Senior Cyber Security Engineer
Financial Times
About us
The Financial Times is one of the world’s leading news organisations, globally recognised for its authority, integrity and accuracy, with a mission to deliver quality information and services worldwide.
At the FT, curiosity thrives and ambitious thinking is rewarded. Here, you’re given the chance to reach millions, create work that matters and deliver impartial journalism in a polarised world.
In our warm, collaborative culture, you’ll connect with a diverse community of experts who support your growth, career aspirations and wellbeing.
Your future at the FT will be filled with opportunities that challenge and inspire you. With no fixed path, you’ll discover new skills and forge a career that can take you anywhere.
Build a newsworthy career at the FT.
Our commitment to diversity, equity and inclusion
We believe in the power of unique perspectives and want all voices in our organisation to be heard, respected and valued. A supportive workplace is one where employees feel they can be themselves and operate to their full potential. We are committed to removing barriers for everyone, with a focus on addressing those faced by underrepresented groups.
About the role:
We’re looking for a Senior Cyber Security Engineer to help mature application and cloud security across the FT’s cloud-native, AWS-hosted technology estate. This role has an approximate 50/50 focus across application security and cloud security, working closely with product, platform and engineering teams to make secure delivery easier by default.
You’ll shape and improve developer-friendly guardrails across GitHub-based CI/CD pipelines, AWS environments and infrastructure-as-code workflows. This includes improving SAST, software composition analysis, secret scanning, IaC scanning, vulnerability management and AWS misconfiguration management so that findings are actionable, low-noise and owned by the right teams.
Day to day, you’ll run practical threat-modelling sessions, review application and cloud designs, improve security playbooks, support vulnerability and misconfiguration remediation, and build automation that reduces toil. We’re looking for someone who has demonstrably improved security outcomes in real engineering environments, not just someone with theoretical knowledge of tools or frameworks.
Depending on team structure, you may also mentor or line-manage one or two security engineers, while remaining hands-on and close to the technical work.
What you’ll bring to the role
Application and cloud security experience: practical experience across both application security and cloud security, ideally in AWS-hosted, cloud-native environments.
Developer-friendly security mindset: you know how to work with engineers, explain risk clearly and design controls that help teams move securely without unnecessary friction.
Vulnerability management at scale: experience improving how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and advisories are identified, prioritised, owned and remediated across engineering teams.
Cloud misconfiguration & vulnerability management: experience identifying and reducing infrastructure-as-code and AWS vulnerabilities & misconfigurations at scale through pragmatic guardrails, tooling and clear remediation paths.
Threat modelling: confidence running lightweight, practical threat-modelling sessions that lead to useful engineering decisions and risk reduction.
CI/CD and code security: hands-on experience with security tooling such as SAST, software composition analysis, secret scanning and IaC scanning.
Automation mindset: ability to write scripts or small tools, ideally in Python, to reduce toil, improve visibility and surface meaningful risk.
Security leadership: ability to mentor other security engineers and influence engineers across the wider organisation. Depending on team structure, this may include line management.
AI security awareness: experience of leveraging AI to improve and scale appsec and cloud sec controls would be useful, but is not essential.
Key Responsibilities
Improve application security guardrails Tune and evolve SAST, software composition analysis, secret scanning and related controls so they are actionable, low-noise and useful to engineering teams.
Improve cloud and IaC security guardrails Help identify, prioritise and reduce AWS and infrastructure-as-code misconfigurations and vulnerabilities at scale.
Drive vulnerability management Improve how application vulnerabilities, dependency risks, bug bounty findings, penetration test findings and third-party advisories are triaged, prioritised and remediated.
Drive cloud misconfiguration management Help teams understand, own and remediate cloud security issues using pragmatic, developer-friendly workflows.
Run practical threat modelling Facilitate lightweight threat-modelling sessions for new products, features, services and architectural changes.
Build automation and tooling Create or improve scripts, integrations, dashboards and workflows that reduce manual effort and make risk easier to understand.
Support secure architecture decisions Provide application and cloud security input into design reviews, AWS architecture decisions and larger technical changes.
Partner with engineering teams Work closely with product, platform and software engineering teams to embed security into design, delivery and operational practices.
Support incidents and lessons learned Provide application and cloud security expertise during incidents and feed lessons learned back into patterns, tooling and guidance.
Mentor others Coach security engineers and engineering teams on practical security approaches. Depending on team structure, this may include line management of one or two security engineers.
Required Experience, Essential:
- Strong practical experience in application security and cloud security, ideally with a balanced focus across both.
