National AI Awards 2025Discover AI's trailblazers! Join us to celebrate innovation and nominate industry leaders.

Nominate & Attend

Technology Risk Analyst

Starling Bank
Manchester
7 months ago
Applications closed

Related Jobs

View all jobs

Application Support - Elite 3E, InTapp - London,Bank Stn

Application Analyst - Tech, Data and AI - London EC

Data Scientist - Home Pricing

Data Scientist - Home Pricing

Senior Data Engineer

Applications Architect

Hello, we’re Starling. We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way. We’re a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company. We’re a bank, but better: fairer, easier to use and designed to demystify money for everyone. We employ more than 3,000 people across our London, Southampton, Cardiff and Manchester offices. 

Role purpose

  • The Technology Risk Analyst will support and report directly into the Head of Information Security Risk but will have exposure across the Bank to the management of Starling’s technology risks.
  • The role holder will perform oversight, challenge and assurance of the performance, security and operational resilience of Starling Bank, our technology, people and processes.

About the role

  • Provide technical oversight of technology (cyber security, software engineering, and data management), ensuring risks are identified, managed and escalated appropriately.
  • Provide guidance on risk identification and control design for key emerging areas such as artificial intelligence 
  • Assure the operational and cyber resilience of Starling Bank’s technology operation by all techniques from inspection, interview to direct testing and scripted checks.
  • Provide sound evaluation of issues, incidents and vulnerabilities and technology opinion to the risk department as a whole.
  • Challenge potential flaws or weaknesses in process, architecture or systems, both directly with first line staff and indirectly via review process.
  • Work with first line to improve controls and risk management in-line with strategic objectives, regulatory requirements and evolving threat landscape.
  • Establish strong relationships with our engineers, data scientists, cyber security team, and leadership.

Requirements

You will have the ability to apply a risk-based approach to challenge the first line across security domains, and have expertise in several of the following areas:

  • Experience within a regulated industry such as financial services or similarly regulated sectors.
  • Ability to assess and test technology control effectiveness through the lifecycle from design to implementation and monitoring.
  • Background conducting assurance or audit on application/system risk assessments, a bonus if this includes machine learning and artificial intelligence systems.
  • Experience with cloud architecture, threat modelling, simulation exercises and risk assessments.
  • Past experience working in a Technology Risk & Control function preferably focused on emerging technology
  • Have been involved in designing and developing Technology controls including Information Security, Systems Management, Third party, and Data Privacy.
  • Working knowledge of key technology related frameworks and international standards, such as ISO 2700x, NIST CSF, NIST AI RMF, COBIT and PCI-DSS.
  • Engaging directly with engineers, reviewing source code and testing approaches as part of CICD pipelines.
  • Ability to understand and evaluate findings from penetration testing, vulnerability and configuration scanning tools, and auditing patch management.
  • Knowledge of assessing controls in the context of cloud environments, containerisation, microservices, and infrastructure-as-code.
  • Good interpersonal skills with ability to challenge in a positive manner and handle difficult situations. 
  • Be self motivated, enjoy problem solving and want to continue to learn and develop.

 

Benefits

  • 25 days holiday (plus take your public holiday allowance whenever works best for you)
  • An extra day’s holiday for your birthday
  • Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
  • 16 hours paid volunteering time a year
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary & group income protection
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Incentivised refer a friend scheme
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

About Us

You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway.

We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.

Starling Bank is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling Bank are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.

By submitting your application, you agree that Starling Bank may collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we may process, where we may process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.

National AI Awards 2025

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

10 AI Recruitment Agencies in the UK You Should Know (2025 Job‑Seeker Guide)

Generative‑AI hype has translated into real hiring: Lightcast recorded +57 % year‑on‑year growth in UK adverts mentioning “machine learning”, “LLM” or “gen‑AI” during Q1 2025. Yet supply still lags. Roughly 18,000 core AI professionals work in the UK, but monthly live vacancies hover around 1,400–1,600. That mismatch makes specialist recruiters invaluable—opening stealth vacancies, advising on salary bands and fast‑tracking interview loops. But many tech agencies sprinkle “AI” on their website without an active desk. To save you time, we vetted 50 + consultancies and kept only those with: A registered UK head office (verified via Companies House). A named AI/Machine‑Learning or Data practice.

AI Jobs Skills Radar 2026: Emerging Frameworks, Languages & Tools to Learn Now

As the UK’s AI sector accelerates towards a £1 trillion tech economy, the job landscape is rapidly evolving. Whether you’re an aspiring AI engineer, a machine learning specialist, or a data-driven software developer, staying ahead of the curve means more than just brushing up on Python. You’ll need to master a new generation of frameworks, languages, and tools shaping the future of artificial intelligence. Welcome to the AI Jobs Skills Radar 2026—your definitive guide to the emerging AI tech stack that employers will be looking for in the next 12–24 months. Updated annually for accuracy and relevance, this guide breaks down the top tools, frameworks, platforms, and programming languages powering the UK’s most in-demand AI careers.

How to Find Hidden AI Jobs in the UK Using Professional Bodies like BCS, IET & the Turing Society

Stop Scrolling Job Boards and Start Tapping the Real AI Market Every week a new headline announces millions of pounds flowing into artificial-intelligence research, defence initiatives, or health-tech pilots. Read the news and you could be forgiven for thinking that AI vacancies must be everywhere—just grab your laptop, open LinkedIn, and pick a role. Yet anyone who has hunted seriously for an AI job in the United Kingdom knows the truth is messier. A large percentage of worthwhile AI positions—especially specialist or senior posts—never appear on public boards. They emerge inside university–industry consortia, defence labs, NHS data-science teams, climate-tech start-ups, and venture studios. Most are filled through referral or conversation long before a recruiter drafts a formal advert. If you wait for a vacancy link, you are already at the back of the queue. The surest way to beat that dynamic is to embed yourself in the professional bodies and grassroots communities where the work is conceived. The UK has a dense network of such organisations: the Chartered Institute for IT (BCS); the Institution of Engineering and Technology (IET) with its Artificial Intelligence Technical Network; the Alan Turing Institute and its student-driven Turing Society; the Royal Statistical Society (RSS); the Institution of Mechanical Engineers (IMechE) and its Mechatronics, Informatics & Control Group; public-funding engines like UK Research and Innovation (UKRI); and an ecosystem of Slack channels and Meetup groups that trade genuine, timely intel. This article is a practical, step-by-step guide to using those networks. You will learn: Why professional bodies matter more than algorithmic job boards Exactly which special-interest groups (SIGs) and technical networks to join How to turn CPD events into informal interviews How to monitor grant databases so you hear about posts months before they exist Concrete scripts, portfolio tactics, and outreach rhythms that convert visibility into offers Follow the playbook and you move from passive applicant to insider—the colleague who hears about a role before it is written down.