Senior Cyber Engineer

Senior Cyber Engineer

Full-Time 60000 - 80000 ÂŁ / year (est.) Home office (partial)
The Financial Times Ltd

At a Glance

  • Tasks: Enhance application and cloud security while collaborating with diverse teams.
  • Company: Join the Financial Times, a leading news organisation known for integrity and innovation.
  • Benefits: Enjoy generous leave, medical cover, gym memberships, and a flexible hybrid working model.
  • Other info: Embrace a culture of curiosity and growth with opportunities to mentor and lead.
  • Why this job: Make a real impact in cybersecurity while shaping your career in a supportive environment.
  • Qualifications: Proven experience in application and cloud security, especially in AWS environments.

The predicted salary is between 60000 - 80000 ÂŁ per year.

The Financial Times is one of the world’s leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to deliver quality information and services worldwide. At the FT, curiosity thrives and ambitious thinking is rewarded. Here, you’re given the chance to reach millions, create work that matters and deliver impartial journalism in a polarised world. In our warm, collaborative culture, you’ll connect with a diverse community of experts who support your growth, career aspirations and wellbeing. Your future at the FT will be filled with opportunities that challenge and inspire you. With no fixed path, you’ll discover new skills and forge a career that can take you anywhere.

Our Commitment to Diversity, Equity and Inclusion

We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued. A supportive workplace is one where employees feel they can be themselves and operate to their full potential. We are committed to removing barriers for everyone, with a focus on addressing those faced by underrepresented groups.

The Role Overview

We’re looking for a Senior Cyber Security Engineer to help mature application and cloud security across the FT’s cloud-native, AWS-hosted technology estate. This role has an approximate 50/50 focus across application security and cloud security, working closely with product, platform and engineering teams to make secure delivery easier by default. You’ll shape and improve developer‑friendly guardrails across GitHub‑based CI/CD pipelines, AWS environments and infrastructure‑as‑code workflows. This includes improving SAST, software composition analysis, secret scanning, IaC scanning, vulnerability management and AWS misconfiguration management so that findings are actionable, low‑noise and owned by the right teams. Day to day, you’ll run practical threat‑modelling sessions, review application and cloud designs, improve security playbooks, support vulnerability and misconfiguration remediation, and build automation that reduces toil. We’re looking for someone who has demonstrably improved security outcomes in real engineering environments, not just someone with theoretical knowledge of tools or frameworks. Depending on team structure, you may also mentor or line‑manage one or two security engineers, while remaining hands‑on and close to the technical work.

What you’ll bring to the role

  • Application and cloud security experience: practical experience across both application security and cloud security, ideally in AWS‑hosted, cloud‑native environments.
  • Developer‑friendly security mindset: you know how to work with engineers, explain risk clearly and design controls that help teams move securely without unnecessary friction.
  • Vulnerability management at scale: experience improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and advisories are identified, prioritised, owned and remediated across engineering teams.
  • Cloud misconfiguration & vulnerability management: experience identifying and reducing infrastructure‑as‑code and AWS vulnerabilities & misconfigurations at scale through pragmatic guardrails, tooling and clear remediation paths.
  • Threat modelling: confidence running lightweight, practical threat‑modelling sessions that lead to useful engineering decisions and risk reduction.
  • CI/CD and code security: hands‑on experience with security tooling such as SAST, software composition analysis, secret scanning and IaC scanning.
  • Automation mindset: ability to write scripts or small tools, ideally in Python, to reduce toil, improve visibility and surface meaningful risk.
  • Security leadership: ability to mentor other security engineers and influence engineers across the wider organisation. Depending on team structure, this may include line management.
  • AI security awareness: experience of leveraging AI to improve and scale appsec and cloud sec controls would be useful, but is not essential.

Key Responsibilities

  • Improve application security guardrails: Tune and evolve SAST, software composition analysis, secret scanning and related controls so they are actionable, low‑noise and useful to engineering teams.
  • Improve cloud and IaC security guardrails: Help identify, prioritise and reduce AWS and infrastructure‑as‑code misconfigurations and vulnerabilities at scale.
  • Drive vulnerability management: Improve how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third‑party advisories are triaged, prioritised and remediated.
  • Drive cloud misconfiguration management: Help teams understand, own and remediate cloud security issues using pragmatic, developer‑friendly workflows.
  • Run practical threat modelling: Facilitate lightweight threat‑modelling sessions for new products, features, services and architectural changes.
  • Build automation and tooling: Create or improve scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand.
  • Support secure architecture decisions: Provide application and cloud security input into design reviews, AWS architecture decisions and larger technical changes.
  • Partner with engineering teams: Work closely with product, platform and software engineering teams to embed security into design, delivery and operational practices.
  • Support incidents and lessons learned: Provide application and cloud security expertise during incidents and feed lessons learned back into patterns, tooling and guidance.
  • Mentor others: Coach security engineers and engineering teams on practical security approaches. Depending on team structure, this may include line management of one or two security engineers.

Required Experience, Essential

  • Strong practical experience in application security and cloud security, ideally with a balanced focus across both.
  • Hands‑on AWS security experience, including common misconfiguration patterns and practical remediation approaches.
  • Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction.
  • Experience in improving cloud or IaC misconfiguration management at scale in a developer‑friendly way.
  • Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning.
  • Experience running practical threat‑modelling sessions that influence design, delivery or remediation decisions.
  • Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.
  • Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping.
  • Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment.
  • Familiarity with Agile or Scrum ways of working.
  • Experience with leveraging AI for AppSec and CloudSec.
  • AWS Certified Security – Speciality or equivalent practical AWS security experience.
  • Terraform or CloudFormation expertise.
  • Incident‑management or incident‑response experience.
  • Experience with Splunk or similar logging/SIEM platforms.
  • Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction.
  • Experience mentoring or line‑managing security engineers.

What’s in it for You?

Our benefits vary by location but we are committed to providing best‑in‑class perks across all our offices. These include generous annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships and opportunities to give back to the community. We’ve embraced a 50% hybrid working model (averaging two to three days onsite) that fosters trust and remote adaptability while encouraging in‑person camaraderie and peer learning. Additionally, we are open to accommodating specific flexible working pattern requests for all roles where feasible.

Accessibility

We are a disability confident employer and Valuable 500 signatory.

Further information

At the FT, we embrace innovation and the use of technology and appreciate that individuals may leverage AI tools as part of their job application process. Whilst we are happy for you to use AI to assist with your application, it is essential that all information provided is authentic and accurately represents your skills, experience, and qualifications. Candidates should be aware that the use of AI throughout the application process may be monitored to ensure a fair and transparent hiring process for all.

Senior Cyber Engineer employer: The Financial Times Ltd

The Financial Times is an exceptional employer, offering a dynamic and inclusive work environment where curiosity and ambition are celebrated. With a strong commitment to employee growth, you will have access to diverse career opportunities, generous benefits including flexible working arrangements, and a collaborative culture that values unique perspectives. Join us in London to make a meaningful impact in the world of journalism while advancing your career in a supportive and innovative setting.
The Financial Times Ltd

Contact Detail:

The Financial Times Ltd Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Cyber Engineer

✨Tip Number 1

Network like a pro! Reach out to current or former employees at the Financial Times on LinkedIn. A friendly chat can give you insider info and maybe even a referral, which can really boost your chances.

✨Tip Number 2

Prepare for the interview by brushing up on your technical skills. Since this role is all about application and cloud security, make sure you can discuss your hands-on experience with AWS and security tooling confidently.

✨Tip Number 3

Show off your problem-solving skills! Be ready to share specific examples of how you've tackled security challenges in the past. The FT loves candidates who can demonstrate real-world impact.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the FT team.

We think you need these skills to ace Senior Cyber Engineer

Application Security
Cloud Security
AWS Security
Vulnerability Management
Infrastructure-as-Code (IaC)
Threat Modelling
CI/CD Security Tooling
SAST
Software Composition Analysis
Secret Scanning
Automation (Python)
Security Leadership
Communication Skills
Collaboration Skills
Agile or Scrum Methodologies

Some tips for your application 🫡

Show Your Passion: When writing your application, let your enthusiasm for cyber security shine through! We want to see how your curiosity and ambition align with our mission at the FT. Share specific examples of your experience that demonstrate your commitment to improving security outcomes.

Tailor Your Application: Make sure to customise your application to highlight your relevant skills and experiences. Focus on your practical experience in application and cloud security, especially in AWS environments. This will help us see how you can contribute to our team right from the start!

Be Clear and Concise: Keep your application straightforward and to the point. Use clear language to explain your technical skills and experiences. We appreciate a well-structured application that makes it easy for us to understand your qualifications and how they fit the role.

Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re serious about joining our team at the FT!

How to prepare for a job interview at The Financial Times Ltd

✨Know Your Stuff

Make sure you brush up on both application and cloud security concepts, especially in AWS environments. Be ready to discuss specific tools like SAST and IaC scanning, and how you've used them in real-world scenarios.

✨Show Your Developer-Friendly Side

Demonstrate your ability to communicate security risks clearly to engineering teams. Prepare examples of how you've designed security controls that help teams work securely without slowing them down.

✨Vulnerability Management is Key

Be prepared to talk about your experience with vulnerability management at scale. Share how you've improved processes for identifying, prioritising, and remediating vulnerabilities across engineering teams.

✨Bring Your Automation A-Game

Highlight any scripts or tools you've developed to automate security workflows. If you have experience with Python, make sure to mention it, as it shows your proactive approach to reducing manual effort in security tasks.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>