Penetration Tester securing systems and customer assets at Starling, a digital bank. Collaborating with teams to conduct penetration tests and enhance security processes.
Responsibilities
Scoping and performing mobile, web application, cloud, and infrastructure penetration tests.
Automation of security testing, and development of internal tooling, to achieve continuous assurance.
Collaboration with engineering teams to facilitate secure development, including:
Review and analysis of proposed technical solutions to identify appropriate security controls.
Input and guidance to security related technical architecture and design decisions.
Code review of features and critical security components.
Practical security testing.
Advising on remediation of security issues and processes to address root causes.
Security assurance reviews of third-party solutions.
Identifying and implementing improvements to the team’s internal processes and procedures.
Review, analysis and reporting of external threats relevant to Starling systems and solutions, in the context of Starling’s desired security posture.
Requirements
5+ years technical information security experience.
Experience of mobile, web application, cloud and infrastructure penetration testing.
Strong technical knowledge in:
Mobile security (iOS and Android)
Web application security
Networking and associated protocols
Cloud security (AWS and GCP)
Containers and Kubernetes
A desire to learn, and ability to apply technical security knowledge to new and unfamiliar areas.
CREST, OSCP or similar industry penetration testing qualification
A good understanding of applied cryptographic techniques.
Reverse engineering and exploit development capabilities.
Experience of security testing in an agile SDLC.
Threat modelling experience.
Experience performing code reviews, particularly in Java and Go.
Experience of fulfilling a client facing security consulting role.
Excellent verbal and written communication skills.
Experience in automation of security testing, with previous development experience desirable.
Benefits
25 days holiday (plus take your public holiday allowance whenever works best for you)
An extra day’s holiday for your birthday
Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
16 hours paid volunteering time a year
Salary sacrifice, company enhanced pension scheme
Life insurance at 4x your salary & group income protection
Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
Generous family-friendly policies
Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing
Software Engineer developing QA automation solutions for Broadridge. Supporting code quality and technical analysis across the development lifecycle in a hybrid role.
Agile Dev Team Member V conducting quality engineering and testing while developing test strategies and mentoring junior staff at Capgemini. Collaborating across teams for continuous improvement in a hybrid work environment.
Senior QA Analyst responsible for manual testing of web and mobile applications at Viv Technologies. Collaborating with project stakeholders and development teams to ensure software quality.
Senior Software Quality Engineer ensuring software quality using modern testing tools in industries like Automotive and Aerospace. Collaborating with stakeholders and overseeing proof of concepts in projects.
Quality Tester responsible for NX functionalities including Modeling and Testing at Expleo. Collaborating with development and business teams to validate technical requirements and improve processes.
QAO Technician supporting testing of commercial vehicle steering systems in a laboratory environment. Collaborating with engineers to ensure compliance with testing requirements and standards.
Quality Assurance Manager ensuring compliance with GMP and regulatory standards for pharmaceutical products. Overseeing QA activities and maintaining a strong quality culture at the site.
Quality Engineer at Datwyler ensuring compliance with regulatory requirements and supporting manufacturing processes. Collaborating to drive continuous improvement initiatives in a regulated environment.
Senior Quality Assurance Engineer at VIA focusing on integrating testing into engineering processes. Leveraging AI - driven automation to enhance QA efficiency and maintain security standards.