Principal Security Programme Manager & Technical Lead - Engine by Starling

StarlingLondon, EnglandHybridFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

At Engine by Starling , we are on a mission to find and work with leading banks all around the world who have the ambition to build rapid growth businesses on our technology.

Engine is Starling's software-as-a-service (SaaS) business—the technology that was built to power Starling—and two years ago we split out as a separate business.

Starling has seen exceptional growth and success, and a large part of that is down to the fact that we have built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions all around the world, enabling them to benefit from the innovative digital features and efficient back-office processes that have helped achieve Starling's success.

As a company, everyone is expected to roll up their sleeves to help deliver great outcomes for our clients. We are an engineering-led company and we’re looking for people who will be excited by the potential for Engine’s technology to transform banking in different markets around the world. Our purpose is underpinned by five values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a Hybrid approach to working here at Engine - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person.

About the role

We are seeking a senior, highly adaptable Principal Security Programme Manager & Technical Lead to serve as a key technical partner to our Business Information Security Officer (BISO). In this high-visibility role, you will help shape, refine, and execute our strategic security roadmap as we rapidly scale our global fintech ecosystem.

You will bridge executive security vision with practical technical delivery—guiding core security initiatives that intersect with the CTO Office while collaborating daily with engineering, SecOps, threat and vulnerability management, and broader group functions. You will also champion secure innovation, ensuring our security posture keeps pace with emerging technologies like AI while embedding technical compliance across key financial standards.

This is a balanced role for a collaborative builder and strategist: you will be equally comfortable influencing engineering peers and designing future-state security controls as you are taking direct ownership to deliver technical milestones.

Responsibilities

- Roadmap Architecture & Scaling: Partner directly with the BISO to evaluate, refine, and drive the security roadmap, proactively proposing strategic updates to support rapid business growth.
- Cross-Functional Execution: Lead core security projects, aligning initiatives across the CTO Office, engineering leads, SecOps, and threat/vulnerability management.
- AI Security Readiness: Define and roll out practical security guardrails, risk assessments, and safe-use practices for AI/LLM adoption across engineering and business units.
- Compliance & Governance Alignment: Ensure technical security controls natively satisfy key regulatory frameworks—including ISO 27001, ISO42001, SOC 1/2, PCI DSS & 3DS, CSA C-STAR, and DORA.
- Pragmatic Technical Advisory: Translate high-level security requirements into actionable, practical guidance for engineering teams without creating delivery bottlenecks.
- Hands-on Delivery: Drive critical technical work streams directly when needed, taking full ownership of project milestones from inception through to operational handover.

Requirements

Knowledge & Technical Expertise

- Fintech or Scale-Up: Deep background in fintech security principles, regulatory demands, and scaling controls within fast-paced environments.
- AI Security & Innovation: Practical understanding of security considerations surrounding AI integration, data privacy, and model risk management.
- Frameworks & Compliance: Hands-on experience mapping technical controls to ISO 27001, ISO42001, SOC 1/2, PCI DSS & 3DS, CSA C-STAR, and DORA.
- Programme Delivery: Strong project and programme management skills, with a proven track record of bringing complex security initiatives to completion.
- Technical Breadth: Strong technical foundation across SecOps, threat & vulnerability management, and secure engineering.

Behaviours & Competencies

- Influence & Autonomy: Exceptional interpersonal and stakeholder management skills; highly self-directed and capable of building cross-functional consensus collaboratively.
- Strategic & Operational Flexibility: Ability to shift seamlessly between strategic planning and hands-on technical execution.
- Pragmatic Problem-Solving: A clear focus on enabling business growth and engineering velocity through balanced, practical security controls.

Preferred Qualifications

- Prior experience operating autonomously as an TPM or Technical Lead in a fast paced environment
- Experience with cloud security architectures.
- Industry certifications in security, privacy, or compliance (e.g., CISSP).

Interview Process

Interviewing is a two-way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general, following an initial chat with one of our Talent Team, you can expect:

- Technical Interview with BISO ~ 45 minutes
- Live Tech Test with DCTO ~ 90 minutes
- Final Interview with CTO ~ 60 minutes

Benefits

- 33 days holiday (including public holidays, which you can take when it works best for you)
- An extra day’s holiday for your birthday
- Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off
- 16 hours paid volunteering time a year
- Salary sacrifice, company enhanced pension scheme
- Life insurance at 4x your salary & group income protection
- Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr & Mrs Smith and Peloton
- Generous family-friendly policies
- Work from Abroad policy
- Incentives refer a friend scheme
- Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
- Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

About Us

You may be put off applying for a role because you don't tick every box. Forget that! While we can’t accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren’t sure if you're 100% there yet, get in touch anyway. We’re on a mission to radically reshape banking – and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.

Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.

When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that Engine by Starling and Starling will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, its retention period, and the rights you can exercise over our use of your personal information.