Information Security Operations Lead (Sydney, Australia)
About the Starling Group
We are Starling. We started by building a new kind of bank because we knew technology had the power to transform how people save, spend, and manage their money. Today, our ambition and our footprint have grown.
Our ecosystem encompasses our pioneering, fully licensed UK bank (Starling), our global Software-as-a-Service technology platform (Engine by Starling), alongside a growing portfolio of specialist financial and software businesses.
While our roots are in the UK, our operations are expanding globally. Though you may be based in one of our international offices (such as Sydney or Toronto), this role is critical to the entire Starling Group. The work you do will support, empower, and protect our businesses worldwide.
Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and leveraging disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to enable you to make decisions regardless of your location or primary responsibilities; innovation and collaboration will be at the core of everything you do. Help is never far away in our open, borderless culture - you will find support in your team and from across the global business. We are in this together!
The way to thrive and shine within Starling is to be a self-driven individual and take full ownership of everything around you: from building, discovering, and solving complex problems, to sharing knowledge with your international colleagues to ensure all processes are efficient and productive. Our purpose across all our businesses is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.
Hybrid Working
We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of place of work in Sydney, so that we're able to interact and collaborate in person.
About the Role
To support our growth, we are looking for an experienced SOC Team Lead with Incident Response experience to join our growing cyber security function. This role will be supporting our 24/7 operational capabilities by providing coverage in working hours from Sydney and Toronto alongside our UK colleagues.
As a member of the Starling Group's SOC team, you will be working with the industry's brightest SecOps professionals to protect Starling Group's customers, assets, and systems using the latest technologies.
- Lead a team of subject matter experts and analysts to ensure Information Security is managed and continuously improved in line with Bank policy and procedure.
- Supporting the development and progression of the Information Security Analyst team from both a technical and professional perspective.
- Incident Triage, Response, and Investigations based on Alerts received from multiple sources which include:
- Cloud Infrastructure/Security.
- Endpoint Detection and Response.
- Perimeter detection tooling. - Conduct Quality Assurance for Triage case handling, mitigation actions and shift handover, collating lessons learned and implementing improvements where required.
- Interpret logs from a variety of sources (e.g. cloud, endpoint, network) to identify root cause and determine next steps for containment, eradication and recovery as part of incident response activities.
- Work together with other teams in the organisation to analyse, contain, eradicate and recover from cyber security incidents
- Continuous development and maintaining of incident handling, response and readiness processes.
- Support the wider SecOps team with detection engineering - creating and optimising analytic triggers to enhance alert efficacy - and threat hunting based on threat intelligence.
- Documentation of incidents and investigations, including analysis findings, containment steps and root cause.
- Plan and participate in Tabletop Exercises.
- Present investigation findings to technical and non-technical audiences.