Information Security Operations Lead (Sydney, Australia)

Starling

Sydney

Hybrid

AUD 150,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

25 days holiday
Perkbox
Volunteer time

Job summary

Starling is seeking an experienced SOC Team Lead to drive incident response and security operations. You will lead a team of SecOps professionals across Sydney and Toronto, coordinating with UK colleagues to protect customers and assets. Hybrid work is supported, with a preference for Sydney-based activity.

Strong leadership, cloud and SIEM expertise are essential. You will mentor analysts, triage incidents, and develop ready-to-run processes while communicating technical findings to diverse

Qualifications

  • 5+ years in an in-house SOC role with incident response and digital forensics.
  • Proven experience leading a team of subject matter experts and managers.
  • Understanding of AWS/GCP cloud security and related tooling.
  • Experience with analytics/SIEM platforms and incident response engagements.
  • Experience with endpoint and cloud investigations and incident command.

Responsibilities

  • Lead a team of analysts to ensure information security aligns with policy.
  • Oversee incident triage, response and investigations from multiple sources.
  • Interpret logs from cloud, endpoint and network sources to identify root causes.
  • Develop and maintain incident handling, response and readiness processes.
  • Coordinate with other teams to contain and recover from security incidents.
  • Plan Tabletop Exercises and present findings to technical and non‑technical audiences.

Skills

SOC leadership
Incident response
Cloud security
SIEM experience
Tabletop exercises
Communication skills
Mentoring
Cross-functional collaboration

Tools

AWS Security Solutions
GCP security tooling
EDR tooling

Job description

We are Starling. We started by building a new kind of bank because we knew technology had the power to transform how people save, spend, and manage their money. Today, our ambition and our footprint have grown.

Our ecosystem encompasses our pioneering, fully licensed UK bank (Starling), our global Software-as-a-Service technology platform (Engine by Starling), alongside a growing portfolio of specialist financial and software businesses.

While our roots are in the UK, our operations are expanding globally. Though you may be based in one of our international offices (such as Sydney or Toronto), this role is critical to the entire Starling Group. The work you do will support, empower, and protect our businesses worldwide.

Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and leveraging disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to enable you to make decisions regardless of your location or primary responsibilities; innovation and collaboration will be at the core of everything you do. Help is never far away in our open, borderless culture - you will find support in your team and from across the global business. We are in this together!

The way to thrive and shine within Starling is to be a self-driven individual and take full ownership of everything around you: from building, discovering, and solving complex problems, to sharing knowledge with your international colleagues to ensure all processes are efficient and productive. Our purpose across all our businesses is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of place of work in Sydney, so that we're able to interact and collaborate in person.

About the Role

To support our growth, we are looking for an experienced SOC Team Lead with Incident Response experience to join our growing cyber security function. This role will be supporting our 24/7 operational capabilities by providing coverage in working hours from Sydney and Toronto alongside our UK colleagues.

As a member of the Starling Group's SOC team, you will be working with the industry's brightest SecOps professionals to protect Starling Group's customers, assets, and systems using the latest technologies.

