Overview
As Senior Cyber Security Engineer, you help mature application and cloud security for the FT’s AWS-hosted, cloud-native estate. You will shape developer-friendly guardrails across CI/CD pipelines, AWS environments and IaC, driving actionable, low-noise findings. You’ll run threat-modelling sessions, review designs and improve security playbooks, reducing toil through automation. You may mentor other engineers while staying hands-on, contributing to secure delivery at scale. This role blends hands-on security practice with shaping engineering outcomes to support the FT’s mission of accurate, impartial journalism.
Responsibilities
- Improve application security guardrails across SAST, software composition analysis, secret scanning and related controls
- Improve cloud and IaC security guardrails and reduce misconfigurations at scale
- Drive vulnerability management: triage, prioritise and remediate findings across engineering teams
- Drive cloud misconfiguration management with developer-friendly workflows
- Run practical threat modelling sessions for new products/features/services
- Build automation and tooling to reduce manual effort and surface risk
- Support secure architecture decisions in design reviews and AWS architecture decisions
- Partner with engineering teams to embed security into design, delivery and operations
- Support incidents and lessons learned with security expertise and tooling guidance
- Mentor others, potentially including line management of one or two security engineers
Key requirements
- Strong practical experience in application security and cloud security, ideally balanced
- Hands-on AWS security experience with common misconfigurations and remediation approaches
- Experience improving vulnerability management across engineering teams
- Experience improving cloud or IaC misconfiguration management at scale in a developer-friendly way
- Experience integrating or tuning security tooling in CI/CD workflows (SAST, software composition analysis, secret scanning, IaC scanning)
- Experience running practical threat-modelling sessions that influence design/delivery/remediation
- Ability to write scripts/tools (preferably Python) to automate security workflows
- Strong communication and collaboration skills to influence engineers and leaders without gatekeeping
- Evidence of improving security practices in a real engineering environment
- Familiarity with Agile or Scrum ways of working
- Strong communication and collaboration
- Mentorship and leadership capability
- Pragmatic problem-solving approach
- SAST
- Software composition analysis
- Secret scanning
…
