At a Glance
- Tasks: Enhance application and cloud security while collaborating with engineering teams.
- Company: Join the Financial Times, a leading global news organisation with a collaborative culture.
- Benefits: Enjoy generous leave, medical cover, gym memberships, and community engagement opportunities.
- Other info: Hybrid work model with a focus on flexibility and team collaboration.
- Why this job: Make a real impact on security in a dynamic, innovative environment.
- Qualifications: Experience in application and cloud security, especially in AWS environments.
The predicted salary is between 63000 - 77000 Β£ per year.
About Us
The Financial Times is one of the world's leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to deliver quality information and services worldwide. Here, you're given the chance to reach millions, create work that matters and deliver impartial journalism in a polarised world. In our warm, collaborative culture, you'll connect with a diverse community of experts who support your growth, career aspirations and wellbeing. Your future at the FT will be filled with opportunities that challenge and inspire you.
Our Commitment to Diversity, Equity and Inclusion
We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued.
Overview
We're looking for a Senior Cyber Security Engineer to help mature application and cloud security across the FT's cloud-native, AWS-hosted technology estate. You'll shape and improve developer-friendly guardrails across GitHub-based CI/CD pipelines, AWS environments and infrastructure-as-code workflows. This includes improving SAST, software composition analysis, secret scanning, IaC scanning, vulnerability management and AWS misconfiguration management so that findings are actionable, low-noise and owned by the right teams.
What you'll bring to the role
- Application and cloud security experience: practical experience across both application security and cloud security, ideally in AWS-hosted, cloud-native environments.
- Developer-friendly security mindset: you know how to work with engineers, explain risk clearly and design controls that help teams move securely without unnecessary friction.
- Vulnerability management at scale: experience improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and advisories are identified, prioritised, owned and remediated across engineering teams.
- Cloud misconfiguration & vulnerability management: experience identifying and reducing infrastructure-as-code and AWS vulnerabilities & misconfigurations at scale through pragmatic guardrails, tooling and clear remediation paths.
- Threat modelling: confidence running lightweight, practical threat-modelling sessions that lead to useful engineering decisions and risk reduction.
- CI/CD and code security: hands-on experience with security tooling such as SAST, software composition analysis, secret scanning and IaC scanning.
- Automation mindset: ability to write scripts or small tools, ideally in Python, to reduce toil, improve visibility and surface meaningful risk.
- AI security awareness: experience of leveraging AI to improve and scale appsec and cloud sec controls would be useful, but is not essential.
Key Responsibilities
- Improve application security guardrails: Tune and evolve SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams.
- Improve cloud and IaC security guardrails: Help identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale.
- Drive vulnerability management: Improve how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated.
- Drive cloud misconfiguration management: Help teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows.
- Build automation and tooling: Create or improve scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand.
- Support secure architecture decisions: Provide application and cloud security input into design reviews, AWS architecture decisions and larger technical changes.
- Partner with engineering teams: Work closely with product, platform and software engineering teams to embed security into design, delivery and operational practices.
Desirable
- Experience with leveraging AI for AppSec and CloudSec.
- AWS Certified Security β Speciality or equivalent practical AWS security experience.
- Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction.
These include generous annual leave, medical cover, inclusive parental leave packages, subsidised gym memberships and opportunities to give back to the community. We currently operate a hybrid model which requires staff to work onsite 50% of the time, subject to role requirements & regular review. While flexible working requests will be considered, not all patterns are suitable for all roles. We believe this balanced approach supports flexibility and protects our culture, making collaboration and communication easier, building stronger relationships and team cohesion, and supporting peer learning.
Accessibility
We are a disability confident employer and Valuable 500 signatory. If you would like to discuss your requirements or have any questions, email talent@ft.com and a member of our team will be happy to help.
Further information
At the FT, we embrace innovation and the use of technology and appreciate that individuals may leverage AI tools as part of their job application process. Whilst we are happy for you to use AI to assist with your application, it is essential that all information provided is authentic and accurately represents your skills, experience, and qualifications. Candidates should be aware that the use of AI throughout the application process may be monitored to ensure a fair and transparent hiring process for all.
Senior Cyber Security Engineer - Hybrid in London employer: The Financial Times
The Financial Times is an exceptional employer, offering a vibrant and inclusive work culture that prioritises employee growth and wellbeing. With generous benefits such as annual leave, medical cover, and opportunities for community engagement, employees are supported in their professional journeys while contributing to meaningful journalism. Located in a collaborative environment, the role of Senior IT Engineer allows you to connect with diverse experts and leverage cutting-edge technology, making a significant impact within the organisation.