Software Engineer - Vulnerability Management

Starling

Cardiff

Hybrid

GBP 60,000 - 90,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

25 days holiday
Birthday day off
Volunteering time
Pension scheme via salary sacrifice

Job summary

Starling Bank in Cardiff, Wales, is seeking a highly motivated Software Engineer to join our Vulnerability Management team. You will design, build, and maintain tooling to automate remediation, and collaborate with engineering teams to reduce risk across our digital banking platform.

You will contribute to cloud security, container hardening, and data-driven security metrics, while participating in cross-functional collaboration and a hybrid work model.

Qualifications

  • Experience designing and maintaining vulnerability management tooling.
  • Strong cloud experience (AWS, GCP) and container security.
  • Proficiency in Kubernetes and infrastructure as code (Terraform).
  • Knowledge of Go or Java and software engineering fundamentals.
  • Experience building integrations via APIs and automations.
  • Ability to learn new technologies and communicate with stakeholders.

Responsibilities

  • Design, build, and maintain vulnerability management tooling and solutions.
  • Drive automation to reduce manual overhead and streamline remediation.
  • Collaborate with internal engineering teams to prioritise remediation activities.
  • Transform vulnerability data into actionable reports and metrics.
  • Develop integrations across platforms to improve data capture in remediation lifecycle.
  • Maintain alignment with security standards, and stay ahead of trends.

Skills

Cloud AWS
Kubernetes
Terraform
Go or Java
Automation
APIs

Tools

Terraform

Job description

Software Engineer - Vulnerability Management Starling Cardiff, Wales, GB

Starling is the UK's first and leading digital bank on a mission to fix banking! Our vision is fast technology, fair service, and honest values. All at the tap of a phone, all the time.

We are about giving customers a new way to spend, save and manage their money while taking better care of the planet which has seen us become a multi-award winning bank that now employs over 2800 across five offices in London, Cardiff, Dublin, Southampton, and Manchester. Our journey started in 2014, and since then we have surpassed 3.5 million accounts (and four account types!) with 350,000 business customers. We are a fully licensed UK bank but at the heart, we are a tech first company, enabling our platform to deliver brilliant products.

Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be, innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture, you will find support in your team and from across the business, we are in this together!

The way to thrive and shine within Starling is to be a self-driven individual and be able to take full ownership of everything around you: From building things, designing, discovering, to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers. Our purpose is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. In Technology, we're asking that you attend the office a minimum of 1 day per week.

About the Role

We are seeking a highly motivated and experienced Vulnerability Management Engineer to join our Cyber Security team. As a Vulnerability Management Engineer, your primary responsibility will be to manage vulnerability management tooling, and have an active role in improving existing processes. You will achieve this by creating automated solutions through collaboration with technical teams across Starling.

