About the role

  • Penetration Tester bridging technical exploitation and real-world business risk at Engine by Starling. Collaborating with teams to strengthen security posture and test core banking platforms.

Responsibilities

  • Conducting penetration tests on our core banking platform, focusing on Cloud and Application Security.
  • Performing manual secure code reviews to identify logic flaws and security anti-patterns.
  • Participate in sessions with different teams to identify design flaws before code is written.
  • Contextualising technical vulnerabilities into "Real-World Risk" scenarios to demonstrate business impact to non-technical executives and within Engine’s risk management framework.
  • Collaborating with Infrastructure teams to audit and secure cloud configurations.
  • Acting as an independent operator within the team, managing your own testing scope and timelines across different business domains.
  • Providing clear, actionable remediation advice that balances security requirements with engineering velocity.
  • Translate complex technical exploits into actionable business risk summaries for non-technical stakeholders and executive leadership.

Requirements

  • 5+ years experience in penetration testing with a focus on cloud native infrastructure, web applications, APIs.
  • Expert-level proficiency with industry-standard tools and the ability to "go manual" when scanners fail.
  • Experience with Cloud Security, (AWS/GCP) specifically AWS/EKS.
  • Ability to conduct code reviews in multiple languages, primarily Java and Go.
  • Experience testing Mobile Applications (iOS and Android).
  • Proven experience in Threat Modelling.
  • You have a working understanding of how software is architected, built and deployed.
  • You have the ability to write your own scripts and tooling to aid in pentesting and improve efficiency. Golang, Python etc.
  • Relevant industry certifications (OSCP, OSWE, CCT-APP, CCT-INF etc.) or relevant demonstrable experience.

Benefits

  • 25 days holiday (plus take your public holiday allowance whenever works best for you)
  • An extra day’s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

Job title

Penetration Tester

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job