Staff Infrastructure Engineer (GCP) - Engine by Starling
Starling Bank
As a Staff Infrastructure Engineer, you design, build and operate scalable, cloud-native infrastructure on GCP across regions, enabling Engine’s banking platform to run reliably and securely. You will lead complex infrastructure programs, shape platform capabilities and standards, and promote automation and security-by-design across the team. You’ll work closely with cross-functional groups to deliver observable, cost-efficient systems that support rapid feature delivery for customers. This role offers meaningful impact at scale in a fast-paced, collaborative fintech environment.
Pay / Benefits- 33 days holiday
- Birthday extra day
- Pension scheme
- Private Medical Insurance with VitalityHealth
- Cycle to Work
- Wellbeing and family-friendly policies
- Design, document, build and maintain scalable infrastructure on GCP
- Ensure performance, reliability and cost-effectiveness of cloud environments
- Automate processes and minimize manual work
- Build security-by-design into platform foundations and ensure compliance with ISO 27001, SOC 2, PCI DSS and 3DS
- Design and operate key and secret management on GCP (Cloud KMS, EKM, Secret Manager) including cryptographic key ceremonies
- Diagnose and fix infrastructure issues rapidly while maintaining security and performance
- Create clear technical documentation and lead team training sessions
- Keep abreast of new technologies and industry changes
- Lead complex infrastructure projects from inception to production, shaping Engine’s future tooling and architecture
- Lead by example, setting a high technical bar for the team
- GCP multi-region disaster recovery experience
- Experience bootstrapping Google Cloud Organizations and IAM
- Experience with GCP services: GKE, Compute Engine, Network Connectivity Center, Cloud SQL, IAM, VPC Service Controls
- Terraform code experience
- Experience with containers, distributed systems and immutable infrastructure
- Key and secret management on GCP (KMS, EKM, Secret Manager) including cryptographic ceremonies
- Hybrid connectivity design between GCP and on-premise locations (NCC, Cloud VPN, Interconnect)
- Workload Identity and Workload Identity Federation
- Observability tooling (Cloud Monitoring, Cloud Logging, Cloud Trace, Prometheus, OpenTelemetry, Grafana)
- Google Workspace / Google Cloud Identity
- Scripting in Python or Go
- CI/CD pipeline experience
- RESTful API and event-driven concepts
- RFCs and ADRs with runbooks in Production
- ownership
- problem solving
- strong communication
- GCP (multi-region, disaster recovery)
- GKE and Compute Engine
- Cloud SQL
Reference: WJ-747_30159259