
Red Team Operator (Cyber Resilience)
- London
- Permanent
- Full-time
- Support designing and executing red team operations against Starling Bank (including all scoping, planning, payload/infrastructure development, , execution, reporting and workshops)
- Identifying complex vulnerabilities and building exploits
- Continually improving the methodology and capability of the team
- Developing and documenting reusable attack components using realistic TTPs
- Conducting purple team exercises to validate and improve defensive measures by collaborating with the SOC team to enhance detection capabilities
- Assist in translating red team tactics into actionable intelligence for blue team operations
- Assist developing threat models and 'worst case scenario' playbooks based on emerging global risks, including APTs, insider threats and supply chain compromise and simulate real-world scenario to evaluate system and organisational resilience
- Assist cyber resilience technical testing initiatives to assess the Bank's ability to withstand and recover from cyber attacks and system disruptions, including technical simulations and controlled attack scenarios (e.g. ransomware, DDoS, data corruption) to evaluate resilience, incident response capabilities, back up integrity, failover procedures and recovery time objectives.
- Facilitate the identification of vulnerabilities, improvements to defence strategies and aid recovery process validation
- Analyse test results, validate breach scenarios, document findings and provide actionable recommendations to enhance Starling's overall cyber resilience posture
- Experience of working in a red team and understanding of the benefits and pitfalls of different adversarial techniques
- Ability to work to define rules of engagement and to show strong discipline and steady judgement, working both independently or as part of a team
- Experience conducting security testing against cloud environments (AWS, GCP, Azure)
- Relevant security testing certifications (e.g. OSCP, CRTO, OSMR, cloud security or similar)
- Familiarity with the cyber risks faced by Starling Bank and other financial institutions
- Sound network and operating system fundamentals (MacOS, Linux and Windows)
- Familiarity with modern software engineering paradigms (CI/CD, Infra as Code)
- Experience in Ai/Ml Systems Security, Including LLMs, transformers and model interpretability
- Certification such as OSCE, CCT, OSEP, OSMR or similar
- Prior experience in incident response, threat intelligence, or ethical hacking at an enterprise level
- Background in regulatory environments (e.g. ISO 27001, SOCII, GDPR or AI Act compliance)
- Software engineering expertise (Java, Kotlin, Go…) or reverse engineering expertise
- Experience and enthusiasm for blogging and speaking both internally to educate our staff and potentially externally
- Stage 1 - 45 mins with one of the team
- Stage 2 - 60 mins technical interview with two team members
- Stage 3 - 45 min final with two executives
- 33 days holiday (including public holidays, which you can take when it works best for you)
- An extra day's holiday for your birthday
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
- 16 hours paid volunteering time a year
- Salary sacrifice, company enhanced pension scheme
- Life insurance at 4x your salary & group income protection
- Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
- Generous family-friendly policies
- Incentives refer a friend scheme
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
- Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing