Information Security Analyst – Vulnerability Management

Company: Starling Bank
Apply for the Information Security Analyst – Vulnerability Management
Location: London
Job Description:

Overview

In this role you will enable timely remediation of security findings by coordinating with engineering and product teams. You apply a risk-based approach to prioritise vulnerabilities and ensure assets are scanned within scope. You’ll maintain vulnerability tooling, document processes, and drive automation to reduce manual work. You act as a security SME, keeping pace with threats and regulatory expectations while collaborating across the tech organisation to strengthen Starling’s security posture.

Pay / Benefits

  • 25 days holiday
  • Birthday day off
  • Pension scheme
  • Private Medical Insurance with VitalityHealth
  • Life insurance 4x salary
  • Perkbox discounts

Responsibilities

  • Bridge security discovery and resolution with engineering/product teams to turn findings into actionable tasks
  • Prioritise vulnerabilities using risk-based reasoning based on impact and exploitability
  • Coordinate with resolver groups to ensure timely remediation of findings
  • Maintain and update vulnerability management tools (Build Phase VM, CWPP, Endpoint VM, VM Intelligence) for effectiveness
  • Review/update vulnerability management documentation to align with compliance and best practices
  • Build and maintain the vulnerability ecosystem across cloud-native and on-prem environments with automation
  • Process vulnerability data to produce reports/metrics to support risk-based management
  • Develop integrations with internal/external tools via APIs to support remediation workflows
  • Ensure compliance with security standards, frameworks, and regulations
  • Stay updated on trends and developments in vulnerability management and security regulations
  • Act as a subject matter expert and evolve the team’s defensive strategy with the wider security org

Key requirements

  • Vulnerability management experience in a security role (analyst/specialist/engineer)
  • Strong knowledge of cloud platforms (AWS, GCP) and cloud-native security architecture
  • Experience with Kubernetes and container security principles
  • Security knowledge in AWS/GCP
  • Basic scripting for automation (Python, Go, Bash)
  • Proven ability to develop integrations via APIs
  • Excellent analytical and problem-solving skills
  • Strong written and verbal communication for cross-functional collaboration
  • Adaptability to learn new technologies and evolving security landscape
  • Analytical thinking
  • Problem-solving
  • Effective communication
  • AWS
  • GCP
  • Kubernetes

…

Posted: September 14th, 2026