Information Security Lead (Incident Response)

Details of the offer

Starling is the UK's first and leading digital bank on a mission to fix banking! We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way.
We're a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company. We're a bank, but better: fairer, easier to use and designed to demystify money for everyone. We employ more than 4,000 people across our London, Southampton, Cardiff and Manchester offices.
Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be; innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture; you will find support in your team and from across the business, we are in this together!
The way to thrive and shine within Starling is to be a self-driven individual and be able to take full ownership of everything around you: from building things, designing, discovering, to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers. Our purpose is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.
Hybrid Working We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person.
About the Role We're open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. The opportunity is to develop and deliver your engineering and/or analyst skills within the Cyber Security group; we recognise that an individual's professional development, strengths and preferences will change over time and so will the demands and opportunities within the bank.
We value people being engaged and caring about customers, caring about the code they write or the business systems and processes they develop to make Starling Secure.
As a member of the Cyber Security team, whilst it is not expected that you will have worked in all of these areas, you will have a broad experience and knowledge across:
Essential Promote cyber security standards, procedures & guidelines, and best practices outside the security functions. Strong communication and interpersonal skills including the ability to explain complex security concepts to technical and non-technical audiences. Ability to engage and communicate with senior stakeholders and support teams across any number of business functions. Understanding of cyber security controls across different technology architectures including cloud (AWS, GCP). Design, development (including scripting and configuration) and continuous improvement of security solutions. Security development lifecycle and deployment. Champion efforts to secure business processes and data through collaboration. Understanding and awareness of security principles including privileged access, role-based access technologies and approaches. Innovation mindset. Enjoy problem solving. Be self-motivated and want to continue to learn and develop and challenge. Programming skills e.g. Python, Go, Java, Rust. Engage with the broader security community within and external to the organisation. Desirable Experience within or across Identify/Detect/Protect/Recover/Respond or Governance NIST Domains. Experience with security control frameworks such as NIST CSF, CIS benchmarks, ISO27001, SOC2. Specific Job Skills and Responsibilities Security Event & Incident Management: Provide leadership and direction during high-priority incidents. Demonstrate command and control, whilst maintaining an overall incident perspective and ensuring the Incident Management processes are followed. Produce clearly written post-incident reporting, and conduct post-incident reviews to ensure lessons learned and remediation steps are implemented. Acting as engineering liaison, providing SME knowledge on infrastructure during an incident. Participate and contribute to threat-led investigation and exercise activities providing guidance and recommendation on improvements for implementation. Stay abreast of current industry trends relevant to the business and cybersecurity. Security Information & Event Management Development: Identify, prioritise, define, and enhance log ingestion (including new sources) into the organisation's SIEM & SOAR enabling continuous improvement in event detection, incident analysis and response. Enable and continuously improve the automation of processes within the wider security operations team leading to effective, timely and scalable response in the evolving threat landscape. Support the development of log pipelines to the SIEM, collaborating with wider technology teams across requisite architecture, in particular data engineering. Support the development and continuous improvement of log parsing capabilities. Ensure technical development within security operations is aligned to wider system development life cycle and operating procedures. Ensure security operations development and automation is clearly documented providing knowledge share to the wider security operations team as appropriate. Act as a subject matter expert, review and advise on security log architecture to enable development of effective detection controls and performant log ingestion. Evaluate new solutions and improvements to existing telemetry and processes based on incident outcomes and capability assessments; identify and propose practicable proportionate improvements. Continually develop and maintain knowledge and expertise on the Bank proprietary systems, security model and wider security best practices. Security Operations Team wide responsibilities: Collaborate with the wider Security operations team in the definition and execution of training to ensure effective security event and incident management procedures. Collaborate with the wider Security and business teams to enable continuous improvement in the efficacy of security information and event management control environment. Acting as engineering liaison, providing SME knowledge on security operations infrastructure and information analysis during an incident. Support and guide further Information Security Engineers within the Security Operations team in the delivery of new capabilities and continuous improvement of team solutions. Participate in cyber security team hiring procedures as required. Interview process Interviewing is a two-way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general, you can expect the below, following a chat with one of our Talent Team:
Overall personality and general interview - Reporting manager - 30 minutes Role based competency - Security team - 1.5 hours Final Interview - Leadership - 30 minutes Starling technology works in a hybrid pattern both from home and one of our three offices. Our preference is that you're located within a commutable distance to either our London, Southampton or Cardiff office, so that we're able to see each other and collaborate in person three days a week.
25 days holiday (plus take your public holiday allowance whenever works best for you) An extra day's holiday for your birthday Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off 16 hours paid volunteering time a year Salary sacrifice, company enhanced pension scheme Life insurance at 4x your salary & group income protection Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton Generous family-friendly policies Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing About Us You may be put off applying for a role because you don't tick every box. Forget that! While we can't accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren't sure if you're 100% there yet, get in touch anyway. We're on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we're proud to bring together people of all backgrounds and experiences who love working together to solve problems.
Starling Bank is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.
When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.
#J-18808-Ljbffr


Nominal Salary: To be agreed

Source: Whatjobs_Ppc

Requirements

Full Stack Php Developer

Full Stack PHP Developer Cardiff £45,000 - £50,000 Hybrid Flexible Working Options Great Company Training Pension Cycle to Work Scheme Own Computer Company B...


Ernest Gordon Recruitment - Cardiff

Published a month ago

Chief Technology Officer (Cto)

Do not pass up this chance, apply quickly if your experience and skills match what is in the following description. Chief Technology Officer About Sero: Sero...


Sero - Cardiff

Published a month ago

Senior Sap Solutions Architect

Senior SAP Solutions Architect Permanent Salary: £67,000 company Benefits Location: Hybrid (2-3 days per week in Cardiff/Newport) We require a Senior SAP Sol...


Certes It Service Solutions - Cardiff

Published a month ago

Software Development Manager - Cardiff - Hybrid Working

Software Development Manager - Cardiff Drive innovation, lead dynamic teams, and shape the future of software! Are you a visionary Software Development Manag...


Circle Group - Cardiff

Published 17 days ago

Built at: 2024-12-18T12:08:31.342Z