  • Lead a team of subject matter experts and analysts to ensure Information Security is managed and continuously improved in line with Bank policy and procedure.
  • Supporting the development and progression of the Information Security Analyst team from both a technical and professional perspective.
  • Incident Triage, Response, and Investigations based on Alerts received from multiple sources which include:
    - Cloud Infrastructure/Security.
    - Endpoint Detection and Response.
    - Perimeter detection tooling.
  • Conduct Quality Assurance for Triage case handling, mitigation actions and shift handover, collating lessons learned and implementing improvements where required.
  • Interpret logs from a variety of sources (e.g. cloud, endpoint, network) to identify root cause and determine next steps for containment, eradication and recovery as part of incident response activities.
  • Work together with other teams in the organisation to analyse, contain, eradicate and recover from cyber security incidents
  • Continuous development and maintaining of incident handling, response and readiness processes.
  • Support the wider SecOps team with detection engineering - creating and optimising analytic triggers to enhance alert efficacy - and threat hunting based on threat intelligence.
  • Documentation of incidents and investigations, including analysis findings, containment steps and root cause.
  • Plan and participate in Tabletop Exercises.
  • Present investigation findings to technical and non-technical audiences.
Requirements
  • 5+ years experience in an in-house SOC role and team, including cyber incident response and digital forensics function.
  • Experience in a similar role leading, developing and motivating a team of subject matter experts and other managers in Information and Cyber Security.
  • Understanding of AWS Security Solutions (or other Public Cloud Solutions)
  • Analysis and Incident Response experience with Cloud systems (GCP, AWS)
  • Experience working and supporting analytics/SIEM platforms.
  • Experience supporting and conducting Incident Response engagements.
  • Experience in endpoint based investigations.
  • Experience in cloud based investigations.
  • Experience with Incident Command and conducting Tabletop Exercises.
  • Experience in acting as both Commander and SME during incidents and investigations.
  • Be a Self Starter with the ability to lead, inspire and drive change through an organisation.
  • Excellent communication skills (both verbal and written), ability to communicate technical concepts to both technical and non-technical audiences.
  • Demonstrated teamwork and collaboration skills as part of a multi-functional team
  • Time management, problem-solving and interpersonal skills.
  • Eagerness to learn and apply knowledge to new security challenges.
  • Willingness to share knowledge with the team and mentor colleagues.
  • A high level understanding of mobile, network and operating system security controls.
Preferred
  • Experience in forensics: cloud (GCP, AWS); endpoint/server (Windows, MacOS, Linux); and/or network.
  • Any experience of programming in Python, Go and/or Java.
  • A Cyber/Information Security related degree and/or relevant cyber security qualification(s) would be desired but not required
  • Understanding of malware analysis techniques
Interview Process
  • First Interview: 45 minutes
  • Technical Interview: 90 minutes
  • Final Interview: 30 minutes
Please Note

We require our successful candidatestopass background checks (including but not limited to employment references, fraud checks, financial probity, social media, and criminal history).

Starling welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process.

Benefits
  • 25 days holiday. You'll also get your birthday on us
  • The option to opt-out of public holidays
  • The option to buy/sell up to 5 days of annual leave a year
  • 16 hours paid volunteering time a yearEnhanced Pat & Mat leave
  • Perkbox
  • Length of service increased annual leave

Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Operations Lead (Sydney, Australia)
Information Security Operations Lead (Sydney, Australia)

Starling • Sydney

Hybrid
AUD 140,000 - 190,000
25 days holiday
Birthday on us
Public holidays opt-out
+5
Information Security Operations Lead (Sydney, Australia)
Information Security Operations Lead (Sydney, Australia)

Starling Bank • Sydney

On-site
AUD 180,000 - 230,000
25 days holiday
Birthday on us
Flexible leave options
+1
Information Security Operations Lead (Sydney, Australia)
Information Security Operations Lead (Sydney, Australia)

Starling Bank Limited • Sydney

On-site
AUD 150,000 - 210,000
25 days holiday
Birthday off
Volunteer time
+1
Information Security Operations Analyst (Sydney, Australia)
Information Security Operations Analyst (Sydney, Australia)

Starling • Sydney

Hybrid
AUD 120,000 - 150,000
25 days holiday
Birthday day off
Volunteer hours
+1
SOC Lead: Incident Response & Cloud Security
SOC Lead: Incident Response & Cloud Security

Starling Bank • Sydney

On-site
AUD 180,000 - 230,000
25 days holiday
Birthday on us
Flexible leave options
+1
Security Operations Lead — Incident Response (SOC)
Security Operations Lead — Incident Response (SOC)

Starling • Sydney

Hybrid
AUD 140,000 - 190,000
25 days holiday
Birthday on us
Public holidays opt-out
+5
Senior SOC Lead — Incident Response & Threat Detection
Senior SOC Lead — Incident Response & Threat Detection

Starling Bank Limited • Sydney

Hybrid
AUD 150,000 - 210,000
25 days holiday
Birthday off
Volunteer time
+1
Senior Solution Architect - Engine By Starling
Senior Solution Architect - Engine By Starling

Starling • New South Wales

On-site
AUD 180,000 - 240,000
25 days holiday
Birthday off
Buy/sell up to 5 days
+4
Senior Solution Architect - Engine by Starling
Senior Solution Architect - Engine by Starling

Starling Bank • Sydney

On-site
AUD 140,000 - 210,000
25 days holiday
Birthday leave
Buy/sell annual leave
+4
Business Development Consultant
Business Development Consultant

Engine by Starling • Sydney

On-site
AUD 80,000 - 100,000
25 days holiday plus your birthday
Option for enhanced parental leave
Paid volunteering time
+1