Information Security Lead - Vulnerability Management

Starling Bank

Information Security Lead - Vulnerability Management

Salary Not Specified

Starling Bank, Bedford Place, City of Southampton

  • Full time
  • Permanent
  • Remote working

Posted 2 weeks ago, 3 May | Get your application in now before you miss out!

Closing date: Closing date not specified

job Ref: 2643350a177047e4bc97e5e456e2d2ac

Full Job Description

We are seeking a highly motivated and experienced Vulnerability Manager to lead a growing vulnerability management team. A successful candidate will work with the team to analyse emerging vulnerabilities provided by threat intelligence sources and penetration testing. The vulnerability manager will collaborate with various technology and engineering teams to share vulnerability findings, provide guidance, and assist through the remediation process. This person will help present this information in a simple digestible format, and coordinate remediation and mitigation efforts with teams across remote and office locations. There will be opportunities to guide continual improvement of the vulnerability management process.

Responsibilities

  • Lead a team of information security professionals to:


  • Assess, investigate and provide guidance on emerging vulnerabilities, incorporating information from threat intelligence sources, internal software and infrastructure scans.

  • Collate and prioritise applicable vulnerabilities based on Starling Bank's environmental factors and risk frameworks

  • Collaborate with relevant technology (security, engineering, workplace technology, data, infrastructure) teams to ensure resolution of findings within agreed timeframes.

  • Track and report on progress of mitigations/resolutions to relevant audiences


  • Identify trends and themes in issues which occur and work collaboratively with wider teams to develop process and procedure improvements.
  • Understand the assets and/or applications at risk from a vulnerability and be able to articulate the potential threat to the Bank in a way anyone in the business could understand.

  • Alignment of risk assessment approach for vulnerabilities to the Bank's risk appetite, operational and information risk frameworks.

  • Promote vulnerability management standards, procedures & guidelines, and best practices outside the security functions.

  • Drive continuous improvement of the vulnerability management approach to ensure prioritisation of tasks is continually effective and mitigating risk to the Bank ongoing.

  • Contribute to the development and enhancement of the Bank's information risk framework.

    Experience in a similar role leading, developing and motivating a team of subject matter experts

  • Strong written and verbal communication skills to effectively collaborate with cross-functional teams and stakeholders

  • Capability to understand the bigger picture while effectively managing details

  • Ability and willingness to learn new technologies and adapt to evolving security landscapes

  • Practical experience in Vulnerability Management fields, including:


  • Endpoint Vulnerability Scanning

  • Vulnerability Intelligence

  • AppSec Vulnerability Management

  • Vulnerability Management of cloud native workloads

  • External Attack Surface Management


  • Technical knowledge in the following areas is desirable:
  • Cloud (AWS, GCP)

  • Containers

  • MacOS and Windows

  • Data analysis and SQL


  • Interview process
  • Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team

    Starling is the UK's first and leading digital bank on a mission to fix banking! We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way.


  • We're a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company. We're a bank, but better: fairer, easier to use and designed to demystify money for everyone. We employ more than 3,000 people across our London, Southampton, Cardiff and Manchester offices.

    Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be, innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture, you will find support in your team and from across the business, we are in this together!

    The way to thrive and shine within Starling is to be a self-driven individual and be able to take full ownership of everything around you: From building things, designing, discovering, to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers. Our purpose is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

    Hybrid Working

    We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. We don't like to mandate how much you visit the office and work from home, that's to be agreed upon between you and your manager., You may be put off applying for a role because you don't tick every box. Forget that! While we can't accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren't sure if you're 100% there yet, get in touch anyway. We're on a mission to radically reshape banking - and that starts with our brilliant team. Whatever came before, we're proud to bring together people of all backgrounds and experiences who love working together to solve problems.

  • 33 days holiday (including public holidays, which you can take when it works best for you)

  • An extra day's holiday for your birthday

  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off

  • 16 hours paid volunteering time a year

  • Salary sacrifice, company enhanced pension scheme

  • Life insurance at 4x your salary & group income protection

  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton

  • Generous family-friendly policies

  • Incentives refer a friend scheme

  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks

  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing