
Quantum Cryptography Architect
Starling Bank14 days ago
Manchester, United Kingdom +2 moreStaff+
Responsibilities
- Own and lead Starling’s Post-Quantum Cryptography strategy, crypto-inventory, and cryptographic-agility roadmap.
- Architect end-to-end security solutions for cloud-native applications, microservices, modern banking platforms, and distributed systems across AWS and GCP.
- Provide expert guidance on PKI, HSMs, key management, KMS, service mesh security, transport-layer protocols, secrets, and data protection.
- Perform threat modeling and technical risk assessments for new and existing architectures.
- Define, document, and promote enterprise cryptographic management standards, including key lifecycle, hardware security, and modern cipher suites.
- Review architectural design documents, RFCs, and ADRs for security guardrail and regulatory alignment.
- Build proof-of-concept security solutions and provide pragmatic guidance to engineering teams.
- Collaborate with software engineers, cloud architects, and security operations, and mentor engineering teams on secure implementations.
- Stay current on security threats, industry trends, and regulatory standards and provide security architecture advisory support.
Requirements
- Proven experience as an Information Security Architect or Senior Security Engineer designing secure distributed systems in modern cloud environments using AWS and GCP.
- Comprehensive practical and theoretical knowledge of symmetric and asymmetric cryptography, PKI management, digital signatures, KMS, and HSMs.
- Strong understanding of quantum-computing threats, NIST PQC standards, hybrid key exchange, and crypto-agility strategies.
- Demonstrated ability to perform threat modeling on complex cloud-native applications, APIs, and microservices architectures such as Kubernetes and ECS.
- Ability to design security controls that enable engineering speed and minimize developer friction.
- Excellent written and verbal communication skills, including the ability to explain complex technical and cryptographic risks to technical teams and senior leadership.
- Experience in fintech, banking, or highly regulated cloud environments and familiarity with PCI-DSS, ISO 27001, or NIST guidelines is desirable.
- Technical experience in security engineering, infrastructure engineering, or penetration testing is desirable.
- Experience with infrastructure, application, and AI security, including container security, secure code reviews, and secure generative AI/ML integration, is desirable.
- Experience applying the SABSA framework is desirable.
- Security certifications such as SABSA, CISSP, AWS Security Specialty, or specialized cryptography credentials are desirable.
Benefits
- Hybrid work with a minimum of one day per week in a Starling office and a preference for being within commuting distance.
- 25 days of holiday plus public holiday allowance, an extra birthday holiday, and increased annual leave with length of service.
- Option to buy or sell up to five additional days off.
- 16 hours of paid volunteering time per year.
- Salary sacrifice and an enhanced company pension scheme.
- Life insurance at four times salary and group income protection.
- Private Medical Insurance with VitalityHealth, including mental health support and cancer care.
- Generous family-friendly policies.
- Perkbox membership with retail discounts, wellness resources, and weekly free and boosted perks.
- Cycle to Work, salary-sacrificed gym partnerships, and electric vehicle leasing initiatives.