At a Glance
- Tasks: Enhance application security and collaborate with engineers on innovative projects.
- Company: Join the Financial Times, a leading news organisation known for integrity and quality.
- Benefits: Enjoy generous leave, medical cover, gym memberships, and a hybrid work model.
- Other info: Diverse culture with opportunities for personal and professional growth.
- Why this job: Make a real impact in cybersecurity while growing your skills in a supportive environment.
- Qualifications: Experience in application security and a passion for working with engineering teams.
About Us
The Financial Times is one of the world’s leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to deliver quality information and services worldwide. At the FT, curiosity thrives and ambitious thinking is rewarded. Here, you’re given the chance to reach millions, create work that matters and deliver impartial journalism in a polarised world. In our warm, collaborative culture, you’ll connect with a diverse community of experts who support your growth, career aspirations and wellbeing. Your future at the FT will be filled with opportunities that challenge and inspire you. With no fixed path, you’ll discover new skills and forge a career that can take you anywhere.
Our Commitment to Diversity, Equity and Inclusion
We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued. A supportive workplace is one where employees feel they can be themselves and operate to their full potential. We are committed to removing barriers for everyone, with a focus on addressing those faced by underrepresented groups.
The Role Overview
We’re looking for a Cyber Security Engineer to help improve application security across the FT’s cloud-native technology estate. This is a hands-on role focused on making secure engineering easier for product, platform and software engineering teams. Application security experience is essential for this role. You’ll help improve developer-friendly security guardrails across GitHub-based CI/CD pipelines, application repositories and engineering workflows. This includes working with SAST, software composition analysis, secret scanning, vulnerability management and secure coding guidance so that security findings are clear, actionable and owned by the right teams. You’ll work closely with engineers to support practical threat modelling, triage application vulnerabilities, improve security playbooks and help teams remediate issues in a pragmatic way. You do not need to be a deep AWS or cloud security specialist, but some exposure to AWS, cloud security or infrastructure-as-code security would be useful.
We’re looking for someone with practical AppSec experience who wants to grow their impact - someone who enjoys working with engineers, improving tooling and helping security become part of normal delivery rather than a last-minute checkpoint.
What you’ll bring to the role
- Application security experience: practical experience identifying, explaining and helping remediate application security risks in modern engineering environments.
- Developer-friendly security mindset: you enjoy working with engineers, explaining risks clearly and helping teams adopt secure practices without unnecessary friction.
- Vulnerability management experience: experience triaging and tracking application vulnerabilities from sources such as SAST, dependency scanning, secret scanning, penetration tests, bug bounty reports or third-party advisories.
- CI/CD and code security awareness: familiarity with security tooling in development workflows, such as SAST, software composition analysis, secret scanning or repository security controls.
- Threat modelling awareness: experience participating in, supporting or facilitating lightweight threat-modelling sessions for applications, services or new features.
- Automation mindset: ability to write scripts or small tools, ideally in Python, to reduce manual effort, improve visibility or make security workflows easier.
- Cloud security awareness: Some exposure to AWS, cloud security or infrastructure-as-code security would be useful, but is not essential.
- Growth mindset: willingness to keep developing across application security, cloud security, secure development and modern engineering practices.
Required Experience, Essential
- Practical experience in application security.
- Experience working with software engineers to explain and remediate security issues.
- Familiarity with common web application security risks and secure coding practices.
- Experience with vulnerability triage, prioritisation and remediation tracking.
- Experience using or interpreting findings from tools such as SAST, software composition analysis, secret scanning or similar.
- Experience participating in or supporting threat-modelling activities.
- Ability to write scripts or small tools, ideally in Python, to automate tasks or improve visibility.
- Strong communication and collaboration skills.
- Familiarity with Agile or Scrum ways of working.
Desirable
- Exposure to AWS security, cloud security or infrastructure-as-code security.
- Experience with Terraform or CloudFormation.
- Experience with container or Kubernetes security.
- Experience with bug bounty, penetration testing or security testing programmes.
- Experience with Splunk or similar logging/SIEM platforms.
- Exposure to AI security, such as LLM-enabled applications, AI-assisted development workflows or prompt/data leakage risks.
- Experience building dashboards, metrics or reports to support vulnerability management.
- Relevant security certifications or training, such as AWS security training, secure coding training, GIAC, ISC2, CREST or equivalent practical experience.
What’s in it for you? Our benefits
Our benefits vary by location but we are committed to providing best-in-class perks across all our offices. These include generous annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships and opportunities to give back to the community. Full details of our benefits are available here.
We currently operate a hybrid model which requires staff to work onsite 50% of the time, subject to role requirements & regular review. While flexible working requests will be considered, not all patterns are suitable for all roles. We believe this balanced approach supports flexibility and protects our culture, making collaboration and communication easier, building stronger relationships and team cohesion, and supporting peer learning. We reserve discretion on reasonable notice to change this approach either generally or for specific individuals or teams.
Accessibility
We are a disability confident employer and Valuable 500 signatory. Please let us know if you require any reasonable adjustments/personalisation as part of the application process or to enable you to attend an interview. If you would like to discuss your requirements or have any questions, email talent@ft.com and a member of our team will be happy to help.
Further information
At the FT, we embrace innovation and the use of technology and appreciate that individuals may leverage AI tools as part of their job application process. Whilst we are happy for you to use AI to assist with your application, it is essential that all information provided is authentic and accurately represents your skills, experience, and qualifications. Candidates should be aware that the use of AI throughout the application process may be monitored to ensure a fair and transparent hiring process for all.
Cyber Security Engineer (Contract) in London employer: The Financial Times
The Financial Times is an exceptional employer, offering a vibrant and collaborative work culture that fosters curiosity and ambition. As a Companies Writer for Investors Chronicle, you'll have the opportunity to engage with a diverse community of experts, enjoy generous benefits including flexible working arrangements, and access numerous growth opportunities that empower you to shape your career in impactful journalism.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Engineer (Contract) in London
✨Get Engaged in Cybersecurity Communities
Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like The Financial Times.
✨Showcase Your Skills Publicly
Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.
✨Stay On Top of Temp Opportunities
Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like The Financial Times.
✨Make Contact with Recruiters Specialising in Cybersecurity
Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like The Financial Times.
We think you need these skills to ace Cyber Security Engineer (Contract) in London
Some tips for your application 🫡
Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives The Financial Times a clear view of your capabilities right off the bat.
Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.
Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at The Financial Times; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!
Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at The Financial Times.
How to prepare for a job interview at The Financial Times
✨Brush Up on Technical Skills
Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with The Financial Times for the Cyber Security Engineer (Contract), be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.
✨Show Your Problem-Solving Prowess
Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!
✨Demonstrate Your Adaptability
As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at The Financial Times.
✨Bring Relevant Certifications
If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the Cyber Security Engineer (Contract) role at The Financial Times.