Cloud Security Engineer (Automation & Tooling) - Engine by Starling

New Today

About Engine by Starling

At Engine by Starling, we are on a mission to find and work with leading banks around the world to build rapid growth businesses on our technology. Engine is Starling's software-as-a-service (SaaS) business, built to power Starling Bank, and split out as a separate business a year ago. Our SaaS technology enables banks and financial institutions to benefit from innovative digital features and efficient back-office processes that have supported Starling's success. Our technologists are at the heart of Engine, delivering in a fast-paced environment focused on building, innovation, and disruptive fintech technology.

We operate a flat structure to empower you to make decisions, with collaboration and support across the team and the business. The role rewards self-drive, ownership, and a bias for delivering great results for customers, guided by our values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a hybrid approach; we prefer candidates located within a commutable distance to our offices to enable in-person collaboration when needed.

About the role

As a Cloud Security Engineer at Engine, you will be a hands-on builder responsible for engineering and automating the security of our core platform. Your primary mission is to treat security as an engineering discipline, creating robust, scalable, and automated solutions to protect our cloud infrastructure and development lifecycle. You will spend your time writing code (Go, Python), defining secure infrastructure-as-code (Terraform), and building tooling that ensures our platform is secure by design and compliant by default. This role is for engineers who love to build, automate, and solve complex security problems through code.

You will work on projects covering identity and access management, cloud and network security, vulnerability management, security monitoring, security hardening, compliance reviews, and more. It is a varied role with close interaction across infrastructure, security engineering, cross-cutting and compliance teams. We welcome conversations with experienced Cloud Security Engineers as well as talented Cloud Engineers with strong programming skills who want to apply their knowledge to security challenges. Your place within the team will depend on your strengths and interests.

This role will cover security across multi-tenant SaaS cloud environments and internal infrastructure, requiring a skilled individual to fortify both infrastructure and application platforms against threats.

What you'll get to do

  • Design, build, and maintain security automation and tooling to enforce security controls and simplify compliance (e.g., automating evidence collection for SOC 2, ISO 27001, or PCI DSS)
  • Build, manage, and automate identity and access management controls to ensure secure access to our cloud platforms and applications
  • Write and review Infrastructure-as-Code (Terraform) to securely configure our AWS and GCP environments
  • Secure CI/CD pipelines by implementing and interpreting results from SAST/DAST/SCA tools and ensuring the integrity of our software supply chain
  • Develop and maintain preventative and detective security controls within our cloud environments, responding to and automating remediation of security alerts
  • Implement and automate technical controls based on findings from security assessments, audits, and architecture reviews
  • Engineer solutions to secure Kubernetes environments, focusing on RBAC, network policies, and runtime security
  • Collaborate with engineering teams to implement security best practices and provide hands-on remediation support
  • Contribute to incident response efforts, including investigation, remediation, and post-mortem analysis of security breaches

Requirements

What skills are essential:

  • Strong, demonstrable hands-on experience in a software or infrastructure engineering role
  • A genuine passion for security and a proactive desire to learn about emerging threats, vulnerabilities, and best practices
  • Proficiency in at least one programming language, with a strong preference for Go, followed by Python
  • Solid understanding of cloud security architecture with hands-on experience securing core infrastructure and services in AWS or GCP
  • Experience with Infrastructure-as-Code, specifically Terraform
  • Aptitude for building tools and automating workflows to solve complex problems
  • Understanding of integrating security into the software development lifecycle
  • Experience securing containerised environments (Kubernetes) and CI/CD pipelines (e.g., GitHub Actions, TeamCity)
  • Strong scripting skills in Bash

What skills are desirable, but not essential:

  • Experience creating custom tools or scripts to solve security challenges
  • Knowledge of security principles, technologies, best practices, threat detection and mitigation
  • Understanding of security concepts, common attack vectors (OWASP Top 10, MITRE ATT&CK), and threat landscape
  • Ability to identify threats, attack vectors, and vulnerabilities in systems and applications
  • Experience automating security controls for compliance frameworks like SOC 2, ISO 27001, or PCI DSS
  • Understanding of Kubernetes security, cluster and mesh security (CKA/CKS is a plus), RBAC, andNetworking best practices
  • Container security knowledge including image provenance (e.g., Sigstore, Notary) and container runtimes
  • Strong knowledge of network protocols, firewalls, IDS/IPS and WAFs
  • Experience performing secure code reviews and security approvals including SAST/DAST
  • Security certifications such as AWS Security Specialist or GCP Professional Cloud Security Engineer

Our interview process

Interviewing is a two-way process. Our interviews are conversational and aim to give you and us the opportunity to learn about each other. Typical steps:

  • Initial interview with Staff Security Engineer
  • Take-home technical task
  • Technical interview with Security Engineer peers
  • Final interview with the CTO/ deputy CTO

Benefits

  • 33 days holiday (including public holidays)
  • Birthday day off
  • Annual leave increases with length of service, with option to buy or sell up to five extra days
  • 16 hours paid volunteering per year
  • Salary sacrifice, company enhanced pension
  • Life insurance at 4x salary and group income protection
  • Private Medical Insurance with VitalityHealth, mental health support, cancer care; partner discounts
  • Generous family-friendly policies
  • Refer-a-friend incentives
  • Perkbox and access to wellness and discounts
  • Cycle to work, gym partnerships, EV leasing and related initiatives

Equality and inclusion

Engine by Starling is an equal opportunity employer. We welcome applicants from all backgrounds and experiences and do not discriminate on any protected characteristic. By submitting your application, you consent to us processing your personal data for recruiting in accordance with our Privacy Notice.

#J-18808-Ljbffr
Location:
London, England, United Kingdom
Salary:
£125,000 - £150,000
Job Type:
FullTime
Category:
Engineering

We found some similar jobs based on your search