- Hands-on AWS security experience, including common misconfiguration patterns and practical remediation approaches.
- Experience improving vulnerability management across engineering teams, including prioritisation, ownership, remediation tracking and noise reduction.
- Experience in improving cloud or IaC misconfiguration management at scale in a developer-friendly way.
- Experience integrating, tuning or improving security tooling in CI/CD workflows, such as SAST, software composition analysis, secret scanning or IaC scanning.
- Experience running practical threat-modelling sessions that influence design, delivery or remediation decisions.
- Ability to write scripts or small tools, ideally in Python, to automate security workflows or improve visibility.
- Strong communication and collaboration skills, with the ability to influence engineers and technical leaders without relying on gatekeeping.
- Evidence of improving application security, cloud security or vulnerability management practices in a real engineering environment.
- Familiarity with Agile or Scrum ways of working.
Desirable
- Experience with leveraging AI for AppSec and CloudSec.
- AWS Certified Security – Speciality or equivalent practical AWS security experience.
- Terraform or CloudFormation expertise.
- Incident-management or incident-response experience.
- Experience with Splunk or similar logging/SIEM platforms.
- Experience with security metrics, dashboards or reporting that helped drive measurable risk reduction.
- Experience mentoring or line-managing security engineers.
Accessibility
We are a disability confident employer and Valuable 500 signatory.
Please let us know if you require any reasonable adjustments/personalisation as part of the application process or to enable you to attend an interview. If you would like to discuss your requirements or have any questions, email View email address on job-boards.eu.greenhouse.io and a member of our team will be happy to help.
Further information
At the FT, we embrace innovation and the use of technology and appreciate that individuals may leverage AI tools as part of their job application process. Whilst we are happy for you to use AI to assist with your application, it is essential that all information provided is authentic and accurately represents your skills, experience, and qualifications.
Candidates should be aware that the use of AI throughout the application process may be monitored to ensure a fair and transparent hiring process for all.
Please beware of fraudulent job postings and offers claiming to be from the Financial Times. All legitimate opportunities will direct you to apply through the official Financial Times careers site, and the FT will never ask for financial information, payments, or referrals to third parties during the hiring process. If you have any concerns about the legitimacy of a job posting or suspect any scam activity, please contact View email address on job-boards.eu.greenhouse.io .
Interested in the FT but don’t see the right role yet? Join our Talent Community to receive exclusive updates, featured jobs, and insights into working at the FT.
- ...Intuition Machines uses AI/ML to build enterprise security products. We apply our research to systems that serve hundreds of millions... ...simple: low overhead, small teams, and rapid iteration. As a Senior Cyber Security Analyst, you will leverage your expertise in bot...
- ...everyone, with a focus on addressing those faced by underrepresented groups. About the role: We’re looking for a Cyber Security Engineer to help improve application security across the FT’s cloud-native technology estate. This is a hands-on role focused on making...
- ...Business Development Manager – Cyber Security (Australian Market) Location: Anywhere in the Philippines (Work From Home) Employment Type: Full-Time Working Hours: Australian Eastern Standard Time (AEST/AEDT) Reporting To: Director – Business Development...
- ...You will play a key role in keeping Axi colleagues safe in the world of Cyber. With a key focus on engineering and automation, this role focuses on implementing strategic solutions to security problems, providing a secure environment for our customers and colleagues...
- ...Philippines Reports To: Director of Information Technology Position Overview We are looking for an experienced Senior Security Engineer to join our remote team from the Philippines. This role sits at the core of our security operations and compliance posture...
- ...JOB SUMMARY The Senior Cloud Security Engineer will be responsible for designing, implementing, and managing robust security solutions for our cloud infrastructure. This role requires a deep understanding of cloud security best practices, risk management, and compliance...
- ...feels valued, empowered, and inspired to grow. Our mission is to securely connect people, places, and information with end-to-end... ...future of work—together What is the role As a Security Engineer you will be responsible for the deployment, configuration, and...
- ...This is a remote position. SUMMARY Seeking a highly skilled Senior Network & Security Engineer with strong experience in enterprise networking and security within an MSP environment. The ideal candidate will be responsible for designing, implementing, supporting...
- ...& Assessment, a distinguished global academic publisher and assessment organisation proudly affiliated with the prestigious University of Cambridge. We are seeking a technically proficient and security-driven Data Security Engineer to join our Group Security Team...
- ...JOB SUMMARY The Application Security Engineer is responsible for assessing the security of new applications and systems, conducting security assessments, and collaborating with the research and development team to implement a robust security framework. The role ensures...
