Level

Starling Bank

Information Security Analyst - Operations

AI in this role

Information Security Analyst focusing on SOC operations, incident triage, threat hunting, and security monitoring in a digital bank.

edr
incident-responsethreat-huntingsecurity-operationssecopstriage

Starling is the UK’s first and leading digital bank on a mission to fix banking! We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way.

We’re a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company. We’re a bank, but better: fairer, easier to use and designed to demystify money for everyone. We employ more than 3,000 people across our London, Southampton, Cardiff and Manchester offices.

Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be, innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture, you will find support in your team and from across the business, we are in this together!

The way to thrive and shine within Starling is to be a self-driven individual and be able to take full ownership of everything around you: From building things, designing, discovering, to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers. Our purpose is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

About the Role

To support our growth, we are looking for SOC Analysts to join our growing cyber security function. This role will be supporting our 24/7 operational capabilities (On-call rota, not shift based).

As a member of the Starling SOC team, you will be working with the industries brightest SecOps professionals to protect Starling customers, assets, and systems using the latest technologies.

Incident Triage, Response, and Investigations based on Alerts received from multiple sources which include:

  • Cloud Infrastructure/Security.
  • Endpoint Detection and Response.
  • Perimeter detection tooling.
  • Investigating and responding to security alerts raised by Users.
  • Enhancing and creating analytic triggers to enhance alert efficacy.
  • Continuous development of incident handling and readiness processes.
  • Proactive threat hunting based on threat intelligence.
  • Documentation of incidents and investigations.

Requirements

About your Skills

We’re open-minded when it comes to hiring and we care more about aptitude and attitude than specific experience or qualifications. Below is an overview:

  • 3+ years experience in an in-house SOC role and team
  • Understanding of AWS Security Solutions (or other Public Cloud Solutions)
  • Analysis and Incident Response experience with Cloud systems such as AWS or GCP
  • Experience working and supporting analytics/SIEM platforms.
  • Experience working in CSIRT/SOC functions.
  • Experience supporting and conducting Incident Response engagements.
  • Experience in endpoint based investigations.
  • Experience in cloud based investigations.
  • Experience with Incident Command and conducting Tabletop Exercises
  • Interest in Automation.
  • Interest in Threat Intelligence and Analytic Tuning.
  • A high level understanding of mobile, network and operating system security controls.
  • Any experience of programming in Python, Go and/or Java.
  • A Cyber/Information Security related degree and/or relevant cyber security qualification(s) would be desired but not required

Interview Process

Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below video interviews, following a chat with one of our Talent Team:

  • First Interview: 45 minutes
  • Technical Interview: 90 minutes
  • Final Interview: 30 minutes

Benefits

We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. In Technology, we're asking that you attend the office a minimum of 1 day per week.

  • 25 days holiday (plus take your public holiday allowance whenever works best for you)
  • An extra day’s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

About Us

You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.

Starling Bank is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. 

When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.

We use AI tools to support various parts of our recruitment process, helping our team manage applications and assessments more efficiently. These tools are strictly used for support and do not replace human judgment with all final hiring decisions being made by our team. If you would like more information about how your data is processed, please reach out to us.

How we rate this

Information Security Analyst - Operations at Starling Bank rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Incident ResponseThreat HuntingSecurity OperationsSecopsTriageEdr

Questions you could be asked

  1. Tell me about a project where incident response was part of your work. What did you do?
  2. Tell me about a project where threat hunting was part of your work. What did you do?
  3. Tell me about a project where security operations was part of your work. What did you do?
  4. Tell me about a project where secops was part of your work. What did you do?
  5. Tell me about a project where triage was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: Incident Response, Threat Hunting, Security Operations, Secops, and Triage. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new cybersecurity jobs by email

One email a week with the new cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Starling Bank

More cybersecurity jobs

Related searches

Same AI level