
Staff Cloud Security Engineer (GCP) - Engine by Starling
Starling Bank22 hours ago
London, United KingdomStaff+
Responsibilities
- Define GCP security architecture covering cloud identity, runtime security, and security posture.
- Design, document, build, and maintain secure scalable GCP infrastructure using Infrastructure as Code.
- Implement secure access, authentication, authorization, and identity mechanisms.
- Engineer and automate GCP security and compliance controls for PCI DSS and 3DS requirements.
- Drive security infrastructure deployments across growing environments.
- Conduct security assessments, audits, threat modeling, architecture reviews, risk triage, and remediation design.
- Lead investigation and remediation during security breaches and other incidents.
- Support security awareness and training programs and promote DevSecOps practices.
Requirements
- Deep expertise in GCP cloud security architecture and a proven track record creating GCP landing zones.
- Experience with organization policies, VPC Service Controls, GCP IAM, GKE, Compute Engine, Shared VPC, and Cloud SQL.
- Expertise securing Kubernetes clusters and service meshes, with networking and RBAC knowledge; CKA or CKS qualifications are a plus.
- Experience with Terraform and other infrastructure provisioning tools.
- Experience with Security Command Center, Binary Authorization, Artifact Registry, Artifact Analysis, Cloud KMS, Cloud External Key Manager, Secret Manager, Workload Identity, and Workload Identity Federation.
- Strong programming skills in Python, Go, or other languages for security automation and open-source contributions.
- Knowledge of security principles, threat detection and mitigation, OWASP Top 10, MITRE ATT&CK, social engineering, vulnerabilities, and incident response.
- Desirable experience includes network security, TCP/IP, BGP, VPNs, firewalls, WAFs, IDS/IPS, hybrid GCP/on-premise connectivity, Assured Workloads, Access Transparency, NIST, SOC 2, ISO 27001, PCI DSS, 3DS, Sigstore, Notary, container runtimes, secure SDLC, SAST, DAST, cryptography, and relevant security certifications.
- Strong problem-solving, communication, documentation, active listening, and stakeholder collaboration skills.
Benefits
- Hybrid working arrangement with a preference for being within commuting distance of an office.
- 33 days of holiday including public holidays, plus an additional birthday holiday and options to buy or sell up to five extra days.
- Annual leave increases with service length.
- 16 hours of paid volunteering time annually.
- Salary sacrifice and an enhanced company pension scheme.
- Life insurance at four times salary and group income protection.
- Private Medical Insurance with VitalityHealth, including mental health support and cancer care.
- Generous family-friendly policies and a refer-a-friend incentive scheme.
- Perkbox membership with retail discounts, wellness services, and weekly perks.
- Cycle to Work, salary-sacrificed gym partnerships, and electric vehicle leasing initiatives.
Tech Stack
Categories
About Starling Bank
Starling Bank is a UK digital bank offering personal and business current accounts, savings, cards, and lending through a mobile-first platform. Founded in 2014 and headquartered in London, it holds a UK banking licence and is privately held. It also commercialises its core technology as Engine by Starling, a SaaS platform that provides banking infrastructure to banks and financial institutions internationally.