Location
London
Hours
Hybrid model with 50% onsite work, subject to role requirements and regular review. Flexible working requests considered.
Salary
Negotiable
About the Role
The Financial Times is a globally recognised news organisation known for its authority, integrity and accuracy. We are seeking a hands-on Application Security Engineer to enhance application security across our cloud-native technology estate. This role focuses on making secure engineering easier for product, platform and software engineering teams by improving developer-friendly security guardrails across GitHub-based CI/CD pipelines, application repositories and engineering workflows. You will work with SAST, software composition analysis, secret scanning, vulnerability management and secure coding guidance to ensure security findings are clear, actionable and owned by the right teams. Collaborating closely with engineers, you will support practical threat modelling, triage application vulnerabilities, improve security playbooks and help teams remediate issues pragmatically. While deep AWS or cloud security expertise is not required, some exposure to AWS, cloud security or infrastructure-as-code security is beneficial. This role is ideal for someone with practical application security experience who enjoys working with engineers, improving tooling and integrating security into normal delivery processes rather than as a last-minute checkpoint.
Experience
- Practical application security experience identifying, explaining and helping remediate security risks in modern engineering environments
- Experience working with software engineers to explain and remediate security issues
- Familiarity with common web application security risks and secure coding practices
- Experience with vulnerability triage, prioritisation and remediation tracking
- Experience using or interpreting findings from tools such as SAST, software composition analysis, secret scanning or similar
- Experience participating in or supporting threat-modelling activities
- Ability to write scripts or small tools, ideally in Python, to automate tasks or improve visibility
- Strong communication and collaboration skills
- Familiarity with Agile or Scrum methodologies
About you
- Developer-friendly security mindset with the ability to explain risks clearly and help teams adopt secure practices without unnecessary friction
- Automation mindset with a willingness to reduce manual effort and improve security workflows
- Growth mindset with eagerness to develop skills in application security, cloud security, secure development and modern engineering practices
Qualifications
- Desirable: Exposure to AWS security, cloud security or infrastructure-as-code security
- Desirable: Experience with Terraform, CloudFormation, container or Kubernetes security
- Desirable: Experience with bug bounty, penetration testing or security testing programmes
- Desirable: Experience with Splunk or similar logging/SIEM platforms
- Desirable: Exposure to AI security including LLM-enabled applications, AI-assisted development workflows or prompt/data leakage risks
- Desirable: Experience building dashboards, metrics or reports to support vulnerability management
- Relevant security certifications or training such as AWS security training, secure coding training, GIAC, ISC2, CREST or equivalent practical experience
Financial Times










