
Senior Cloud Security Engineer (GCP) - Engine by Starling
Starling Bank1 day ago
London, United KingdomSenior
Responsibilities
- Define Google Cloud security architecture covering cloud identity, runtime security, and security posture.
- Design, document, build, and maintain secure scalable GCP infrastructure using Infrastructure as Code.
- Implement secure access, authentication, authorization, IAM, and workload identity mechanisms.
- Engineer and automate GCP security controls and compliance checks for standards including PCI DSS and 3DS.
- Deploy security infrastructure across growing cloud environments.
- Perform security assessments, audits, threat modelling, architecture reviews, risk triage, and corrective control design.
- Lead incident response, including investigation and remediation of security breaches.
- Support security awareness and training programs and promote DevSecOps practices.
Requirements
- Deep expertise in GCP cloud security architecture, including landing zones, organization policies, VPC Service Controls, and GCP IAM.
- Experience with GKE, Kubernetes cluster security, service-oriented architectures, distributed systems, immutable infrastructure, Compute Engine, Shared VPC, and Cloud SQL.
- Expertise with Terraform and other infrastructure provisioning tools.
- Experience with Security Command Center, Binary Authorization, Artifact Registry, Artifact Analysis, Cloud KMS, Cloud External Key Manager, Secret Manager, Workload Identity, and Workload Identity Federation.
- Strong programming skills in Python, Go, or other languages for security automation and open-source contributions.
- Knowledge of security principles, threat detection and mitigation, common attack vectors, OWASP Top 10, and the MITRE ATT&CK Framework.
- Understanding of incident response, vulnerability identification, security requirements documentation, and risk reduction.
- Desirable experience includes TCP/IP, BGP, VPNs, firewalls, WAFs, IDS/IPS, hybrid GCP and on-premises connectivity, Assured Workloads, Access Transparency, NIST, SOC 2, ISO 27001, PCI DSS, 3DS, Sigstore, Notary, SAST, DAST, and cryptography management.
- Relevant certifications such as ISC2 CC, CISSP, CCSP, CISM, AWS Security Specialty, or GCP Professional Cloud Security Engineer are desirable.
Benefits
- 33 days of holiday including public holidays, with an additional birthday holiday and options to buy or sell up to five extra days.
- 16 hours of paid volunteering time annually, salary sacrifice, and an enhanced pension scheme.
- Life insurance at four times salary and group income protection.
- Private Medical Insurance with VitalityHealth, including mental health support and cancer care.
- Family-friendly policies, referral incentives, Perkbox membership, retail and wellness discounts, Cycle to Work, gym partnerships, and electric vehicle leasing.
- Hybrid working with a preference for candidates within commuting distance of an office.
Tech Stack
Categories
About Starling Bank
Starling Bank is a UK digital bank offering personal and business current accounts, savings, cards, and lending through a mobile-first platform. Founded in 2014 and headquartered in London, it holds a UK banking licence and is privately held. It also commercialises its core technology as Engine by Starling, a SaaS platform that provides banking infrastructure to banks and financial institutions internationally.