Responsibilities
  • Design, build, and maintain robust vulnerability management tooling and technical solutions.
  • Drive efficiency by implementing automated solutions that eliminate manual overhead and streamline operations.
  • Partner with internal engineering teams and remediators to intelligently prioritise remediation activities.
  • Synthesise raw vulnerability data into actionable insights, reports, and metrics to support a risk-based security posture.
  • Engineer custom integrations between internal and external platforms to enhance data capture throughout the remediation lifecycle.
  • Maintain strict adherence to global security standards, regulatory requirements, and industry frameworks.
  • Keep at the forefront of the industry by monitoring emerging trends in vulnerability management and shifting regulatory landscapes.
  • Treat security as a continuous engineering challenge to outpace the threat landscape, proactively identifying vulnerabilities and architecting technical solutions to fortify our global ecosystem.
  • Develop and maintain comprehensive technical playbooks and runbooks to standardise vulnerability triage, remediation, and incident response procedures, ensuring consistent, repeatable, and efficient security operations across the team.
  • Utilise pattern and trend analysis to identify "Vulnerability Hotspots" (e.g., recurring issues in specific base Images or teams) to drive strategic risk reduction rather than just individual remediation.
Requirements
Strong technical knowledge, including:
  • Cloud Experience (AWS, GCP)
  • Kubernetes and Container experience
  • Infrastructure as code (terraform)
  • Proficiency with either Go or Java programming languages
  • Strong engineering and automation background with a keen interest in Vulnerability Management
  • Experience with developing integrations by interacting with APIs
  • Ability and willingness to learn new technologies and adapt to evolving security landscapes
  • Capability to understand the bigger picture while effectively managing details
  • Strong written and verbal communication skills to effectively collaborate with cross-functional teams and stakeholders
Additional Technical Requirements
  • Deep understanding of container & orchestration security: practical knowledge of securing containerised environments, including image scanning, runtime protection, and hardening K8s manifests.
  • Proficiency in cloud posture management: familiarity with tools and frameworks to monitor cloud configuration drift and ensure adherence to security benchmarks (e.g., CIS Benchmarks, AWS/GCP best practices)
  • Riskbased prioritisation models: proven ability to translate raw vulnerability data (CVSS scores, exploitability) into business contextualised risk insights, enabling engineering teams to prioritise remediation effectively.
  • Practical experience in one or more of the vulnerability management fields would be desirable but not essential:
  • Endpoint vulnerability scanning
  • Vulnerability intelligence,
  • AppSec vulnerability management
  • Vulnerability management of cloud native workloads
  • External attack surface management
  • Experience with Software Bill of Materials (SBOM) management, specifically ingesting and correlating standard format

Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • First stage with our Information Security Lead
  • Second stage - Take home task
  • Third stage with additional members of the Vulnerability Management and Security Engineering team
  • Final stage with Security Engineering Lead and Information Security Director
  • 25 days holiday (plus take your public holiday allowance whenever works best for you)
  • An extra day's holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineer - Vulnerability Management
Software Engineer - Vulnerability Management

Starling • Manchester

Hybrid
GBP 70,000 - 110,000
25 days holiday
Birthday day off
Pension scheme
+3
Software Engineer - Vulnerability Management
Software Engineer - Vulnerability Management

Starling • Southampton

Hybrid
GBP 70,000 - 120,000
Hybrid working
25 days holiday
Birthday day off
+5
Information Security Engineer - Vulnerability Management
Information Security Engineer - Vulnerability Management

Starling Bank Limited • Greater London

Hybrid
GBP 75,000 - 110,000
25 days holiday
Birthday day off
Pension scheme
+2
Information Security Analyst - Vulnerability Management
Information Security Analyst - Vulnerability Management

Starling • Greater London

On-site
GBP 65,000 - 90,000
25 days holiday
Birthday day off
Private Medical Insurance
Information Security Analyst - Vulnerability Management
Information Security Analyst - Vulnerability Management

Starling Bank Limited • Greater London

Hybrid
GBP 70,000 - 90,000
Holiday entitlement
Private medical insurance
Cycle to Work
+1
Information Security Analyst - Vulnerability Management
Information Security Analyst - Vulnerability Management

Starling Bank • Greater London

Hybrid
GBP 70,000 - 95,000
25 days holiday
Birthday day off
Private medical insurance
+2
Information Security Analyst - Vulnerability Management
Information Security Analyst - Vulnerability Management

Starling • Southampton

Hybrid
GBP 60,000 - 90,000
25 days holiday
Birthday day off
Pension scheme
+5
Information Security Analyst - Vulnerability Management
Information Security Analyst - Vulnerability Management

Starling • Manchester

Hybrid
GBP 60,000 - 90,000
25 days holiday
Birthday day off
Pension scheme
+3
Information Security Analyst - Vulnerability Management
Information Security Analyst - Vulnerability Management

Starling • Cardiff

Hybrid
GBP 55,000 - 75,000
Senior Penetration Tester
Senior Penetration Tester

Starling • Southampton

Hybrid
GBP 65,000 - 90,000
25 days holiday
Birthday day off
Hybrid working