Senior Cloud Security Engineer (GCP) – Engine by Starling

Company: Starling Bank
Apply for the Senior Cloud Security Engineer (GCP) – Engine by Starling
Location: London
Job Description:

Overview

As a Senior GCP Security Engineer, you will own the security foundations of Engine’s Google Cloud Platform. You collaborate with security, infrastructure, and product teams to design a secure cloud architecture and implement scalable, automated controls. You will drive continuous compliance (PCI DSS, 3DS) and lead incident response while championing a DevSecOps culture. This role sits at the heart of fast-paced fintech innovation, shaping secure infrastructure used by banks worldwide. You will work across IAM, networks, and hardened GKE clusters to protect data and services.

Pay / Benefits

  • 33 days holiday including public holidays
  • Birthday leave
  • Private Medical Insurance with VitalityHealth
  • Pension scheme
  • Life insurance 4x salary
  • Cycle to Work and EV leasing

Responsibilities

  • Collaborate with stakeholders to define our Google Cloud security architecture (cloud identity, runtime security, security posture)
  • Design, document, build and maintain a secure and scalable infrastructure on GCP using Infrastructure as Code
  • Safeguard systems with secure user access, authentication and authorization mechanisms
  • Engineer and automate technical controls in GCP to demonstrate compliance with PCI DSS and 3DS
  • Drive security infrastructure deployments across growing environments
  • Perform regular security assessments, audits, threat modelling and architecture design reviews
  • Lead incident response efforts, including investigation and remediation of security breaches
  • Support internal security awareness and DevSecOps mindset across technology teams

Key requirements

  • Mature understanding of cloud security architecture with deep expertise in GCP
  • Experience creating a GCP landing zone with organisation policies and VPC Service Controls
  • Deep understanding of GCP IAM and its limitations
  • Experience with containerised architectures on GCP (GKE, Compute Engine, Shared VPC, Cloud SQL)
  • Expertise in Kubernetes security (GKE), RBAC, and network best practices
  • Experience with Infrastructure as Code (Terraform)
  • Experience with Security Command Center, Binary Authorization, Artifact Registry, and Secret Manager
  • Experience with KMS, EKM, and cryptographic key management
  • Experience with Workload Identity and Workload Identity Federation
  • Experience with cloud-native security logging, monitoring, and detection
  • Strong programming skills (Python, Go) for automation
  • Good knowledge of OWASP Top 10 and MITRE ATT&CK
  • Excellent problem-solving and communication skills
  • Proactive security posture with threat awareness
  • Incident response process knowledge
  • Problem-solving
  • Communication
  • Active listening
  • GCP security architecture
  • GKE security and Kubernetes RBAC
  • Terraform

…

Posted: September 14th, 2026