
Product Security Engineer - Engine by Starling
- London
- Permanent
- Full-time
- Conduct comprehensive security architecture and design reviews, ensuring that security is embedded from the start
- Lead the threat modelling process (e.g., using STRIDE) for new products and features, identifying potential design flaws and defining security requirements
- Manage the end-to-end penetration testing lifecycle, from scoping engagements with technical teams to triaging, validating, and driving the remediation of findings
- Analyse and interpret results from security tools (SAST, DAST, vulnerability scanners) to prioritise and address the most critical risks
- Act as a key security advisor to engineering teams, providing expert guidance on security best practices, vulnerability mitigation, and secure design patterns
- Translate regulatory requirements (PCI DSS, SOC 2, ISO 27001) into concrete technical controls and implementation plans in collaboration with the GRC team
- Lead incident response efforts, including investigation and remediation of security breaches
- Support our internal security awareness and training programs and advocating the DevSecOps mindset that we have created across our technology teams
- Significant experience in a security-focused role with a strong emphasis on risk analysis, threat detection, and architectural review
- Proven expertise in conducting threat modelling and security design reviews for complex, cloud-native applications (AWS/GCP, Kubernetes)
- Deep understanding of common application and infrastructure vulnerabilities (OWASP Top 10, MITRE ATT&CK) and their mitigation
- Experience managing penetration testing engagements and working with development teams on remediation
- Mature understanding and experience with cloud security architecture (AWS, Google Cloud)
- The ability to read and understand code (e.g., Go, Python) and Infrastructure-as-Code (Terraform) to effectively analyse security risks
- The ability to document security requirements from various stakeholders
- A practical understanding of how to integrate security into the software development lifecycle
- Excellent communication skills, with the ability to articulate complex technical risks to diverse audiences
- A thorough understanding of the incident response process and the principles of Zero Trust architecture
- A proactive approach to staying updated with the latest security threats, vulnerabilities, and mitigation techniques
- Hands-on experience helping a company achieve and maintain compliance with frameworks like SOC 2, ISO 27001, or PCI DSS
- Experience in automating security controls and compliance checks against standards and frameworks which include SOC 2, ISO 27001, PCI DSS/3DS
- Experience performing secure code reviews and using SAST/DAST tools for security approvals
- Expertise in Kubernetes, securing clusters and meshes (Cilium is preferable), networking best practices and RBAC implementation (CKA, CKS qualifications are a plus)
- Container security knowledge including container image provenance (e.g. Sigstore, Notary) with an in-depth knowledge of container runtimes
- Strong understanding of network protocols & practices, firewalls, intrusion detection/prevention systems and WAFs
- Understanding of integrating security into the software development lifecycle
- Experience performing secure code reviews and security approvals including the use of static and dynamic application security testing (SAST/DAST) tools
- Experience in Cryptography management & enhancements
- Experience configuring and utilising cloud-native security logging, monitoring, and detection services
- Experience with Infrastructure as Code and infrastructure provisioning tools (Cloudformation, Terraform) for analysis and review
- Scripting and programming skills (e.g., Python, Go) for creating proof-of-concepts or small scripts to validate findings
- Relevant security certifications such as ISC2 CC, CISSP, CCSP, CISM, AWS Security Specialist or GCP Professional Cloud Security Engineer
- Initial interview with our Staff Security Engineer - ~45 minutes
- Take home technical task to be discussed in the next interview
- Technical interview with some of our Security and Information Security team members - ~1.5 hours
- Final interview with our CTO / deputy CTO ~45 minutes
- 33 days holiday (including public holidays, which you can take when it works best for you)
- An extra day's holiday for your birthday
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
- 16 hours paid volunteering time a year
- Salary sacrifice, company enhanced pension scheme
- Life insurance at 4x your salary & group income protection
- Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
- Generous family-friendly policies
- Incentives refer a friend scheme
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
- Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing