Cyber Security Engineer (Hybrid in London

Cyber Security Engineer (Hybrid in London

London Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
Financial Times

At a Glance

  • Tasks: Enhance application security and collaborate with engineers on innovative security solutions.
  • Company: Join the Financial Times, a leading news organisation known for integrity and quality.
  • Benefits: Enjoy generous leave, medical cover, gym memberships, and community engagement opportunities.
  • Other info: Hybrid work model with a focus on collaboration and team cohesion.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technology and diverse teams.
  • Qualifications: Practical AppSec experience and familiarity with CI/CD security tools are essential.

The predicted salary is between 63000 - 77000 £ per year.

The Financial Times is one of the world’s leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to deliver quality information and services worldwide. Here, you’re given the chance to reach millions, create work that matters and deliver impartial journalism in a polarised world. In our warm, collaborative culture, you’ll connect with a diverse community of experts who support your growth, career aspirations and wellbeing.

We’re looking for a Cyber Security Engineer to help improve application security across the FT’s cloud-native technology estate. This is a hands-on role focused on making secure engineering easier for product, platform and software engineering teams.

You’ll help improve developer-friendly security guardrails across GitHub-based CI/CD pipelines, application repositories and engineering workflows. This includes working with SAST, software composition analysis, secret scanning, vulnerability management and secure coding guidance so that security findings are clear, actionable and owned by the right teams.

You’ll work closely with engineers to support practical threat modelling, triage application vulnerabilities, improve security playbooks and help teams remediate issues in a pragmatic way. You do not need to be a deep AWS or cloud security specialist, but some exposure to AWS, cloud security or infrastructure-as-code security would be useful.

We’re looking for someone with practical AppSec experience who wants to grow their impact - someone who enjoys working with engineers, improving tooling and helping security become part of normal delivery rather than a last-minute checkpoint.

  • Application security experience: practical experience identifying, explaining and helping remediate application security risks in modern engineering environments.
  • Developer-friendly security mindset: you enjoy working with engineers, explaining risks clearly and helping teams adopt secure practices without unnecessary friction.
  • CI/CD and code security awareness: familiarity with security tooling in development workflows, such as SAST, software composition analysis, secret scanning or repository security controls.
  • Automation mindset: ability to write scripts or small tools, ideally in Python, to reduce manual effort, improve visibility or make security workflows easier.
  • Some exposure to AWS, cloud security or infrastructure-as-code security would be useful, but is not essential.
  • Experience working with software engineers to explain and remediate security issues.
  • Familiarity with common web application security risks and secure coding practices.
  • Experience using or interpreting findings from tools such as SAST, software composition analysis, secret scanning or similar.
  • Ability to write scripts or small tools, ideally in Python, to automate tasks or improve visibility.
  • Familiarity with Agile or Scrum ways of working.
  • Exposure to AWS security, cloud security or infrastructure-as-code security.
  • Experience with bug bounty, penetration testing or security testing programmes.
  • Exposure to AI security, such as LLM-enabled applications, AI-assisted development workflows or prompt/data leakage risks.
  • Experience building dashboards, metrics or reports to support vulnerability management.
  • Relevant security certifications or training, such as AWS security training, secure coding training, GIAC, ISC2, CREST or equivalent practical experience.

These include generous annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships and opportunities to give back to the community. We currently operate a hybrid model which requires staff to work onsite 50% of the time, subject to role requirements & regular review. While flexible working requests will be considered, not all patterns are suitable for all roles. We believe this balanced approach supports flexibility and protects our culture, making collaboration and communication easier, building stronger relationships and team cohesion, and supporting peer learning.

We are a disability confident employer and Valuable 500 signatory. If you would like to discuss your requirements or have any questions, email talent@ft.com and a member of our team will be happy to help.

At the FT, we embrace innovation and the use of technology and appreciate that individuals may leverage AI tools as part of their job application process. Whilst we are happy for you to use AI to assist with your application, it is essential that all information provided is authentic and accurately represents your skills, experience, and qualifications. Candidates should be aware that the use of AI throughout the application process may be monitored to ensure a fair and transparent hiring process for all.

Cyber Security Engineer (Hybrid in London employer: Financial Times

The Financial Times is an exceptional employer, offering a dynamic and inclusive work environment where curiosity and ambition are celebrated. With opportunities for professional growth and a commitment to diversity, employees can thrive in a culture that values unique perspectives and fosters collaboration. The flexibility of remote or hybrid working arrangements from Belfast or London, combined with a comprehensive benefits package, makes the FT an attractive choice for those seeking meaningful and impactful careers in the legal field.

Financial Times

Contact Details:

Financial Times Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Security Engineer (Hybrid in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Financial Times, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Financial Times

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Financial Times. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Security Engineer (Hybrid in London

Application Security
CI/CD Security
SAST
Software Composition Analysis
Secret Scanning
Vulnerability Management
Secure Coding Practices

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Financial Times insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Financial Times that you’re committed to staying ahead in the game.

How to prepare for a job interview at Financial Times

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Financial Times to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Financial Times.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.