> Markdown version of [/jobs/ext/2214849-software-engineer-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/2214849-software-engineer-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer - Vulnerability Management - **Company:** Starling Bank - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Cloud Computing, Cyber Security, Software Vulnerability Management, Software Security, Containerization, Kubernetes, CIS Benchmarks, Terraform, Vulnerability Analysis - **Published:** August 25, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2939727735-2 ## About the Role We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. In Technology, we're asking that you attend the office a minimum of 1 day per week., Strong technical knowledge, including: * Cloud Experience (AWS, GCP) * Kubernetes and Container experience * Infrastructure as code (terraform) * Proficiency with either Go or Java programming languages * Strong engineering and automation background with a keen interest in Vulnerability Management * Experience with developing integrations by interacting with APIs * Ability and willingness to learn new technologies and adapt to evolving security landscapes * Capability to understand the bigger picture while effectively managing details * Strong written and verbal communication skills to effectively collaborate with cross-functional teams and stakeholders Additional Technical Requirements * Deep understanding of container & orchestration security: practical knowledge of securing containerised environments, including image scanning, runtime protection, and hardening K8s manifests. * Proficiency in cloud posture management: familiarity with tools and frameworks to monitor cloud configuration drift and ensure adherence to security benchmarks (e.g. CIS Benchmarks, AWS/GCP best practices) * Riskbased prioritisation models: proven ability to translate raw vulnerability data (CVSS scores, exploitability) into business contextualised risk insights, enabling engineering teams to prioritise remediation effectively. * Practical experience in one or more of the vulnerability management fields would be desirable but not essential: * Endpoint vulnerability scanning * Vulnerability intelligence, * AppSec vulnerability management * Vulnerability management of cloud native workloads * External attack surface management Experience with Software Bill of Materials (SBOM) management, specifically ingesting and correlating standard format ## Description We are seeking a highly motivated and experienced Vulnerability Management Engineer to join our Cyber Security team. As a Vulnerability Management Engineer, your primary responsibility will be to manage vulnerability management tooling, and have an active role in improving existing processes. You will achieve this by creating automated solutions through collaboration with technical teams across Starling., * Design, build, and maintain robust vulnerability management tooling and technical solutions. * Drive efficiency by implementing automated solutions that eliminate manual overhead and streamline operations. * Partner with internal engineering teams and remediators to intelligently prioritise remediation activities. * Synthesise raw vulnerability data into actionable insights, reports, and metrics to support a risk-based security posture. * Engineer custom integrations between internal and external platforms to enhance data capture throughout the remediation lifecycle. * Maintain strict adherence to global security standards, regulatory requirements, and industry frameworks. * Keep at the forefront of the industry by monitoring emerging trends in vulnerability management and shifting regulatory landscapes. * Treat security as a continuous engineering challenge to outpace the threat landscape, proactively identifying vulnerabilities and architecting technical solutions to fortify our global ecosystem. * Develop and maintain comprehensive technical playbooks and runbooks to standardise vulnerability triage, remediation, and incident response procedures, ensuring consistent, repeatable, and efficient security operations across the team. * Utilise pattern and trend analysis to identify "Vulnerability Hotspots" (e.g., recurring issues in specific base Images or teams) to drive strategic risk reduction rather than just individual remediation., Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team: * First stage with our Information Security Lead * Second stage - Take home task * Third stage with additional members of the Vulnerability Management and Security Engineering team * Final stage with Security Engineering Lead and Information Security Director ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fullstack Developer Salary UK](https://www.wearedevelopers.com/magazine/251-fullstack-developer-salary-uk) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Software Engineer Salary in The UK](https://www.wearedevelopers.com/magazine/231-software-engineer-salary-in-the-uk)