Penetration Tester bridging technical exploitation and real-world business risk at Engine by Starling. Collaborating with teams to strengthen security posture and test core banking platforms.
Responsibilities
Conducting penetration tests on our core banking platform, focusing on Cloud and Application Security.
Performing manual secure code reviews to identify logic flaws and security anti-patterns.
Participate in sessions with different teams to identify design flaws before code is written.
Contextualising technical vulnerabilities into "Real-World Risk" scenarios to demonstrate business impact to non-technical executives and within Engine’s risk management framework.
Collaborating with Infrastructure teams to audit and secure cloud configurations.
Acting as an independent operator within the team, managing your own testing scope and timelines across different business domains.
Providing clear, actionable remediation advice that balances security requirements with engineering velocity.
Translate complex technical exploits into actionable business risk summaries for non-technical stakeholders and executive leadership.
Requirements
5+ years experience in penetration testing with a focus on cloud native infrastructure, web applications, APIs.
Expert-level proficiency with industry-standard tools and the ability to "go manual" when scanners fail.
Experience with Cloud Security, (AWS/GCP) specifically AWS/EKS.
Ability to conduct code reviews in multiple languages, primarily Java and Go.
Experience testing Mobile Applications (iOS and Android).
Proven experience in Threat Modelling.
You have a working understanding of how software is architected, built and deployed.
You have the ability to write your own scripts and tooling to aid in pentesting and improve efficiency. Golang, Python etc.
Relevant industry certifications (OSCP, OSWE, CCT-APP, CCT-INF etc.) or relevant demonstrable experience.
Benefits
25 days holiday (plus take your public holiday allowance whenever works best for you)
An extra day’s holiday for your birthday
Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
16 hours paid volunteering time a year
Salary sacrifice, company enhanced pension scheme
Life insurance at 4x your salary & group income protection
Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
Generous family-friendly policies
Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
Software Quality Engineer responsible for quality of Elo's payment solutions. Involves manual and automated testing processes, collaborating with engineering and product teams.
System Integration QA Testing Supervisor leading enterprise systems testing at a growing natural gas utility. Managing tasks across various platforms for operational efficiency.
Quality Assurance Specialist at True North Salmon, ensuring food safety and quality compliance. Analyzing trends, collaborating with teams, and managing quality assurance programs.
QA/QC Director responsible for strategic leadership and operational oversight in a biotech facility. Leading QA and QC functions supporting cell and gene therapies with FDA compliance.
Forex Country Manager responsible for developing and executing business strategies in Qatar. Leading business development and client acquisition efforts within the forex industry.
Quality Assurance/Performance Test Engineer responsible for improving delivery approach and product quality. Collaborating on new test scenarios and performance test executions for the greek market.
Quality Assurance Employee maintaining quality management and ensuring product standards in glass manufacturing. Supporting safety optimization projects within a professional team.
Corporate Quality Assurance Manager responsible for leading quality activities at Mondelēz International. Ensuring compliance and implementing quality metrics for successful business objectives.
Business Tester ensuring quality in a strategic leasing management system project at Sogeti. Collaborating with teams to validate functional requirements and enhance user experience.