Senior Cyber Security Engineer

Company: The Financial Times
Apply for the Senior Cyber Security Engineer
Location: London
Job Description:

Overview

As Senior Cyber Security Engineer, you help mature application and cloud security for the FT’s AWS-hosted, cloud-native estate. You will shape developer-friendly guardrails across CI/CD pipelines, AWS environments and IaC, driving actionable, low-noise findings. You’ll run threat-modelling sessions, review designs and improve security playbooks, reducing toil through automation. You may mentor other engineers while staying hands-on, contributing to secure delivery at scale. This role blends hands-on security practice with shaping engineering outcomes to support the FT’s mission of accurate, impartial journalism.

Responsibilities

  • Improve application security guardrails across SAST, software composition analysis, secret scanning and related controls
  • Improve cloud and IaC security guardrails and reduce misconfigurations at scale
  • Drive vulnerability management: triage, prioritise and remediate findings across engineering teams
  • Drive cloud misconfiguration management with developer-friendly workflows
  • Run practical threat modelling sessions for new products/features/services
  • Build automation and tooling to reduce manual effort and surface risk
  • Support secure architecture decisions in design reviews and AWS architecture decisions
  • Partner with engineering teams to embed security into design, delivery and operations
  • Support incidents and lessons learned with security expertise and tooling guidance
  • Mentor others, potentially including line management of one or two security engineers

Key requirements

  • Strong practical experience in application security and cloud security, ideally balanced
  • Hands-on AWS security experience with common misconfigurations and remediation approaches
  • Experience improving vulnerability management across engineering teams
  • Experience improving cloud or IaC misconfiguration management at scale in a developer-friendly way
  • Experience integrating or tuning security tooling in CI/CD workflows (SAST, software composition analysis, secret scanning, IaC scanning)
  • Experience running practical threat-modelling sessions that influence design/delivery/remediation
  • Ability to write scripts/tools (preferably Python) to automate security workflows
  • Strong communication and collaboration skills to influence engineers and leaders without gatekeeping
  • Evidence of improving security practices in a real engineering environment
  • Familiarity with Agile or Scrum ways of working
  • Strong communication and collaboration
  • Mentorship and leadership capability
  • Pragmatic problem-solving approach
  • SAST
  • Software composition analysis
  • Secret scanning

…

Posted: October 1st, 2026