Senior Cyber Security Engineer
Summary
Senior security engineer at the Financial Times in Central London with a 50/50 application and cloud security focus: tuning SAST/SCA/secret-scanning guardrails in CI/CD, reducing AWS and IaC misconfigurations, driving vulnerability management and threat modelling, and building Python automation. Hybrid role requiring 50% onsite.
Salary: £62,000 - 88,000 per year
Requirements:- Strong practical experience in application security and cloud security, ideally with a balanced focus across both.
- Hands-on AWS security experience, including common misconfiguration patterns and practical remediation approaches.
- Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction.
- Experience in improving cloud or IaC misconfiguration management at scale in a developer-friendly way.
- Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning.
- Experience running practical threat-modelling sessions that influence design, delivery or remediation decisions.
- Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.
- Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping.
- Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment.
- Familiarity with Agile or Scrum ways of working.
- Experience with leveraging AI for AppSec and CloudSec is desirable.
- AWS Certified Security – Speciality or equivalent practical AWS security experience is desirable.
- Terraform or CloudFormation expertise is desirable.
- Incident-management or incident-response experience is desirable.
- Experience with Splunk or similar logging/SIEM platforms is desirable.
- Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction is desirable.
- Experience mentoring or line-managing security engineers is desirable.
- Improve application security guardrails by tuning and evolving SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams.
- Improve cloud and IaC security guardrails by helping identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale.
- Drive vulnerability management by improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated.
- Drive cloud misconfiguration management by helping teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows.
- Run practical threat modelling sessions for new products, features, services and architectural changes.
- Build automation and tooling by creating or improving scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand.
- Support secure architecture decisions by providing application and cloud security input into design reviews, AWS architecture decisions and larger technical changes.
- Partner with engineering teams to embed security into design, delivery and operational practices.
- Support incidents and lessons learned by providing application and cloud security expertise during incidents and feeding lessons learned back into patterns, tooling and guidance.
- Mentor others by coaching security engineers and engineering teams on practical security approaches, and potentially line-managing one or two security engineers depending on team structure.
- AI
- AWS
- CI/CD
- Cloud
- Support
- Python
- Security
- Splunk
- Terraform
- GitHub
More:
We are the Financial Times, one of the worlds leading news organisations, globally recognised for our authority, integrity and accuracy, with a mission to deliver quality information and services worldwide. Our culture is warm and collaborative, and we offer opportunities to grow, learn new skills and build a career with no fixed path. This Senior Cyber Security Engineer role focuses on maturing application and cloud security across our cloud-native, AWS-hosted technology estate, with a balanced 50/50 focus across application security and cloud security. We work closely with product, platform and engineering teams to make secure delivery easier by default. We offer best-in-class benefits that vary by location, including generous annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships and opportunities to give back to the community. We currently operate a hybrid model requiring staff to work onsite 50% of the time, subject to role requirements and regular review. We are committed to diversity, equity and inclusion, and we are a disability confident employer and Valuable 500 signatory.
last updated 36 week of 2026