Point your AI agent at freehire and let it find you a job.

Get the CLI →

The Financial Times

NewBe an early applicant

Senior Cyber Security Engineer

Posted Updated
Discussion

Summary

Senior security engineer at the Financial Times in Central London with a 50/50 application and cloud security focus: tuning SAST/SCA/secret-scanning guardrails in CI/CD, reducing AWS and IaC misconfigurations, driving vulnerability management and threat modelling, and building Python automation. Hybrid role requiring 50% onsite.

Salary: £62,000 - 88,000 per year

Requirements:
  • Strong practical experience in application security and cloud security, ideally with a balanced focus across both.
  • Hands-on AWS security experience, including common misconfiguration patterns and practical remediation approaches.
  • Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction.
  • Experience in improving cloud or IaC misconfiguration management at scale in a developer-friendly way.
  • Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning.
  • Experience running practical threat-modelling sessions that influence design, delivery or remediation decisions.
  • Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.
  • Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping.
  • Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment.
  • Familiarity with Agile or Scrum ways of working.
  • Experience with leveraging AI for AppSec and CloudSec is desirable.
  • AWS Certified Security – Speciality or equivalent practical AWS security experience is desirable.
  • Terraform or CloudFormation expertise is desirable.
  • Incident-management or incident-response experience is desirable.
  • Experience with Splunk or similar logging/SIEM platforms is desirable.
  • Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction is desirable.
  • Experience mentoring or line-managing security engineers is desirable.
Responsibilities:
  • Improve application security guardrails by tuning and evolving SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams.
  • Improve cloud and IaC security guardrails by helping identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale.
  • Drive vulnerability management by improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated.
  • Drive cloud misconfiguration management by helping teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows.
  • Run practical threat modelling sessions for new products, features, services and architectural changes.
  • Build automation and tooling by creating or improving scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand.
  • Support secure architecture decisions by providing application and cloud security input into design reviews, AWS architecture decisions and larger technical changes.
  • Partner with engineering teams to embed security into design, delivery and operational practices.
  • Support incidents and lessons learned by providing application and cloud security expertise during incidents and feeding lessons learned back into patterns, tooling and guidance.
  • Mentor others by coaching security engineers and engineering teams on practical security approaches, and potentially line-managing one or two security engineers depending on team structure.
Technologies:
  • AI
  • AWS
  • CI/CD
  • Cloud
  • Support
  • Python
  • Security
  • Splunk
  • Terraform
  • GitHub

More:

We are the Financial Times, one of the worlds leading news organisations, globally recognised for our authority, integrity and accuracy, with a mission to deliver quality information and services worldwide. Our culture is warm and collaborative, and we offer opportunities to grow, learn new skills and build a career with no fixed path. This Senior Cyber Security Engineer role focuses on maturing application and cloud security across our cloud-native, AWS-hosted technology estate, with a balanced 50/50 focus across application security and cloud security. We work closely with product, platform and engineering teams to make secure delivery easier by default. We offer best-in-class benefits that vary by location, including generous annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships and opportunities to give back to the community. We currently operate a hybrid model requiring staff to work onsite 50% of the time, subject to role requirements and regular review. We are committed to diversity, equity and inclusion, and we are a disability confident employer and Valuable 500 signatory.

last updated 36 week of 2026

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available