
Senior Red Team Operator (Cyber Resilience)
- London
- Permanent
- Full-time
- Lead the design and execution of red team operations against Starling Bank (including scoping, planning, payload/infrastructure development, execution, reporting and workshops)
- Identify complex vulnerabilities and build advanced exploits
- Continually improve the methodology and capability of the team
- Mentor junior team members and share expertise
- Develop and document reusable attack components using realistic TTPs
- Lead purple team exercises and collaborate with the SOC team to enhance detection capabilities
- Translate red team tactics into actionable intelligence for blue team operations
- Develop advanced threat models and 'worst case scenario' playbooks based on emerging global risks (APTs, insider threats, supply chain compromise) and simulate complex real-world scenarios
- Lead cyber resilience testing initiatives to assess the Bank's ability to withstand and recover from cyber attacks, including controlled attack scenarios (ransomware, DDoS, data corruption) to evaluate resilience and recovery capabilities
- Drive identification of vulnerabilities, improve defence strategies and validate recovery processes
- Analyse complex test results, validate breach scenarios, document findings and provide strategic actionable recommendations
- Coordinate multi-stage testing scenarios and lead cross-team activities
- Experience leading red team operations and deep understanding of the benefits and pitfalls of different adversarial techniques
- Ability to define rules of engagement and demonstrate strong discipline and steady judgement, working both independently and as part of a team
- Experience conducting advanced security testing against cloud environments (AWS, GCP, Azure)
- Advanced security testing certifications (e.g. OSCP, CRTO, OSMR, OSCE, OSEP, cloud security or similar)
- Deep familiarity with the cyber risks faced by Starling Bank and other financial institutions
- Expert-level network and operating system fundamentals (MacOS, Linux and Windows)
- Proficiency with modern software engineering paradigms (CI/CD, Infra as Code)
- Leadership and mentoring experience
- Capability to manage risk and controls around red team activities
- Expertise in AI/ML systems security, including LLMs, transformers and model interpretability
- Advanced certifications such as CSSAS, CSSAM, CCT or similar
- Extensive experience in incident response, threat intelligence, or ethical hacking at an enterprise level
- Strong background in regulatory environments (e.g. ISO 27001, SOCII, GDPR or AI Act compliance)
- Software engineering expertise (Java, Kotlin, Go…) or advanced reverse engineering expertise
- Proven track record in blogging and speaking both internally to educate staff and externally at conferences
- Experience developing innovative security testing methodologies
- Stage 1 - 45 mins with one of the team
- Stage 2 - 60 mins technical interview with two team members
- Stage 3 - 45 min final with two executives
- 33 days holiday (including public holidays, which you can take when it works best for you)
- An extra day's holiday for your birthday
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
- 16 hours paid volunteering time a year
- Salary sacrifice, company enhanced pension scheme
- Life insurance at 4x your salary & group income protection
- Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
- Generous family-friendly policies
- Incentives refer a friend scheme
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
- Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing