Scoping and performing mobile, web application, cloud, and infrastructure penetration tests.
Automation of security testing, and development of internal tooling, to achieve continuous assurance.
Collaboration with engineering teams to facilitate secure development, including:
Review and analysis of proposed technical solutions to identify appropriate security controls.
Input and guidance to security related technical architecture and design decisions.
Code review of features and critical security components.
Practical security testing.
Advising on remediation of security issues and processes to address root causes.
Security assurance reviews of third-party solutions.
Identifying and implementing improvements to the team’s internal processes and procedures.
Review, analysis and reporting of external threats relevant to Starling systems and solutions, in the context of Starling’s desired security posture.
Requirements
5+ years technical information security experience.
Experience of mobile, web application, cloud and infrastructure penetration testing.
Strong technical knowledge in:
Mobile security (iOS and Android)
Web application security
Networking and associated protocols
Cloud security (AWS and GCP)
Containers and Kubernetes
A desire to learn, and ability to apply technical security knowledge to new and unfamiliar areas.
CREST, OSCP or similar industry penetration testing qualification
A good understanding of applied cryptographic techniques.
Reverse engineering and exploit development capabilities.
Experience of security testing in an agile SDLC.
Threat modelling experience.
Experience performing code reviews, particularly in Java and Go.
Experience of fulfilling a client facing security consulting role.
Excellent verbal and written communication skills.
Experience in automation of security testing, with previous development experience desirable.
Benefits
25 days holiday (plus take your public holiday allowance whenever works best for you)
An extra day’s holiday for your birthday
Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
16 hours paid volunteering time a year
Salary sacrifice, company enhanced pension scheme
Life insurance at 4x your salary & group income protection
Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
Generous family-friendly policies
Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
QA Engineer developing E2E automation framework for web and mobile applications in healthcare. Ensuring quality and regulatory compliance in a hybrid work environment.
Quality Assurance Analyst at WGU monitoring QA processes and collaborating with stakeholders on Military Education benefits compliance. Managing audits, risk - based surveys, and mentoring colleagues.
Lead QA Automation Engineer at HFM developing automation strategies for trading systems. Focus on AI/ML adoption and mentoring a high - performing team in Larnaca, Cyprus.
Lead QA Automation Engineer at HFM overseeing testing for low - latency financial trading systems. Focused on AI/ML adoption in automation processes and team mentorship.
QA Engineer testing backend services and AI/ML applications at Evnek Technologies. Requires 5+ years experience and expertise in test automation and backend systems.
Quality Assurance Pharmacist role ensuring pharmaceutical lot releases and adherence to quality standards at DSM - Firmenich. Engaging in continuous improvement and regulatory compliance.
QA Tester and Business Process Analyst at Stefanini, a global company specialized in co - creating future solutions. Focus on software quality assurance and process optimization.
QA Engineer ensuring reliability and performance of Android - based POS systems at CompassX. Collaborating with teams to execute testing and support operations in a hybrid role.
Electrical Verification Engineer testing and validating Belimo electronic actuators and hydronic control valves. Focused on automation, verification, and ensuring product compliance with design requirements.
QA Game Tester assessing game functionality within a gaming - focused DevQA team at Magic Media. Collaborating with development teams to identify bugs and enhance playability.