Skip to Main Content
Location icon
London

Cyber Security Engineer

Financial Times
Office & Professional
Office & Professional
Negotiable
Company logo image
Description

Location
London

Hours
Full Time - Hybrid model with 50% onsite work, subject to role requirements and regular review

Salary
Competitive salary, details provided upon application

About the Role
The Financial Times is a globally recognised news organisation known for its authority, integrity and accuracy. We are seeking a Cyber Security Engineer to enhance application security across our cloud-native technology estate. This hands-on role focuses on making secure engineering easier for product, platform and software engineering teams. You will work to improve developer-friendly security guardrails across GitHub-based CI/CD pipelines, application repositories and engineering workflows. Key responsibilities include working with SAST, software composition analysis, secret scanning, vulnerability management and secure coding guidance to ensure security findings are clear, actionable and owned by the right teams. You will collaborate closely with engineers to support practical threat modelling, triage application vulnerabilities, improve security playbooks and help teams remediate issues pragmatically. While deep AWS or cloud security expertise is not required, some exposure to AWS, cloud security or infrastructure-as-code security is beneficial. This role is ideal for someone with practical application security experience who enjoys working with engineers, improving tooling and embedding security into normal delivery processes rather than as a last-minute checkpoint.

Our Commitment to Diversity, Equity and Inclusion
We value unique perspectives and strive to create a workplace where all voices are heard, respected and valued. We are committed to removing barriers for everyone, with a focus on underrepresented groups, fostering a supportive environment where employees can be themselves and reach their full potential.

Benefits
We offer best-in-class perks including generous annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships and community engagement opportunities. Our hybrid working model supports flexibility while maintaining strong collaboration and team cohesion. We are a disability confident employer and provide reasonable adjustments to support all applicants and employees.

Requirements

Experience
- Practical experience in application security, including identifying, explaining and helping remediate security risks in modern engineering environments
- Experience working with software engineers to explain and remediate security issues
- Familiarity with common web application security risks and secure coding practices
- Experience with vulnerability triage, prioritisation and remediation tracking
- Experience using or interpreting findings from tools such as SAST, software composition analysis, secret scanning or similar
- Experience participating in or supporting threat-modelling activities
- Ability to write scripts or small tools, ideally in Python, to automate tasks or improve visibility
- Strong communication and collaboration skills
- Familiarity with Agile or Scrum ways of working

About you
- Developer-friendly security mindset, enjoying working with engineers and helping teams adopt secure practices without unnecessary friction
- Automation mindset with ability to reduce manual effort and improve security workflows
- Growth mindset with willingness to develop skills across application security, cloud security, secure development and modern engineering practices

Qualifications
- Exposure to AWS security, cloud security or infrastructure-as-code security is desirable but not essential
- Experience with Terraform or CloudFormation, container or Kubernetes security, bug bounty, penetration testing or security testing programmes is advantageous
- Experience with Splunk or similar logging/SIEM platforms
- Exposure to AI security, such as LLM-enabled applications, AI-assisted development workflows or prompt/data leakage risks is a plus
- Experience building dashboards, metrics or reports to support vulnerability management
- Relevant security certifications or training such as AWS security training, secure coding training, GIAC, ISC2, CREST or equivalent practical experience are beneficial

Expiry date: 27/08/2026
Cyber Security Engineer
Company:
Financial Times
Job Type:
Full-time
Location:
London