Business Information Security Officer (BISO) - Engine by Starling

Starling Bank
London
6 months ago
Applications closed

Related Jobs

View all jobs

Cyber Security Project Manager

Regional Information Security Officer

Information Security Officer

Information Security Officer

Senior Information Security Analyst

Information Security Officer

At Engine by Starling, we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses, on our technology. 

Engine is Starling's software-as-a-service (SaaS) business, the technology that was built to power Starling Bank, and two years ago we split out as a separate business. 

Starling Bank has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features, and efficient back-office processes that has helped achieve Starling's success.

We draw upon our experience as knowledgeable bankers, and best in class technologists to become the chosen option for these banks, and preferred partners for leading consultancies.

As a company, everyone is expected to roll up their sleeves to help deliver great outcomes for our clients. We are an engineering led company and we’re looking for someone who will be excited by the potential for Engine’s technology to transform banking in different markets around the world.

Hybrid Working

We have a Hybrid approach to working here at Engine - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. We don't like to mandate how much you visit the office and work from home, that's to be agreed upon between you and your manager. 

Sometravel(including international) may be necessary depending on the client and nature of the engagement.

About the Role

This role will shape our Security objectives, practices and associated policies and processes within Engine as well as lead the continuous improvement of our Information Security capabilities whilst managing a growing Information Security Team.

The successful candidate will act as the liaison between Engine and Starling Bank’s Information Security teams whilst also ensuring that they are the point of contact for all Information security related questions raised by Engine clients and our auditors.

We’re looking for a curious, versatile, adaptable and experienced information security or cyber specialist with executive presence and strong leadership skills who enjoys the challenge of a varied and collaborative role. 

You’ll enjoy problem solving, working with a wide variety of stakeholders, and enabling us to be creative in continuing to provide innovative products and services to support our clients, and stay at the forefront of all things Information Security.

What you'll get to do

Manage and maintain the Information Security Policy and Information Security Management System to ensure (i) it meets the needs of Engine, its clients, employees and other stakeholders and (ii) compliance with the relevant industry standards, regulatory and certification requirements such as ISO 27001. Oversee Engine’s Information Security governance documents (processes, standards and procedures) and optimise reporting of identified threats and vulnerabilities.  Oversee the process for obtaining and maintaining compliance certifications and accreditations including but not limited to ISO 27001, SOC 2 and PCI DSS/3DS through engagement with internal teams and our external auditors. Maintain the Information Security Risk Register; identifying, assessing and mitigating information security risks (including security risks related to third-parties and partners) and ensuring coherence with Engine’s Risk Management framework. Act as a point of contact for all Information Security related client queries and issues; providing expert opinion and communication during initial client conversations, RFPs, RFIs, delivery and throughout the client lifecycle. Act as an Information Security point of contact for Business Continuity Planning and Disaster Recovery; this includes responsibility for initiation and execution of cyber business impact analysis.  Advise the wider organisation on compliance and governance requirements. Oversee Incident Response related to Information Security and ensure coherence and collaboration with the broader Technology response capability. Liaise with external bodies and organisations to keep abreast of the threat landscape, emerging trends, technologies and legislation that have an impact on Information Security.  Assist as necessary to investigate security breaches and pursue associated disciplinary and legal matters.  Lead and manage a team of subject matter experts to ensure Information Security is managed effectively throughout the IT service delivery lifecycle, addressing client needs. Promote security awareness by collaborating with the relevant teams to provide training and awareness to the wider Engine organisation.

Requirements

Deep understanding and knowledge of cyber security principles, security standards and regulatory compliance and its application in a wide variety of organisations with a strong risk culture. Experience in a business facing security role, ideally in an Information Security Director, BISO, CISO or similar capacity Strong business acumen and commercial awareness with previous experience in a senior client-facing role or similar. Be a self starter / self motivated with the ability to lead, inspire and drive change through an organisation.  Have the ability to be pragmatic while balancing the needs of Engine against security. Ability to work with a variety of stakeholders across all levels and can adapt communication style to different stakeholders. Have an ability to think and plan strategically and systematically while recognising the need to deliver to the business requirements.  Have previous experience working in a complex IT organisation encompassing service delivery, application development and IT infrastructure. An understanding of best practice within Information Security and risk management including standards such as ISO 27001, NIST, Cyber Essentials and COBIT. An understanding of legislation and regulations that impact information Security. Data Protection Act and GDPR, Freedom of Information Act, PCI DSS. Have previous experience in leading, developing and motivating a team of subject matter experts.  An understanding of current and emerging threats and countermeasures and the organisational challenges to addressing these threats. A good practical knowledge of security technologies and wider business solutions including Identity and access management, SIEM, remote working and cloud technologies. Experience of working in a banking or financial services environment would be beneficial. ISC2 CISSP or ISACA CISM, ISACA CRISC, CISA or Open FAIR qualifications would be beneficial.

