Senior Infrastructure Engineer (GCP) - Engine by Starling
Starling Bank
Overview
In this role you design, build and run scalable, secure cloud foundations for Engine’s cloud-native banking platform across regions and providers. You will drive reliability, security by design, and cost-aware operations while enabling rapid feature delivery in a collaborative, high-ownership culture. You’ll lead complex infrastructure initiatives and share knowledge to raise the engineering bar. This is an opportunity to shape the platform that powers banking innovation at scale.
Pay / Benefits- 33 days holiday (including public holidays)
- Birthday day off
- Pension scheme
- Private Medical Insurance with VitalityHealth
- Life insurance 4x salary
- Partner discounts (Waitrose, Mr & Smith, Peloton)
- Design, document, and maintain scalable infrastructure on GCP across regions
- Ensure performance, reliability and cost-effectiveness of cloud environments
- Automate processes and minimize manual work
- Build security-by-design foundations and ensure platform compliance with ISO 27001, SOC 2, PCI DSS, 3DS
- Design and operate key/secret management on GCP (Cloud KMS, EKM, Secret Manager) including cryptographic ceremonies
- Diagnose and resolve infrastructure issues with a focus on security and performance
- Write technical documentation and host team training sessions
- Stay current with new technologies and industry changes
- Lead complex infrastructure projects from inception to run, shaping tooling, automation, and architecture
- Lead by example, setting high technical standards for the team
- Proven GCP multi-region disaster recovery experience
- Experience bootstrapping Google Cloud Organisations and hardening enterprise resources
- GCP services: GKE, Compute Engine, Network Connectivity Center, Cloud SQL, IAM, VPC Service Controls
- Terraform coding experience
- Experience with containers, distributed systems and immutable infrastructure
- Experience with key/secret management on GCP (KMS, EKM, Secret Manager) including key ceremonies
- Hybrid connectivity design from GCP to on-premise HSMs using NCC, Cloud VPN, Interconnect
- Workload Identity and Workload Identity Federation for authentication
- Observability tooling: Cloud Monitoring, Cloud Logging, Cloud Trace, Managed Service for Prometheus, OpenTelemetry, Grafana
- Google Workspace / Google Cloud Identity setup
- Automation scripting (Python or Go)
- CI/CD implementation
- RESTful API and event-driven concepts
- RFCs and ADRs for design-to-production documentation and runbooks
- Ideally: Zero Trust security (mTLS, SSO) and AWS experience
- Golang/Java/Python development familiarity
- Networking concepts and GCP-on-prem connectivity knowledge
- Self-driven and proactive
- Strong problem-solving mindset
- Collaborative and able to mentor others
- GCP multi-region architecture
- Terraform
- Kubernetes (GKE)
Reference: WJ-747_30169703