> Markdown version of [/jobs/ext/2215031-information-security-analyst-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/2215031-information-security-analyst-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - Vulnerability Management - **Company:** Starling Bank - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Bash Shell, Cloud Computing, Cloud Computing Security, Cyber Security, Python (Programming Language), PCI Data Security Standards, Systems Integration, Software Vulnerability Management, Scripting, Kubernetes, Teamcity, Terraform, Jenkins, Golang - **Published:** August 25, 2026 - **Apply:** https://find.jobs/jobs-near-me/apply/ats-redirect/?id=2939727755-2 ## About the Role We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. In Technology, we're asking that you attend the office a minimum of 1 day per week., * Demonstrated vulnerability management experience in a role such as vulnerability analyst, specialist, or engineer. * Strong technical knowledge of cloud platforms (aws, gcp) and cloud-native security architecture. * Experience with kubernetes and container security principles. * Security knowledge in AWS/GCP. * Basic scripting skill for automation purposes (Python, Go, Bash etc.). * Proven ability to develop integrations by interacting with APIs. * Excellent analytical and problem-solving skills to identify vulnerabilities and assess potential impact. * Strong written and verbal communication skills to foster collaboration across cross functional teams and stakeholders. * Adaptability to learn new technologies and evolve alongside the security landscape. Desirable * Knowledge of CI/CD pipelines management including TeamCity and Jenkins. * Knowledge of external attack surface management. * Proficiency in infrastructure as code, specifically terraform. * Competence in at least one programming language (e.g. java, golang, python) for automation. ## Description We are seeking a highly motivated and experienced Vulnerability Management Analyst to join our team. As a Vulnerability Management Analyst, your primary responsibility will be to enable remediation groups and engineers to address and resolve outstanding findings within agreed timeframes. You will achieve this by effectively triaging and prioritising vulnerabilities using a risk-based approach. Additionally, you will ensure that all assets within the scope of vulnerability management are scanned within agreed time frames. What you'll get to do * Partner with engineering and product teams to bridge the gap between security discovery and resolution, turning complex findings into clear, actionable tasks. * Utilise a risk-based approach to prioritise vulnerabilities based on their potential impact and exploitability * Coordinate with resolver groups to ensure timely and efficient remediation of identified vulnerabilities * Maintain and update a wide range of Vulnerability Management tools (Build Phase VM, CWPP, Endpoint VM, VM Intelligence) to ensure their effectiveness and reliability * Review and update Vulnerability Management related documentation to align with internal and external compliance requirements, industry best practices and emerging threats (e.g. ISO 27000, PCI-DSS, NIST) * Build and maintain our vulnerability ecosystem, from cloud-native stacks to endpoint security, using automation to reduce manual overhead for the wider team. * Process vulnerability data to provide reports, insights and metrics, that aid in the risk-based approach to vulnerability management. * Develop integrations for internal and external tools to capture data relevant to the vulnerability remediation process (e.g. by interacting with APIs) * Ensure compliance with relevant security standards, frameworks, and regulations * Stay up to date with the latest trends and developments in vulnerability management, security standards, and regulations, * Develop and maintain vulnerability management tooling, ensuring reliable coverage across cloud-native and on-premise environments. * Lead the shift towards automated remediation by implementing integrations that reduce manual toil for engineering teams. * Work with internal remediators to prioritise vulnerability management activities * Process vulnerability data to provide reports, insights and metrics, that aid in the risk-based approach to vulnerability management. * Develop integrations for internal and external tools to capture data relevant to the vulnerability remediation process * Ensure compliance with relevant security standards, frameworks, and regulations * Stay up to date with the latest trends and developments in vulnerability management, security standards, and regulations * Act as a subject matter expert, staying ahead of emerging threats and evolving the team's defensive strategy alongside the wider security organisation. What you can expect from us * Join a group of highly skilled individuals and have the opportunity to learn and grow with them * Work in a supportive and creative environment that encourages initiative and experimentation * Receive strong mentorship from senior members and peers to unlock your full potential * Collaborate with members of the wider security organisation and technical teams, fostering knowledge sharing and collaboration ## Related Videos - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Fullstack Developer Salary UK](https://www.wearedevelopers.com/magazine/251-fullstack-developer-salary-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)