About this role
Salary: £65,000 - 105,000 per year
Requirements: We are looking for a mid-to-senior level Information Security Architect or Senior Security Engineering professional with experience designing secure, distributed systems in modern cloud environments such as AWS and GCP.We need deep practical and theoretical knowledge of symmetric and asymmetric cryptography, PKI management, digital signatures, key management systems, and HSMs.We require strong understanding of Post-Quantum Cryptography, quantum computing threats to modern encryption, NIST PQC standards, hybrid key exchange, and crypto-agility.We need demonstrated threat modeling and system design experience across complex cloud-native applications, APIs, and microservices architectures such as Kubernetes and ECS.We value a pragmatic approach to security that enables engineering speed and minimizes developer friction.We expect excellent written and verbal communication skills, with the ability to explain complex technical and cryptographic risks clearly to technical teams and senior leadership.Experience in fintech, banking, or highly regulated cloud environments such as PCI-DSS, ISO 27001, or NIST guidelines is desirable.A strong background in highly technical security roles such as Security Engineering, Infrastructure Engineering, or Penetration Testing is desirable.Experience in infrastructure, application, and AI security, including container security, secure code reviews, and secure integration of generative AI or ML, is desirable.Practical experience with the SABSA framework is desirable.Recognised industry security certifications such as SABSA, CISSP, AWS Security Specialty, or specialised cryptography credentials are desirable. Responsibilities: Architect end-to-end security solutions for cloud-native applications, microservices, and modern banking platforms.Develop and lead our Post-Quantum Cryptography transition roadmap and crypto-inventory strategy.Perform threat modeling and technical risk assessments on new and existing platform architectures.Define, document, and promote enterprise cryptographic management standards, including key lifecycle, hardware security, and modern cipher suites.Review architectural design documents, RFCs, and ADRs to ensure alignment with our security guardrails and regulatory requirements.Mentor engineering teams and provide guidance on cryptographic implementations, secure secret management, and data protection at rest and in transit.Support the wider Security Architecture team with day-to-day security architecture activities and ad hoc advisory services. Technologies: AIAWSArchitectCloudCryptographyGCPHardwareSupportKubernetesRESTSecuritymicroservices More:
We are Starling, the UKs first and leading digital bank, on a mission to fix banking through fast technology, fair service, and honest values. We are a multi-award-winning, tech-first bank with more than 3,000 people across our offices in London, Cardiff, Dublin, Southampton, and Manchester. Since launching in 2014, we have surpassed 3.5 million accounts and 350,000 business customers. Our Security Architecture team plays a key role in shaping security across our organisation, and this role has a strategic focus on Cryptography and Post-Quantum Readiness. We work in a hybrid model, with a preference for candidates within commuting distance of one of our offices and a minimum of 1 day per week in the office for Technology roles. We offer a collaborative, flat culture, a conversational interview process, and a benefits package that includes 25 days holiday, an extra day off for your birthday, enhanced pension, life insurance, private medical insurance, volunteering time, family-friendly policies, wellbeing and retail perks, and support for cycle to work, gym partnerships, and EV leasing. We value diversity, inclusion, ownership, collaboration, and a willingness to join us even if you do not tick every box.
last updated 36 week of 2026