- ...communities we live in.. About the Role (your why) Our Endpoint Engineering team is responsible for creating and maintaining robust... ...and ensuring standardization across diverse IT landscapes. As a Senior Endpoint Engineering Specialist, you’ll work closely with...
- ...Kroll’s Cyber Risk team helps organizations respond to and prepare for cyber incidents across some of the most complex and high‑profile... ...matters Develop hands‑on experience across multiple cyber security disciplines Why this role is a great start Hands‑on from...
- ...Position : Senior Data Engineer Salary : 3,000 - 5,000 NZD Working Hours & Conditions : New Zealand working hours OVERVIEW: This isn't a role where you'll be handed a ticket queue. You'll own meaningful pieces of work, shape how we build, and have a direct...
- ...jobs offered by thousands of trusted employers in Singapore and Malaysia, across all sectors! We are looking for a skilled Senior Software Engineer who, along with our excellent software development team, will be responsible for working on projects that are currently...
- ...solutions that leverage DB standards, with a strong focus on cyber security and cyber resiliency Our team is diverse, international... ...multiple technical towers as appropriate. Providing engineering solutions to solve new and existing operational challenges....
- ...Position: AI SECURITY EXPERT Salary rang e: up to ₱150,000 Philippine Peso (with the final offer subject to the client’s discretion... ..., production-ready systems that are robust against an evolving cyber threat landscape. Core Responsibilities Your focus will...
- ...This is a remote position. Design, develop, and maintain robust frameworks and internal tools to enhance engineering efficiency, developer experience, and product quality. Partner with cross-functional teams (Engineering, QA, DevOps, and Product) to identify...
- ...site; Provide 2nd level support to the NOCs for such services and be an escalation point for such issues; Work with the core engineering team to resolve higher level problems and implement solutions per request; Participate in Migrations and support of additional...
- ...SYSTRA is one of the world's leading engineering and consultancy groups specialising in public transport and sustainable mobility. With... ...order to invent the mobility of tomorrow. Context The Senior Electrical Engineer is responsible for leading the design, development...
- ...Senior Data Engineer Work setup: We operate in a hybrid work environment, and we encourage applicants who are open to working in the office two days a week to apply. Work schedule: Monday to Friday, 3PM to 11PM Manila time, overlaps with UK operating hours Employment...
- This is a remote position. Responsible for independently and cooperatively understanding business requirements. Architecting, designing and implementing a reliable and scalable automation framework for a real-world machine learning platform. Automating tests...
- ...SYSTRA is one of the world's leading engineering and consultancy groups specialising in public transport and sustainable mobility. With... ...order to invent the mobility of tomorrow. Context The Senior Drainage Engineer will be leading the design of urban, roadway...
- ...SYSTRA is one of the world's leading engineering and consultancy groups specialising in public transport and sustainable mobility. With... ...order to invent the mobility of tomorrow. Context The Senior Road Engineer will be responsible for leading geometric design...
- ...This is a remote position. We are seeking a highly organized and dependable Security Administrator Intern to manage user access, credentials, and routine security operations across various business systems. The ideal candidate will have strong attention to detail...
- ...SYSTRA is one of the world's leading engineering and consultancy groups specialising in public transport and sustainable mobility. With... ...order to invent the mobility of tomorrow. Context the Senior Structural Engineer will perform structural engineering calculations...
- ...is the Kroll’s difference. Kroll’s Security Operation’s Center helps firm manage cybersecurity... ...equivalent in Computer Science, Systems Engineering, Cybersecurity, Information Technology,... ...4 years of monitoring experience in Cyber Security Operations Center. Excellent...
- ...Review DRD (Design Requirements Documents) relating to new and on-going projects Bug review and Lab test new code for various security platforms (Cisco, Palo Alto, HPE Aruba ClearPass) Lab testing for new network/security designs and technologies (Firewall, IPS,...
- Job Overview We are looking for an experienced Senior Full Stack AI Engineer to design, build, and deploy AI-powered applications from concept... ...Generation (RAG) systems using vector databases. }~} Build secure REST APIs and backend services. }~} Architect cloud-...
- ...pipelines, build systems, and release automation that enable engineering teams to deliver software reliably and efficiently. As part of... ...observability, and log management tools. • Familiarity with security scanning and shift-left security practices in CI/CD pipelines....
- ...This is a remote position. My Amazon Guy is looking for an experienced Automation Security Specialist to join our team! In this role, you will be responsible for optimizing and modernizing existing automation workflows in Zapier. A key focus will be transitioning...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Cyber Security Engineer. Be the first to apply!
