessments and audits to identify risks and vulnerabilities, triage found risks appropriately, then design controls to implement as corrective actions
  • Work with the compliance team to conduct third party SaaS security reviews and support other compliance initiatives such as SOC 2, ISO27001 and PCI-DSS
  • Collaborate with infrastructure, security engineering, cross cutting and compliance teams on ongoing projects
  • Lead incident response efforts, including investigation and remediation of security breaches
  • Support our internal security awareness and training programs
  • Spearhead workplace security initiatives, plan projects and track their progress
  • Develop services for the future, automating and simplifying them, as well as making them more robust and secure using Infrastructure as Code where possible
  • SaaS vendors constantly release new features – you will help to keep up and preferably stay ahead with our own feature requests to them
  • Keeping abreast of new technologies and changes in the industry
  • We provide a 24×7 global service. As a SME you might be called to help in exceptional circumstances.

Requirements

What skills are essential:

  • Strong understanding of identity federation (SAML, OAuth, OpenID Connect, etc.)
  • Experience with Identity and Access Management policy application and enforcement
  • Strong understanding of standard corporate IT systems such as office networks, physical security systems, email and DNS configuration, file sharing systems, etc
  • Experience designing, implementing, and managing IAM solutions
  • Experience with Infrastructure as Code and infrastructure provisioning tools (Cloudformation, Terraform).
  • Experience as an administrator of various enterprise SaaS applications
  • Experience independently managing short and long term projects
  • Experience with creating automations, using a scripting language like Python
  • Good discipline with regard to the effective and safe testing and release of changes

What skills are desirable:

  • Experience with SaaS security (Google Workspace, Atlassian, etc.)
  • Experience with Zero Trust security (MTLS, SCEP)
  • Hands-on experience as an administrator on some or all of the following types of tools: EDR, MDM, SIEM, Okta, Google Workspace, EntraID solutions
  • Knowledge of security and compliance frameworks like NIST, SOC2, ISO270001, PCI-DSS
  • Experience performing risk assessments, gap assessments, and threat modelling
  • A strong understanding of networking concepts, application security, authentication & authorization and cloud security best practice
  • Strong knowledge of overall security concepts and best practices
  • Experience with cloud platforms such as AWS, GCP, Azure
  • Relevant security certifications such as Okta Certified Professional, Security+, ISC2 Certified in Cybersecurity preferred but not required

Interview process

Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • Initial interview – ~45 minutes
  • Technical interview – 1 hours
  • Final Interview ~45 minutes

Benefits

  • 33 days holiday (including public holidays, which you can take when it works best for you)
  • An extra day’s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Incentives refer a friend scheme
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

You may be put off applying for a role because you don’t tick every box. Forget that! While we can’t accommodate every flexible working request, we’re always open to discussion. So, if you’re excited about working with us, but aren’t sure if you’re 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.

Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. 

When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Engine by Starling and Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.

Before you apply -
Register now and turn on alerts for jobs like this!

By registering you agree to our terms and conditions.

No thanks, continue to apply