Penetration Tester securing systems and customer assets at Starling, a digital bank. Collaborating with teams to conduct penetration tests and enhance security processes.
Responsibilities
Scoping and performing mobile, web application, cloud, and infrastructure penetration tests.
Automation of security testing, and development of internal tooling, to achieve continuous assurance.
Collaboration with engineering teams to facilitate secure development, including:
Review and analysis of proposed technical solutions to identify appropriate security controls.
Input and guidance to security related technical architecture and design decisions.
Code review of features and critical security components.
Practical security testing.
Advising on remediation of security issues and processes to address root causes.
Security assurance reviews of third-party solutions.
Identifying and implementing improvements to the team’s internal processes and procedures.
Review, analysis and reporting of external threats relevant to Starling systems and solutions, in the context of Starling’s desired security posture.
Requirements
5+ years technical information security experience.
Experience of mobile, web application, cloud and infrastructure penetration testing.
Strong technical knowledge in:
Mobile security (iOS and Android)
Web application security
Networking and associated protocols
Cloud security (AWS and GCP)
Containers and Kubernetes
A desire to learn, and ability to apply technical security knowledge to new and unfamiliar areas.
CREST, OSCP or similar industry penetration testing qualification
A good understanding of applied cryptographic techniques.
Reverse engineering and exploit development capabilities.
Experience of security testing in an agile SDLC.
Threat modelling experience.
Experience performing code reviews, particularly in Java and Go.
Experience of fulfilling a client facing security consulting role.
Excellent verbal and written communication skills.
Experience in automation of security testing, with previous development experience desirable.
Benefits
25 days holiday (plus take your public holiday allowance whenever works best for you)
An extra day’s holiday for your birthday
Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
16 hours paid volunteering time a year
Salary sacrifice, company enhanced pension scheme
Life insurance at 4x your salary & group income protection
Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
Generous family-friendly policies
Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
Primary Metallurgical QA Professional ensuring compliance with metallurgical processes at Metallus. Overseeing chemical and testing application aspects of primary steelmaking for various products in a manufacturing plant.
Senior QA engineer at Barco responsible for testing applications and ensuring quality in a collaborative team environment. Requires strong skills in automation and CI/CD tools.
Supplier Quality Engineer providing quality engineering support during product launch processes. Collaborating with suppliers and the USA quality engineer to ensure product quality and compliance.
QA Chapter Lead developing skills in testing, guiding a community of experts at Vodafone in high impact digital and core IT platforms. Inspiring knowledge transfer and innovation in testing practices.
Quality Assurance Associate at Lilly providing quality support for drug product manufacturing and batch disposition in pharmaceuticals. Ensuring adherence to quality systems for external manufacturers with a focus on compliance and continuous improvement.
Quality Assurance Specialist overseeing production quality and compliance at Berghof Fluoroplastic Technology. Conducting inspections and continuous improvement initiatives in manufacturing.
Quality Engineer at Brink responsible for maintaining ISO 9001 standards and improving production processes. Work collaboratively within the quality team to support and advise on critical processes.
Quality Assurance Engineer leading automation testing efforts for the Analytics Scrum Team at Hitachi Energy. Focused on developing frameworks and ensuring quality for analytical algorithms.
Quality Manager responsible for regular quality checks and problem resolution in flat glass production. Collaborating with teams to enhance product quality and ensure compliance with standards.
Quality Engineer responsible for implementing and supervising quality management systems at Tenneco in Swarzedz - Jasin, Poland. Conducting audits, maintaining documentation, and supporting training activities.