Overview
In this role, you join Starling’s 24/7 cyber security function to protect customers, assets and systems. You will operate in a fast-paced, collaborative team that values ownership and practical security solutions. You will triage, respond to, and investigate security incidents across cloud, endpoint, and perimeter technologies, while improving detection and readiness. You’ll contribute to threat hunting, incident documentation, and analytic tuning to strengthen our security posture. This is a hands-on opportunity to shape Starling’s security operations in a growing, disruptive fintech environment.
Pay / Benefits
- Hybrid working
- 25 days holiday
- Private Medical Insurance
- Pension
- Life insurance (4x salary)
- Volunteer time
Responsibilities
- Incident triage, response, and investigations based on alerts from cloud, endpoint, and perimeter tooling
- Investigate and respond to security alerts raised by users
- Enhance analytic triggers and alert efficacy
- Continuously develop incident handling and readiness processes
- Proactive threat hunting using threat intelligence
- Document incidents and investigations
Key requirements
- 3+ years in an in-house SOC role and team
- Understanding of AWS Security Solutions (or other public cloud)
- Experience with analytics/SIEM platforms
- Experience in CSIRT/SOC functions
- Experience supporting and conducting Incident Response engagements
- Experience in endpoint and cloud-based investigations
- Experience with Incident Command and Tabletop Exercises
- Interest in Automation and Threat Intelligence / Analytic Tuning
- Knowledge of mobile, network and OS security controls
- Programming experience in Python, Go and/or Java
- Cyber/Security related degree or qualifications would be desirable but not required
- Curiosity
- Collaborative mindset
- Proactive problem-solving
- AWS security
- Cloud investigations (AWS/GCP)
- Endpoint Detection and Response
…
