Starling is the UK’s first and leading digital bank on a mission to fix banking! We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way.
We’re a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company. We’re a bank, but better: fairer, easier to use and designed to demystify money for everyone. We employ more than 4,000 people across our London, Southampton, Cardiff and Manchester offices.
Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be, innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture, you will find support in your team and from across the business, we are in this together!
The way to thrive and shine within Starling is to be a self-driven individual and be able to take full ownership of everything around you: From building things, designing, discovering, to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers. Our purpose is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.
Hybrid Working
We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. In Technology, we're asking that you attend the office a minimum of 1 day per week.
About the Role and Opportunity
We’re open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. The opportunity is to develop and deliver your managerial and leadership skills within the Cyber security group, we recognise that an individual's professional development, strengths and preferences will change over time and so will the demands and opportunities within the bank.
We value people being engaged and caring about customers, caring about the code they write or the business systems and processes they develop to make Starling Secure.
As a member of the Cyber Security team, whilst It is not expected that you will have worked in all of these areas, you will have a broad experience and knowledge across:
Essential
1. Hands-on experience with enterprise-grade security tooling.
2. Experience of delivering technology solutions in a highly regulated environment.
3. Proven experience in IAM leadership with end to end exposure to identity governance and access management.
4. Strong Knowledge of IAM principles and frameworks ( RBAC, PAM, SSO, MFA, Zero Trust).
5. Demonstrated ability to lead and inspire cross-functional teams
6. Design, development (including scripting and configuration) and continuous improvement of security solutions.
7. Track record of delivery and service improvement.
8. Strong communication and interpersonal skills including the ability to explain complex security concepts to technical and non-technical audiences.
9. Strong general Cyber Security domain knowledge, including Cloud security.
Desirable
10. Programming skills Python, Go, Java, Rust.
11. Experience with security control frameworks such as NIST CSF, CIS benchmarks, ISO27001, SOC2.
Requirements
12. Demonstrated leadership in managing a technical team, providing support across operations, projects, and engineering.
13. Experience implementing IAM solutions in hybrid or multi-cloud environments
14. Experience of design and delivery related to Identity Management Systems, Okta, EntraID, Ping, etc.
15. Experience of design and delivery related to Identity Governance Systems, Sailpoint, Saviynt, ConductorOne, etc.
16. Experience with automation and developer tooling (CI/CD) and Infrastructure as Code.
17. Understanding of best-practice credential management practices.
18. Understanding of modern authentication technologies, their application and strengths/drawbacks.
19. Strong identity knowledge, including Privileged Access Management, Role Based Access Control and Identity Governance.
20. Excellent verbal and written communication skills.
Responsibilities
21. Lead, mentor and develop the IAM team, building technical capability and strong stakeholder relationships
22. Contribute to and execute the IAM roadmap with the Information Security Lead - Identity and Access Management, ensuring alignment with business, compliance and security objectives
23. Oversee the full IAM lifecycle including identity governance, privileged access management, authentication, and authorisation.
24. Ensure access controls, policies, processes and procedures meet regulatory, audit, and security requirements
25. Drive modernisation initiatives such as zero trust, adaptive authentication and cloud based IAM
26. Collaborate with the wider business functions to embed IAM across enterprise services
27. Provide reporting and insights into IAM programme health, risks, and progress for senior leadership
28. Organise and manage the team to ensure operational coverage and that staff are appropriately skilled.
29. Responsible for the delivery of resilient Identity and Access Management services to the Bank. This includes both processes and technologies covering Identity Management, Authentication and Identity Governance.
30. Responsible for the processes and controls governing access to COTS and bespoke Banking tooling, including Role-Based Access Control.
31. Collaborate with engineering and business teams to facilitate delivery, including:
32. Review and analysis of proposed technical solutions and business processes to identify appropriate security controls.
33. Input and guidance to security related technical architecture and design decisions.
34. Code review of features and critical security components.
35. Advising on remediation of security issues and processes to address root causes.
36. Develop policies, standards, processes, guidelines, and documentation for consumption by internal teams.
37. Triage and management of IAM security events including, where necessary, participation in IAM security incident management.
Interview Process
Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:
38. General Interview and Role Based Competency - Line Manager and Director of InfoSec
39. Technical Interview with our Information Security Director
40. Final Interview - Leadership (CISO)
Benefits
41. 25 days holiday (plus take your public holiday allowance whenever works best for you)
42. An extra day’s holiday for your birthday
43. Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
44. 16 hours paid volunteering time a year
45. Salary sacrifice, company enhanced pension scheme
46. Life insurance at 4x your salary & group income protection
47. Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
48. Generous family-friendly policies
49. Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
50. Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
About us
You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.