# Junior Information Security Analyst (GRC) - Engine by Starling

[Starling Bank](https://www.jorb.ai/firms/starling-bank.md) · London · United Kingdom

Starling Bank is hiring a Junior Information Security Analyst (GRC) - Engine by Starling in London. Posted 2026-09-01; applications close 2026-10-31.

**Apply**: https://apply.workable.com/starling-bank/j/B465795049

Posted 4d ago.

## Role details

## About Engine by Starling

At Engine by Starling, we are on a mission to find and work with leading banks around the world that are ambitious to build rapid growth businesses using our technology.

Engine is Starling’s software-as-a-service (SaaS) business—the technology built to power Starling. Two years ago, we split it out as a separate business. Starling has seen exceptional growth and success, largely because we built our own modern technology from the ground up. This SaaS technology platform is now available to banks and financial institutions worldwide, enabling them to benefit from innovative digital features and efficient back-office processes.

We’re an engineering-led company where everyone is expected to roll up their sleeves to deliver great outcomes for our clients. Our purpose is underpinned by five values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

## Hybrid Working

We have a hybrid approach. Our preference is that you’re located within a commutable distance of one of our offices so we can interact and collaborate in person.

## About the Role

In this role, you will help maintain and mature our governance, risk, and compliance (GRC) program. You’ll play a key part in ensuring our ongoing adherence to security standards and regulations, building trust for our clients and stakeholders. This is a hands-on role, ideally suited to someone who can engage with stakeholders across our business.

## What You’ll Get to Do

  
- **Compliance Management:** Learn and support the day-to-day management of our compliance programs, with a primary focus on ISO 27001, SOC 1, SOC 2, CSTAR, and PCI DSS/3DS.
  
- **Audit Support:** Act as a liaison for internal and external auditors—gather evidence, prepare for audits, and track timely remediation of findings.
  
- **Risk Management:** Participate in our risk assessment process by identifying, analysing, and documenting information security risks. Assist in developing and monitoring risk treatment plans.
  
- **Policy & Procedure Maintenance:** Help develop, update, and maintain information security policies, standards, and procedures so they remain current, accurate, and aligned with compliance requirements.
  
- **Evidence Collection & Review:** Streamline evidence collection for compliance frameworks to ensure audit readiness.
  
- **Cross-Functional Collaboration:** Work closely with Engineering, Product, and Security Operations teams to embed security controls into processes and culture.
  
- **Continuous Improvement:** Identify opportunities to improve the effectiveness and efficiency of our GRC program and related processes.
  
- **Security Awareness:** Assist in delivering and improving our security awareness training for all employees.
  
- **Third-Party Risk Assessments:** Support end-to-end vendor management by evaluating the security posture of prospective and current vendors to ensure they meet Engine’s security and compliance standards.

## Requirements

  
- A minimum of 1 year of experience in an information security role.
  
- Proven experience supporting and managing compliance efforts.
  
- Strong skills in security metrics and reporting.
  
- Experience with audit processes and evidence collection.
  
- A proactive, organised, and detail-oriented approach to your work.
  
- Experience with GRC software is a plus.

## Desired Qualifications (If You Have Some of These)

  
- Foundational certificates in IT Risk or Audit.
  
- ISC2 Certified in Cybersecurity (CC).
  
- ISO 27001 Foundation training.

## Interview Process

Interviews are conversational. In general, following a chat with one of our Talent Team members, you can expect:

  
- **Stage 1:** 45 minutes with team members
  
- **Stage 2:** 60 minutes with team members
  
- **Stage 3:** Final stage with BISO

## Benefits

  
- 33 days holiday (including public holidays), which you can take when it works best for you.
  
- An extra day’s holiday for your birthday.
  
- Annual leave increases with length of service, and you can buy or sell up to five extra days off.
  
- 16 hours paid volunteering time a year.
  
- Salary sacrifice and a company enhanced pension scheme.
  
- Life insurance at 4x your salary and group income protection.
  
- Private Medical Insurance with VitalityHealth, including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith, and Peloton.
  
- Generous family-friendly policies.
  
- Incentives refer a friend scheme.
  
- Perkbox membership with access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks.
  
- Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships, and Electric Vehicle (EV) leasing.

## About Us

You may be put off applying because you don’t tick every box—forget that. While we can’t accommodate every flexible working request, we’re always open to discussion. If you’re excited about working with us but aren’t sure if you’re 100% there yet, get in touch anyway.

We’re on a mission to radically reshape banking—and that starts with our brilliant team. Whatever came before, we’re proud to bring together people of all backgrounds and experiences who love working together to solve problems.

Engine by Starling is an equal opportunity employer, and we’re proud of our ongoing efforts to foster diversity and inclusion in the workplace. Individuals seeking employment at Engine by Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.

## Applying to this role

This Junior Information Security Analyst (GRC) - Engine by Starling role at Starling Bank runs through the firm's own careers portal and expects a CV and cover letter written specifically for the posting, not a portable submission carried across firms. Jorb AI's application agent tailors a CV and cover letter from your background to this posting and tracks the role alongside the rest of your applications.

[Tailor this application](https://www.jorb.ai/signup?ref=job-atom&firm=starling-bank&job=6a972f0fadb2a993174426ea)

## More open roles at Starling Bank

- [Junior Technical Project Manager - Engine by Starling](https://www.jorb.ai/jobs/6a98107f91da1953b239807c.md) – London, posted 8d ago
- [Reconciliation Specialist (12 month FTC)](https://www.jorb.ai/jobs/6a7f038e2845f753f77731e6.md) – London, posted 22d ago

---

Updated: 2026-09-05
Canonical: https://www.jorb.ai/jobs/6a972f0fadb2a993174426ea
