Senior Cyber Security Engineer in London

Senior Cyber Security Engineer in London

London Full-Time 60000 - 80000 £ / year (est.) No working from home possible
The Financial Times

At a Glance

  • Tasks: Enhance application and cloud security in a dynamic AWS environment.
  • Company: Join a leading tech firm focused on innovative security solutions.
  • Benefits: Competitive salary, flexible working, and opportunities for professional growth.
  • Other info: Work in a supportive team with a focus on continuous improvement and innovation.
  • Why this job: Make a real impact by shaping secure delivery practices and mentoring future security leaders.
  • Qualifications: Experience in application and cloud security, with strong collaboration skills.

The predicted salary is between 60000 - 80000 £ per year.

We’re looking for someone who has demonstrably improved security outcomes in real engineering environments, not just someone with theoretical knowledge of tools or frameworks.

Requirements:

  • Application and cloud security experience: practical experience across both application security and cloud security, ideally in AWS-hosted, cloud-native environments.
  • Developer-friendly security mindset: you know how to work with engineers, explain risk clearly and design controls that help teams move securely without unnecessary friction.
  • Vulnerability management at scale: experience improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and advisories are identified, prioritised, owned and remediated across engineering teams.
  • Cloud misconfiguration & vulnerability management: experience identifying and reducing infrastructure-as-code and AWS vulnerabilities & misconfigurations at scale through pragmatic guardrails, tooling and clear remediation paths.
  • Threat modelling: confidence running lightweight, practical threat-modelling sessions that lead to useful engineering decisions and risk reduction.
  • CI/CD and code security: hands-on experience with security tooling such as SAST, software composition analysis, secret scanning and IaC scanning.
  • Automation mindset: ability to write scripts or small tools, ideally in Python, to reduce toil, improve visibility and surface meaningful risk.
  • Security leadership: ability to mentor other security engineers and influence engineers across the wider organisation. Depending on team structure, this may include line management.
  • AI security awareness: experience of leveraging AI to improve and scale appsec and cloud sec controls would be useful, but is not essential.
  • Strong practical experience in application security and cloud security, ideally with a balanced focus across both.
  • Hands-on AWS security experience, including common misconfiguration patterns and practical remediation approaches.
  • Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction.
  • Experience in improving cloud or IaC misconfiguration management at scale in a developer-friendly way.
  • Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning.
  • Experience running practical threat-modelling sessions that influence design, delivery or remediation decisions.
  • Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.
  • Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping.
  • Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment.
  • Familiarity with Agile or Scrum ways of working (Desirable).
  • Experience with leveraging AI for AppSec and CloudSec (Desirable).
  • AWS Certified Security – Speciality or equivalent practical AWS security experience (Desirable).
  • Terraform or CloudFormation expertise (Desirable).
  • Incident-management or incident-response experience (Desirable).
  • Experience with Splunk or similar logging/SIEM platforms (Desirable).
  • Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction (Desirable).
  • Experience mentoring or line-managing security engineers.

What the job involves:

We’re looking for a Senior Cyber Security Engineer to help mature application and cloud security across the FT’s cloud-native, AWS-hosted technology estate. This role has an approximate 50/50 focus across application security and cloud security, working closely with product, platform and engineering teams to make secure delivery easier by default.

You’ll shape and improve developer-friendly guardrails across GitHub-based CI/CD pipelines, AWS environments and infrastructure-as-code workflows. This includes improving SAST, software composition analysis, secret scanning, IaC scanning, vulnerability management and AWS misconfiguration management so that findings are actionable, low-noise and owned by the right teams.

Day to day, you’ll run practical threat-modelling sessions, review application and cloud designs, improve security playbooks, support vulnerability and misconfiguration remediation, and build automation that reduces toil. Depending on team structure, you may also mentor or line-manage one or two security engineers, while remaining hands-on and close to the technical work.

Tune and evolve SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams. Help identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale. Improve how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated.

Help teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows. Facilitate lightweight threat-modelling sessions for new products, features, services and architectural changes. Create or improve scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand.

Provide application and cloud security input into design reviews, AWS architecture decisions and larger technical changes. Work closely with product, platform and software engineering teams to embed security into design, delivery and operational practices. Provide application and cloud security expertise during incidents and feed lessons learned back into patterns, tooling and guidance. Coach security engineers and engineering teams on practical security approaches. Depending on team structure, this may include line management of one or two security engineers.

Senior Cyber Security Engineer in London employer: The Financial Times

As a Senior Cyber Security Engineer at our company, you will thrive in a dynamic and collaborative environment that prioritises innovation and security excellence. We offer a supportive work culture that encourages continuous learning and professional growth, with opportunities to mentor fellow engineers and influence security practices across teams. Located in a vibrant tech hub, our organisation provides access to cutting-edge resources and a community of like-minded professionals dedicated to making a meaningful impact in the field of cyber security.

The Financial Times

Contact Details:

The Financial Times Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Cyber Security Engineer in London

Tip Number 1

Network like a pro! Attend industry meetups, conferences, or webinars where you can connect with other cyber security professionals. Don’t be shy—introduce yourself and share your experiences. You never know who might have the inside scoop on job openings!

Tip Number 2

Show off your skills in practical settings. Consider contributing to open-source projects or participating in hackathons. This not only boosts your portfolio but also demonstrates your hands-on experience with application and cloud security, which is exactly what employers are looking for.

Tip Number 3

Prepare for interviews by brushing up on your technical knowledge and soft skills. Be ready to discuss real-world scenarios where you've improved security outcomes. Practice explaining complex concepts in simple terms—this will show that you can communicate effectively with engineers.

Tip Number 4

Don’t forget to apply through our website! We’re always on the lookout for talented individuals like you. Tailor your application to highlight your relevant experience in AWS security and vulnerability management, and let us know how you can help make secure delivery easier by default.

We think you need these skills to ace Senior Cyber Security Engineer in London

Application Security
Cloud Security
AWS Security
Vulnerability Management
Threat Modelling
CI/CD Security Tooling
Infrastructure as Code (IaC)

Some tips for your application 🫡

Show Your Real-World Impact:When you're writing your application, make sure to highlight specific examples where you've improved security outcomes in real engineering environments. We want to see how your hands-on experience has made a difference, not just theoretical knowledge.

Be Developer-Friendly:Remember, we’re looking for someone who can work well with engineers. Use clear language to explain risks and how your security measures can help teams move securely without slowing them down. Show us you can bridge the gap between security and development!

Highlight Your Automation Skills:If you've got experience writing scripts or tools, especially in Python, make sure to mention it! We love candidates who can automate security workflows and improve visibility, so share any relevant projects or tools you've developed.

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to keep track of your application and ensure it gets the attention it deserves. Plus, it shows you’re serious about joining our team at StudySmarter.

How to prepare for a job interview at The Financial Times

Know Your Stuff

Make sure you can talk confidently about your hands-on experience with application and cloud security. Be ready to share specific examples of how you've improved security outcomes in real engineering environments, especially in AWS-hosted settings.

Speak Developer's Language

Since this role requires a developer-friendly security mindset, practice explaining complex security concepts in simple terms. Show that you can collaborate effectively with engineers and help them understand risks without creating unnecessary friction.

Showcase Your Automation Skills

Be prepared to discuss any scripts or tools you've developed, particularly in Python, to automate security workflows. Highlight how these have helped reduce toil and improve visibility in security processes.

Prepare for Practical Scenarios

Expect to run through practical threat-modelling sessions during the interview. Brush up on your ability to facilitate these discussions and demonstrate how they lead to actionable engineering decisions and risk reduction.