At a Glance
- Tasks: Enhance application and cloud security in a dynamic AWS environment.
- Company: Join a leading tech firm focused on innovative security solutions.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Other info: Collaborative culture with a focus on continuous improvement and innovation.
- Why this job: Make a real impact by shaping secure delivery practices and mentoring future security leaders.
- Qualifications: Experience in application and cloud security, with strong communication skills.
The predicted salary is between 60000 - 80000 € per year.
Requirements
- Application and cloud security experience: practical experience across both application security and cloud security, ideally in AWS-hosted, cloud-native environments.
- Developer-friendly security mindset: you know how to work with engineers, explain risk clearly and design controls that help teams move securely without unnecessary friction.
- Vulnerability management at scale: experience improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and advisories are identified, prioritised, owned and remediated across engineering teams.
- Cloud misconfiguration & vulnerability management: experience identifying and reducing infrastructure-as-code and AWS vulnerabilities & misconfigurations at scale through pragmatic guardrails, tooling and clear remediation paths.
- Threat modelling: confidence running lightweight, practical threat-modelling sessions that lead to useful engineering decisions and risk reduction.
- CI/CD and code security: hands-on experience with security tooling such as SAST, software composition analysis, secret scanning and IaC scanning.
- Automation mindset: ability to write scripts or small tools, ideally in Python, to reduce toil, improve visibility and surface meaningful risk.
- Security leadership: ability to mentor other security engineers and influence engineers across the wider organisation, potentially including line management.
- AI security awareness: experience of leveraging AI to improve and scale appsec and cloud sec controls would be useful, but is not essential.
- Strong practical experience: in application security and cloud security, ideally with a balanced focus across both.
- Hands-on AWS security experience: including common misconfiguration patterns and practical remediation approaches.
- Experience improving vulnerability management: across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction.
- Experience in improving cloud or IaC misconfiguration management: at scale in a developer-friendly way.
- Experience integrating, tuning or improving security tooling: in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning.
- Experience running practical threat-modelling sessions: that influence design, delivery or remediation decisions.
- Ability to write scripts or small tools: ideally in Python, to automate security workflows or improve visibility.
- Strong communication and collaboration skills: with the ability to influence engineers and technical leaders without relying on gatekeeping.
- Evidence of improving application security, cloud security or vulnerability management practices: in a real engineering environment.
- Familiarity with Agile or Scrum ways of working: (Desirable).
- Experience with leveraging AI for AppSec and CloudSec: (Desirable).
- AWS Certified Security – Speciality or equivalent practical AWS security experience: (Desirable).
- Terraform or CloudFormation expertise: (Desirable).
- Incident-management or incident-response experience: (Desirable).
- Experience with Splunk or similar logging/SIEM platforms: (Desirable).
- Experience with security metrics, dashboards or reporting: that helped drive measurable risk reduction (Desirable).
- Experience mentoring or line-managing security engineers.
What the job involves
We’re looking for a Senior Cyber Security Engineer to help mature application and cloud security across the FT’s cloud-native, AWS-hosted technology estate. This role has an approximate 50/50 focus across application security and cloud security, working closely with product, platform and engineering teams to make secure delivery easier by default. You’ll shape and improve developer-friendly guardrails across GitHub-based CI/CD pipelines, AWS environments and infrastructure-as-code workflows. This includes improving SAST, software composition analysis, secret scanning, IaC scanning, vulnerability management and AWS misconfiguration management so that findings are actionable, low-noise and owned by the right teams.
Day to day, you’ll run practical threat-modelling sessions, review application and cloud designs, improve security playbooks, support vulnerability and misconfiguration remediation, and build automation that reduces toil. We’re looking for someone who has demonstrably improved security outcomes in real engineering environments, not just someone with theoretical knowledge of tools or frameworks. Depending on team structure, you may also mentor or line-manage one or two security engineers, while remaining hands-on and close to the technical work.
Tune and evolve SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams. Help identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale. Improve how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated. Help teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows. Facilitate lightweight threat-modelling sessions for new products, features, services and architectural changes. Create or improve scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand. Provide application and cloud security input into design reviews, AWS architecture decisions and larger technical changes. Work closely with product, platform and software engineering teams to embed security into design, delivery and operational practices. Provide application and cloud security expertise during incidents and feed lessons learned back into patterns, tooling and guidance. Coach security engineers and engineering teams on practical security approaches. Depending on team structure, this may include line management of one or two security engineers.
Senior Cyber Engineer in London employer: Deepstreamtech
As a Senior Cyber Engineer at our company, you'll thrive in a dynamic and collaborative environment that prioritises innovation and security. We offer a supportive work culture that encourages professional growth through mentorship opportunities and hands-on experience with cutting-edge technologies in AWS-hosted, cloud-native settings. Our commitment to developer-friendly security practices ensures that you can make a meaningful impact while enjoying a balanced work-life integration.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Cyber Engineer in London
✨Tip Number 1
Network, network, network! Get out there and connect with folks in the industry. Attend meetups, webinars, or even local tech events. You never know who might be looking for someone with your skills!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to application and cloud security. This gives potential employers a taste of what you can do.
✨Tip Number 3
Prepare for interviews by brushing up on your technical knowledge and soft skills. Be ready to discuss your experience with AWS, vulnerability management, and threat modelling. Practice explaining complex concepts in simple terms.
✨Tip Number 4
Don’t forget to apply through our website! We’re always on the lookout for talented individuals like you. Plus, it’s a great way to ensure your application gets seen by the right people.
We think you need these skills to ace Senior Cyber Engineer in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in application and cloud security. We want to see how your skills align with the specific requirements of the Senior Cyber Engineer role.
Showcase Your Hands-On Experience:Don’t just list your skills; give us examples of how you've applied them in real-world scenarios. Whether it’s vulnerability management or threat modelling, we love seeing practical experience that demonstrates your impact.
Communicate Clearly:Use straightforward language to explain complex security concepts. Remember, we’re looking for someone who can bridge the gap between security and engineering teams, so clarity is key!
Apply Through Our Website:We encourage you to submit your application through our website. It’s the best way for us to keep track of your application and ensure it gets the attention it deserves!
How to prepare for a job interview at Deepstreamtech
✨Know Your Stuff
Make sure you brush up on your application and cloud security knowledge, especially in AWS environments. Be ready to discuss specific experiences where you've improved security outcomes or managed vulnerabilities at scale.
✨Speak Developer's Language
Since this role requires a developer-friendly security mindset, practice explaining complex security concepts in simple terms. Think about how you've collaborated with engineering teams in the past and be prepared to share those stories.
✨Showcase Your Automation Skills
Be ready to talk about any scripts or tools you've developed, particularly in Python, that have helped automate security workflows. Highlight how these contributions reduced manual effort and improved visibility for teams.
✨Prepare for Practical Scenarios
Expect to run through practical threat-modelling sessions during the interview. Familiarise yourself with common misconfigurations and vulnerabilities in AWS, and think about how you would approach identifying and remediating them in a real-world context.