Skip to Main Content
Location icon
London

Senior Cyber Security Engineer

Financial Times
Office & Professional
Office & Professional
Negotiable
Company logo image
Description

Location
London

Hours
Full Time

Salary
Negotiable

About the Role
The Financial Times is one of the world’s leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to deliver quality information and services worldwide. At the FT, curiosity thrives and ambitious thinking is rewarded. You will have the chance to reach millions, create work that matters and deliver impartial journalism in a polarised world. In a warm, collaborative culture, you’ll connect with a diverse community of experts who support your growth, career aspirations and wellbeing. Your future at the FT will be filled with opportunities that challenge and inspire you, allowing you to discover new skills and forge a career that can take you anywhere.

We are looking for a Senior Cyber Security Engineer to help mature application and cloud security across the FT’s cloud-native, AWS-hosted technology estate. This role has an approximate 50/50 focus across application security and cloud security, working closely with product, platform and engineering teams to make secure delivery easier by default. You will shape and improve developer-friendly guardrails across GitHub-based CI/CD pipelines, AWS environments and infrastructure-as-code workflows. This includes improving SAST, software composition analysis, secret scanning, IaC scanning, vulnerability management and AWS misconfiguration management so that findings are actionable, low-noise and owned by the right teams.

Day to day, you will run practical threat-modelling sessions, review application and cloud designs, improve security playbooks, support vulnerability and misconfiguration remediation, and build automation that reduces toil. You will be someone who has demonstrably improved security outcomes in real engineering environments, not just theoretical knowledge of tools or frameworks. Depending on team structure, you may also mentor or line-manage one or two security engineers, while remaining hands-on and close to the technical work.

Our Commitment to Diversity, Equity and Inclusion
We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued. A supportive workplace is one where employees feel they can be themselves and operate to their full potential. We are committed to removing barriers for everyone, with a focus on addressing those faced by underrepresented groups.

Working Model
We currently operate a hybrid model which requires staff to work onsite 50% of the time, subject to role requirements and regular review. While flexible working requests will be considered, not all patterns are suitable for all roles. This balanced approach supports flexibility and protects our culture, making collaboration and communication easier, building stronger relationships and team cohesion, and supporting peer learning.

Accessibility
We are a disability confident employer and Valuable 500 signatory. Reasonable adjustments can be made to support candidates throughout the application process and interview.

Requirements

Experience
- Strong practical experience in application security and cloud security, ideally with a balanced focus across both.
- Hands-on AWS security experience, including common misconfiguration patterns and practical remediation approaches.
- Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction.
- Experience in improving cloud or infrastructure-as-code misconfiguration management at scale in a developer-friendly way.
- Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning.
- Experience running practical threat-modelling sessions that influence design, delivery or remediation decisions.
- Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.
- Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping.
- Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment.
- Familiarity with Agile or Scrum ways of working.

About you
You are a pragmatic security professional with a developer-friendly mindset who understands how to work collaboratively with engineering teams to embed security without creating unnecessary friction. You are hands-on, able to mentor others, and comfortable influencing across multiple teams and levels of seniority. You have a passion for automation and continuous improvement, and you thrive in dynamic, cloud-native environments.

Qualifications
- While formal certifications are not mandatory, AWS Certified Security – Specialty or equivalent practical AWS security experience is desirable.
- Experience with Terraform or CloudFormation is advantageous.
- Incident-management or incident-response experience is beneficial.
- Experience with Splunk or similar logging/SIEM platforms is a plus.
- Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction is desirable.
- Experience mentoring or line-managing security engineers is a plus.
- Awareness or experience leveraging AI to improve and scale application and cloud security controls is useful but not essential.

Expiry date: 07/10/2026
Senior Cyber Security Engineer
Company:
Financial Times
Job Type:
Full-time
Location:
London