About the role
We are seeking a highly motivated and experienced Vulnerability Manager to lead a vulnerability management team. A successful candidate will work with the team to analyse emerging vulnerabilities provided by threat intelligence sources and penetration testing. The vulnerability manager will collaborate with various technology and engineering teams to share vulnerability findings, provide guidance, and assist through the remediation process. This person will help present this information in a simple digestible format, and coordinate remediation and mitigation efforts with teams across remote and office locations. There will be opportunities to guide continual improvement of the vulnerability management process.
Hybrid working
We have a hybrid approach to working here at Starling - our preference is that you’re located within a commutable distance of one of our offices so that we’re able to interact and collaborate in person. In Technology, we’re asking that you attend the office a minimum of 1 day per week.
Responsibilities
- Assessing and investigating emerging vulnerabilities, drawing from threat intelligence sources and internal software and infrastructure scans, providing comprehensive guidance based on findings.
- Collaborating with relevant technology teams, including security, engineering, workplace technology, data, and infrastructure, to ensure the timely resolution of identified issues.
- Tracking and reporting on the progress of mitigation efforts and resolutions to pertinent audiences.
- Overseeing the vulnerability management and policy compliance lifecycle, which encompasses scanning, prioritisation, reporting, and remediation governance.
- Promote vulnerability management standards, procedures & guidelines, and best practices outside the security functions.
- Identify trends and themes in issues which occur and work collaboratively with wider teams to develop process and procedure improvements.
- Conducting hands‑on vulnerability analysis across infrastructure, cloud environments, and applications.
- Ensuring compliance with internal security policies and regulatory requirements.
- Providing reporting, key performance indicators (KPIs), and executive visibility on the organisation’s vulnerability posture.
- Supporting audits, risk assessments, and responses to emerging vulnerabilities.
- Active involvement in internal and external audits, and experience in managing audit relationships.
Qualifications
- Proven experience in a similar leadership role, guiding and motivating a team of subject matter experts.
- Strong understanding of Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS), threat intelligence, and remediation workflows.
- Knowledge of common vulnerabilities, attack vectors, and mitigation techniques.
- Familiarity with application development platforms.
- Excellent written and verbal communication skills for effective collaboration with cross functional teams and stakeholders.
- Ability to understand the larger context while effectively managing complex details.
- Willingness and capability to learn new technologies and adapt to evolving security landscapes.
- Practical experience in the following fields of vulnerability management:
Endpoint Vulnerability Scanning
Vulnerability Intelligence
Application Security (AppSec) Vulnerability Management
Vulnerability Management for cloud native workloads
- Desirable technical knowledge includes:
Cloud services (AWS, GCP)
Containers
MacOS and Windows environments
Data analysis and SQL
Interview process
- First stage with the Penetration Testing and Vulnerability Management Lead.
- Second stage with additional members of the Vulnerability Management team.
- Final stage with InfoSec Director and CISO.
Benefits
- 33 days holiday (including public holidays, which you can take when it works best for you).
- An extra day’s holiday for your birthday.
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off.
- 16 hours paid volunteering time a year.
- Salary sacrifice, company enhanced pension scheme.
- Life insurance at 4x your salary & group income protection.
- Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton.
- Generous family‑friendly policies.
- Incentives – refer a friend scheme.
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks.
- Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing.
Equal Employment Opportunity
Starling Bank is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.
#J-18808-Ljbffr