Interview process

Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

45 mins with the Chief Client Officer hours with the CTO and Deputy CTO 45 mins with the CEO and Chief of Staff

This role for applications will close on Mon 21st October.

Benefits

33 days holiday (including public holidays, which you can take when it works best for you) An extra day’s holiday for your birthday Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off 16 hours paid volunteering time a year Salary sacrifice, company enhanced pension scheme Life insurance at 4x your salary & group income protection Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton Generous family-friendly policies Incentives refer a friend scheme Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.

Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law. 

When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Engine by Starling and Starling Bank will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Contract vs Permanent Cybersecurity Jobs: Which Pays Better in 2025?

Cybersecurity has become one of the fastest-growing and most crucial fields in modern business. With high-profile breaches dominating headlines and the ongoing digital transformation exposing organisations to new threats, companies across the UK are competing to attract skilled cybersecurity professionals. Roles range from penetration testers (pen testers) and SOC (Security Operations Centre) analysts to compliance officers, cloud security architects, threat intelligence analysts, and CISOs (Chief Information Security Officers). As demand continues to surge, cybersecurity salaries have climbed accordingly, and businesses have turned to more flexible hiring practices. Alongside permanent employment, many professionals explore short-term day‑rate contracting or fixed-term contracts (FTCs), searching for the ideal balance of pay, job security, and growth opportunities. Which arrangement truly pays better in 2025—and which best aligns with your ambitions? In this article, we dive into the contract vs. permanent debate with a focus on cybersecurity roles. We will examine the current market, the structure of day‑rate vs. FTC vs. permanent positions, the pros and cons of each, and some hypothetical pay comparisons. By the end, you should have a clearer sense of which career path might suit your situation and goals—whether you are a seasoned specialist aiming for top rates, or an up-and-coming analyst seeking a stable environment to develop in.

Cyber Security Jobs for Non‑Technical Professionals: Where Do You Fit In?

Defence Needs More Than Hackers in Hoodies When headlines warn of ransomware crippling hospitals or deepfakes swaying elections, we picture hoodie‑clad hackers and elite penetration testers. Yet the reality of the UK’s cyber security sector is broader—and desperately short of talent. The Department for Science, Innovation & Technology (DSIT) estimates a shortfall of 11,200 cyber security professionals in 2024, while 43 % of advertised roles require governance, risk or communication skills rather than hands‑on technical exploits. Put plainly: if you can guide policy, manage projects, interpret regulations or inspire behaviour change, cyber security wants you. This guide highlights the fastest‑growing non‑technical roles, the transferable skills you already possess, and a concrete 90‑day plan to land a cyber security job—no packet sniffers required.

BAE Systems Cybersecurity Jobs in 2025: Your Complete UK Guide to Protecting Governments, Businesses and Critical Infrastructure

From securing the Royal Navy’s new Dreadnought submarines to foiling multimillion‑pound fraud rings, BAE Systems Digital Intelligence (DI)—formerly Detica—sits at the sharp end of global cyber defence. Head‑quartered in Guildford with hubs in Gloucester, Leeds and London, the 5,500‑strong DI business delivers threat‑intelligence platforms, secure‑by‑design software and 24/7 SOC services to government and commercial clients worldwide. With escalating ransomware, AI‑driven disinformation and complex supply‑chain threats, BAE plans to expand its UK cyber workforce by 20 % in 2025. Whether you’re a graduate passionate about reverse engineering, a DevSecOps engineer who loves IaC, or an incident‑response pro comfortable in high‑side environments, this guide explains how to land a BAE Systems cybersecurity job in 2025.